Security Experts:

Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Mobile & Wireless

Spain’s Spy Chief Sacked Over Phone Hacking Scandal

Spain’s government on Tuesday sacked the country’s spy chief as part of a widening scandal over the hacking of the mobile phones of the prime minister and Catalan separatist leaders.

Spain’s government on Tuesday sacked the country’s spy chief as part of a widening scandal over the hacking of the mobile phones of the prime minister and Catalan separatist leaders.

Paz Esteban, the first woman to head Spain’s CNI intelligence agency, will be replaced, Defence Minister Margarita Robles whose ministry oversees the agency, told a news conference in confirming media reports.

“Full security does not exist, we have a series of threats regarding security which get bigger each day,” the minister added.

Esteban appeared before a parliamentary committee for questioning on Thursday over the phone hacking scandal which has dominated headlines for days.

She confirmed that 18 Catalan separatists, including Pere Aragones, the head of Catalonia’s regional government, had been spied on by the CNI but always with court approval.

The scandal broke in April when Canadian cybersecurity watchdog Citizen Lab said the phones of over 60 people linked to the Catalan separatist movement had been tapped using Pegasus spyware after a failed independence bid in 2017.

The affair has sparked a crisis between Sanchez’s minority government and Catalan separatist party ERC. Sanchez’s fragile coalition relies on the ERC to pass legislation in parliament.

The scandal deepened after the government announced on May 2 that the phones of Sanchez and Robles were hacked by the same spyware, made by Israel’s NSO group, in May and June 2021.

Sanchez is the first serving head of government confirmed to have been targeted by controversial Pegasus spyware.

The revelation raised questions over who is to blame and whether Spain has adequate security protocols.

Interior Minister Fernando Grande-Marlaska’s phone was also among those hacked last year, government spokeswoman Isabel Rodriguez said Tuesday after all cabinet minister’s phone were analysed.

“Since then there are no traces of Pegasus infections” of the phones of cabinet ministers, she told a join news conference with Robles.

Some Spanish media have pointed the finger at Morocco, which was in a diplomatic spat with Spain at the time, but the government has said it was no evidence of who may be responsible.

Pegasus spyware infiltrates mobile phones to extract data or activate a camera or microphone to spy on their owners.

The Israel-based NSO Group, which owns Pegasus, claims the software is only sold to government agencies to target criminals and terrorists, with the green light of Israeli authorities.

The company has been criticized by global rights groups for violating users’ privacy around the world and it faces lawsuits from major tech firms such as Apple and Microsoft.

Amnesty International, the London-based rights group, said the software has been used to hack up to 50,000 mobile phones worldwide.

Related: Apple Ships Urgent Patch for FORCEDENTRY Zero-Days

Related: New iOS Zero-Click Exploit Defeats Apple ‘BlastDoor’ Sandbox

Related: Apple Adds ‘BlastDoor’ to Secure iPhones From Zero-Click Attacks

 

Related: Secretive Israeli Exploit Company Behind Wave of Zero-Day Exploits

Written By

AFP 2023

Click to comment

Expert Insights

Related Content

Mobile & Wireless

Technical details published for an Arm Mali GPU flaw leading to arbitrary kernel code execution and root on Pixel 6.

Mobile & Wireless

Apple rolled out iOS 16.3 and macOS Ventura 13.2 to cover serious security vulnerabilities.

Mobile & Wireless

Apple’s iOS 12.5.7 update patches CVE-2022-42856, an actively exploited vulnerability, in old iPhones and iPads.

Mobile & Wireless

Two vulnerabilities in Samsung’s Galaxy Store that could be exploited to install applications or execute JavaScript code by launching a web page.

Cybercrime

The FBI dismantled the network of the prolific Hive ransomware gang and seized infrastructure in Los Angeles that was used for the operation.

Ransomware

The Hive ransomware website has been seized as part of an operation that involved law enforcement in 10 countries.

Cybercrime

A digital ad fraud scheme dubbed "VastFlux" spoofed over 1,700 apps and peaked at 12 billion ad requests per day before being shut down.

Mobile & Wireless

South Dakota Gov. Kristi Noem says her personal cell phone was hacked and linked it to the release of documents by the January 6...