Nokia developer forum hacked and defaced in AntiSec attack
Nokia has issued a statement confirming that the security of its developer forum website was compromised by an attacker who successfully obtained a database table with user account information. Nokia has taken down its developer community site while it conducts further analysis. The attack exploited a SQL injection vulnerability in the website's forum software.
The statement issued by Nokia indicates that the attackers gained more account records than the company initially believed, but that the information was not particularly sensitive in nature. The breached data includes user e-mail addresses and public profile information, but apparently not passwords or password hashes.
Nokia says that only 7 percent of the forum users had supplied profile information, which may include instant messaging usernames and date of birth. The only material threat posed to individual users, according to Nokia, is unsolicited e-mail. The company apologized for the incident and sent out messages to inform users.