French submarines spring a security leak

Investigations underway to find out how secret details of operating capabilities were leaked

More than 22,000 pages of secret operating documents for Indian submarines have been leaked, prompting concerns over the security of the vessels and questions about how such a massive data breach could have happened.

The French Scorpene submarines are being built in a state-run shipyard in Mumbai for the Indian navy, with the first vessel expected to be in service by the end of this year, according to Reuters. However, it is thought the 22,400 documents involved were in fact stolen in 2011.

Advertisement - Article continues below

In a statement to the press, Indian defence minister Manohar Parrikar said: "I understand there has been a case of hacking ... we will find out what happened."

In an additional statement, the Indian Defence Ministry said: "The available information is being examined ... and an analysis is being carried out by the concerned specialists. It appears the source of the leak is from overseas and not in India."

A spokeswoman for DCNS, which is building the six submarines and 35% owned by technology and engineering giant Thales, said that "for now [DCNS doesn't] know if the information is correct".

Reuters added that the level of detail in the documents "creates a major strategic problem for India, Malaysia and Chile", which, according to a source, operate the same model of submarine.

Advertisement
Advertisement - Article continues below

"It's a huge deal ... it allows them to understand everything about the submarines. What speeds it can do; how noisy it is; what speeds the mast can be raised at ... all of that is just devastating," the source told Reuters.

Advertisement - Article continues below

Speaking to IT Pro, Bola Rotibi, research director at analyst house Creative Intellect, said: "That this happened in 2011 goes to show how insecure things were at that time. It's only in the last three or four years that people have really started to double down on security."

The incident, Rotibi said, could be the result of "good old fashioned spying" by a nation-state, but equally it could be "more Machiavellian" industrial espionage-cum-sabotage, particularly as the details of the documents were released. Indeed, this is an allegation hinted at by DCNS.

"The competition is more and more hard and all means can be used in thei context," the company's spokeswoman told Reuters.

"There is [this breach news from] India, [so] Australia and other countries could raise legitimate questions over DCNS. It's part of the tools in economic war," she added.

For Rotibi, however, apportioning blame is less important than preparing for and dealing with breaches.

Advertisement - Article continues below

"Breaches can happen at any level, whether governmental or business," she said. "This case just reinforces two things we have seen over and again in our own research: the need for thorough screening of employees and contractors, to protect against insider threats, and for organisations to have processes in place to prevent, detect and remediate breaches."

Main image credit: Tunku Abdul Rahman, cc license 3

Advertisement

Recommended

Visit/security/data-breaches/355056/vpnmentors-web-mapping-project-finds-more-exposed-military-files-via
data breaches

Printing company exposes 343GB of sensitive military data

20 Mar 2020
Visit/security/ddos/28039/how-to-protect-against-a-ddos-attack
Security

How to protect against a DDoS attack

25 Oct 2019
Visit/data-breaches/29418/equifax-data-breach-cost-14-billion-so-far
data breaches

Ex-Equifax CIO to serve four months for insider trading

2 Jul 2019

Most Popular

Visit/mobile/mobile-phones/355239/microsofts-patent-design-reveals-a-mobile-device-with-a-third-screen
Mobile Phones

Microsoft patents a mobile device with a third screen

6 Apr 2020
Visit/development/application-programming-interface-api/355192/apple-buys-dark-sky-weather-app-and-leaves
application programming interface (API)

Apple buys Dark Sky weather app and leaves Android users in the cold

1 Apr 2020
Visit/software/video-conferencing/355229/zoom-we-moved-too-fast
video conferencing

Zoom CEO admits company "moved too fast" as privacy issues mount

6 Apr 2020