the tech buzz

SUBSCRIBE
AIEnterpriseDealsSecurityCrypto
Newsletter

the tech buzz

Your premier source for technology news, insights, and analysis. Covering the latest in AI, startups, cybersecurity, and innovation.

FOLLOW US

THE DAILY

Get the latest technology updates delivered straight to your inbox.

Company

  • About Us
  • Editorial Team
  • Write For Usnew
  • Contact Us
  • Advertisenew

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Disclaimer
  • EULA
  • AI Code of Conduct

Resources

  • Newsletters
  • RSS Feeds
  • Subscribe
  • Pricing & Packages
  • Sitemap
  • Archives
  • TechBuzz Pressnew

PUBLISH WITH US

Reach 1.1M+ subscribers via TechBuzz Press.

TechBuzz Press

HAVE A TIP?

Send us a tip using our anonymous form.

Send a tip

HAVE QUESTIONS?

Reach out to us on any subject.

Ask Now

Browse by Category

AIBlockchainCloudSecurityDataDealsInvestmentsEnterpriseVenturesIoTMobileRoboticsSoftwareStartupsAppleMetaMicrosoftOpenAiGoogleTesla

© 2026 The Tech Buzz. All rights reserved.

the tech buzz

Surveillance Tech Provider Protei Hacked, Data Stolen

ArticlesNewsletters
ArticlesNewsletters
cybersecurity/SORM

Surveillance Tech Provider Protei Hacked, Data Stolen

Russian telecom surveillance company Protei was breached, website defaced

by The Tech Buzz

PUBLISHED: Mon, Nov 17, 2025, 1:38 PM UTC | UPDATED: Fri, Sep 4, 2026, 7:18 AM UTC

Add as a preferred source on Google
Surveillance Tech Provider Protei Hacked, Data Stolen

A Russian telecom company that develops surveillance technology for phone and internet providers was hacked, with attackers stealing 182 gigabytes of data and defacing its website. The breach targeted Protei, a company that sells deep packet inspection systems and censorship tools to governments across dozens of countries including Bahrain, Italy, Kazakhstan, Mexico, and Pakistan.

The hack of Protei represents a significant breach in the surveillance technology sector, exposing the inner workings of a company that helps governments monitor and censor their citizens' communications. The Jordan-headquartered firm, originally founded in Russia, found itself on the receiving end of the very digital intrusion tactics its technology enables.

The attack came to light when hackers defaced Protei's website on November 8, according to archived copies on the Wayback Machine. The defacement message - "another DPI/SORM provider bites the dust" - wasn't random vandalism but a pointed reference to the company's core business selling deep packet inspection systems and surveillance equipment.

Protei operates in a controversial corner of the telecom industry, providing governments with the tools to monitor and control internet traffic. The company's client list spans dozens of countries across central Africa, the Middle East, and beyond, where its technology helps authorities intercept calls, text messages, and web browsing data from telecom networks.

The breach netted attackers around 182 gigabytes of sensitive files from Protei's web servers, including years worth of internal emails that could reveal client relationships and business practices. This trove of data has since been provided to DDoSecrets, a transparency collective that specializes in making leaked datasets available for public interest research.

Advertisement

Protei's technology centers around SORM, Russia's lawful intercept system that has been exported to multiple countries seeking to monitor their populations. Phone and internet providers install SORM equipment directly on their networks, creating backdoors that allow government agencies to access the complete digital communications of any customer.

The company's deep packet inspection devices go beyond simple monitoring - they can identify specific types of web traffic, from social media platforms to messaging apps, and selectively block access. This capability makes Protei's systems particularly valuable to authoritarian governments seeking to control information flow and suppress dissent.

Citizen Lab's 2023 research revealed how Iranian telecom giant Ariantel consulted with Protei about implementing traffic logging and website blocking capabilities. Internal documents showed Protei promoting its technology's ability to restrict internet access for specific individuals or entire population segments.

The timing of this breach is particularly significant given increasing global scrutiny of surveillance technology exports and their role in human rights abuses. Companies like Protei operate in a gray area where telecommunications infrastructure meets government surveillance, often with limited oversight or accountability.

Advertisement

Mohammad Jalal, managing director of Protei's Jordan operations, hasn't responded to requests for comment about the breach. The company's silence raises questions about how it plans to address the security failure and protect client information that may have been compromised.

