Ein Smartphone mit Symbolen für Kundendaten steht neben einem rot leuchtenden externen Server in einem Zürcher Büro.
JournalPlus / KI-generiertes Symbolbild
Technology10:00 UhrJournalPlus RedaktionReading time: 4 min0 comments

Possible Salt Data Leak: The Real Risk Begins Afterwards

Salt reports no known intrusion into its core systems, but identifies misuse of access to a secondary system. What is confirmed, what remains unclear, and how customers should react.

The most important information so far regarding the possible data leak at Salt is also its biggest limitation: The case is not yet fully clarified. The telecom company informed customers that, following claims appearing on the internet, it found no intrusion into its own systems. However, misuse of existing access to a secondary system was identified.

Therefore, it is neither proven that all alleged data sets are genuine, nor is the incident harmless. According to currently available information, names, postal addresses, phone numbers, and birth dates could be affected. How many individuals are impacted, who operates the secondary system, how long the access was misused, and whether data truly flowed out completely, remains publicly unknown.

Why "Only Master Data" Is Not Reassuring

The mentioned details are not passwords. However, they can make fraud attempts more credible. Someone knowing a name, residential address, phone number, and birth date can craft a message that appears to be a genuine Salt communication, a package notification, or a bank call. The Bundesamt für Cybersicherheit (Federal Office for Cybersecurity) warns that stolen personal information can be used for phishing, account takeovers, identity theft, or financial fraud years later.

The concrete risk therefore lies less in an immediate debit than in the combination of data: A known phone number facilitates smishing via SMS, a birth date can be misused in poorly protected verification processes, and a correct address increases credibility. This does not imply that such misuse has already been observed at Salt. However, it explains why affected individuals should be particularly vigilant in the coming months.

Eine Person prüft eine verdächtige Nachricht auf dem Smartphone; ein Laptop zeigt Symbole für Kontoschutz und Zwei-Faktor-Authentifizierung.
Nach einem Datenabfluss steigt vor allem das Risiko glaubwürdig personalisierter Phishing-Nachrichten. · JournalPlus / KI-generiertes Symbolbild

What Customers Should Do Now

Unexpected messages should not be opened via embedded links. Anyone receiving an invoice, a threat of service suspension, or a request for "verification" should access their customer account via the manually entered address salt.ch or the official app. Codes from SMS or authenticator apps should never be shared in a chat or with an alleged support employee.

A precautionary password change is particularly advisable if the same password is used for multiple services. For email accounts, a unique password with two-factor authentication is crucial, as many other accounts can be reset through it. Customers should also check Salt invoices and notifications about SIM or eSIM changes. In case of an unexpected network outage or an unknown SIM activation, the provider should be contacted directly through an official channel.

Anyone who has already entered bank or credit card details on a linked page must immediately contact their financial institution. Suspicious messages can be reported to the Bundesamt für Cybersicherheit (Federal Office for Cybersecurity). A police report is advisable if financial damage or concrete identity theft has occurred.

What Obligations the Data Protection Act Sets

Swiss data protection law distinguishes between a security breach and the obligation to report it. Those responsible must report a breach to the Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (Federal Data Protection and Information Commissioner) as quickly as possible if it is likely to result in a high risk to personal rights or fundamental freedoms. A commissioned service provider, in turn, must report an incident to the responsible company as quickly as possible.

Affected individuals must be informed if this is necessary for their protection or if the Data Protection Commissioner requests it. Whether the threshold of a «high risk» is met depends not only on the number of data sets but also on their nature, combination, potential misuse, and the protective measures taken. Based solely on the customer information, it cannot be inferred whether Salt has submitted a report to the EDÖB.

The Open Questions Are Verifiable

A robust investigation requires more than just the term «secondary system». Salt should disclose which categories of data were actually affected, how many individuals were notified, whether an external data processor was involved, and which access rights were changed. Equally relevant is whether the data in question was merely claimed online or technically verified.

Until these points are answered, it would be incorrect to speak of a confirmed breach of Salt's core systems. It would also be wrong to dismiss master data as trivial. The reasonable middle ground is sober: no panic, no unverified links – and heightened vigilance, especially when a message contains an astonishing amount of personal details.

Sources

Share article

Report an error in this article

Thanks for the tip. Please describe the error as precisely as possible.

PNG, JPG or WebP, max. 5 MB

Comments

Sign in to join the discussion.

No comments yet. Be the first to write one.