2.7M phone calls to Swedish medical advice service laid open for anyone
computersweden.idg.se
computersweden.idg.se
The article contains a gold nugget in a partial interview with Davide Nyblom, the CEO of Medicall, the company responsible. When asked for comment by the magazine:
Davide Nyblom: "I've checked with our IT, what you're saying is not possible."
Reporter: "I have the files in front of me."
Davide Nyblom: "I've checked with our IT, and it can't happen".
Reporter: "Do you want me to play you one of the files?"
[hangs up the phone]
Some context: In Sweden, one can dial 1177 to receive medical advice for anything that isn't an urgent life and death situation. The trained medical staff at the 1177 call centers give advice at the best of their ability, or see to that the caller goes to an emergency room, schedules an appointment or even has an ambulance, when applicable.
Now, some of these calls apparently get routed to an off-shore operation in Thailand, were Swedish expat staff help out during off hours and such.
The publication Computer Sweden found that every call forwarded to this call center laid open for anyone with internet access to download or stream. All that was needed was a URL - there weren't even any password credentials needed.
All in all, 2.7 million calls were affected, from 2013 and up until the very moment Computer Sweden contacted the responsible company, and had them up their security.
I can't even start to fathom the vastness of this breach of integrity.
Apparently it is only calls from three län (administrative regions), but only because the others didn't use the service of the company in question.
The URL was apparently http://188.92.248.19:443/medicall/.