The hacker's identity and motivations remain unknown, but the targeted nature of the attack and the pointed defacement message suggest someone with specific knowledge of Protei's business model. The phrase referencing "DPI/SORM providers" indicates the attacker understood exactly what kind of company they were targeting.

This breach joins a growing list of cybersecurity incidents affecting surveillance technology providers, highlighting the irony of companies that help governments spy on citizens becoming victims of digital intrusion themselves. As governments worldwide grapple with balancing security needs and privacy rights, incidents like this expose the vulnerabilities inherent in building surveillance infrastructure.

The Protei breach exposes the fragile security posture of companies that build surveillance infrastructure for governments worldwide. While the full impact of the stolen 182GB of data remains to be seen, this incident underscores how surveillance technology providers can become targets themselves, potentially compromising not just their own operations but the sensitive government relationships they've built. As digital rights advocates gain access to internal communications through leaks like this, the surveillance industry may face increased scrutiny over its role in enabling authoritarian control of internet communications.

More Topics:
SORMdeep packet inspection

Advertisement

Advertisement

Trending Now

1

GoPro CEO Vows Cameras Stay Core After Starman Deal

2

Judge Splits Ruling in X vs. Twitter Rival Fight

3

Tim Cook Steps Down, Ternus Takes Apple's Helm

4

Google's Lyria 3.5 Brings AI Music to Gemini

5

Google Translate Gets Listening Mode, Live Background Mode

People Also Ask

Protei is a Russian surveillance technology company that sells deep packet inspection systems and SORM lawful intercept equipment to governments in dozens of countries including Bahrain, Italy, Kazakhstan, Mexico, and Pakistan for monitoring citizens' communications.

Hackers stole 182 gigabytes of sensitive data from Protei's web servers, including years of internal emails that could reveal client relationships and business practices. The data was provided to transparency collective DDoSecrets.

Protei's website was defaced on November 8, with hackers leaving the message 'another DPI/SORM provider bites the dust' referencing the company's surveillance technology business model and deep packet inspection systems.

Protei's surveillance technology is used by governments across dozens of countries in central Africa, the Middle East, and beyond, including Bahrain, Italy, Kazakhstan, Mexico, Pakistan, and Iran for monitoring and censoring communications.

SORM creates backdoors installed directly on telecom networks that allow government agencies to intercept calls, text messages, and web browsing data. The technology can also selectively block access to specific platforms and messaging apps.

The 182GB of stolen Protei data was provided to DDoSecrets, a transparency collective that specializes in making leaked datasets available for public interest research and exposing surveillance industry practices.

More in cybersecurity

How To Prevent Account Takeover?

How To Prevent Account Takeover?

Coupang CEO Resigns After 34M Customer Data Breach

Coupang CEO Resigns After 34M Customer Data Breach

Petco Data Breach Exposes SSNs, Driver's Licenses in Major Leak

Petco Data Breach Exposes SSNs, Driver's Licenses in Major Leak

Petco Data Breach Exposes Customer Info in App Config Error

Petco Data Breach Exposes Customer Info in App Config Error

Marquis Ransomware Attack Hits 400K+ Bank Customers

Marquis Ransomware Attack Hits 400K+ Bank Customers

Okta beats Q3 earnings as AI agent push drives growth

Okta beats Q3 earnings as AI agent push drives growth

More Articles

Mixpanel Data Breach Exposes Millions, OpenAI Cuts Ties

Mixpanel Data Breach Exposes Millions, OpenAI Cuts Ties

Dec 2

Coupang Data Breach Hits 34M Users in Months-Long Attack

Coupang Data Breach Hits 34M Users in Months-Long Attack

Dec 1

London Councils Hit by Major Cyberattack, Emergency Plans Activated

London Councils Hit by Major Cyberattack, Emergency Plans Activated

Nov 26

Tyler Technologies jury system bug exposed juror data across US

Tyler Technologies jury system bug exposed juror data across US

Nov 26

Major Banks Assess Data Theft After SitusAMC Breach

Major Banks Assess Data Theft After SitusAMC Breach

Nov 24

Corporate America ditches passwords as 92% of CISOs go passwordless

Corporate America ditches passwords as 92% of CISOs go passwordless

Nov 23