Columbia University Discovers Cisco Phone Hack

By

There’s new cause for companies to be worried about their network safety, user privileges and laissez-faire BYOD policies. At the Chaos Communications conference December 29, it was revealed that Cisco phones are vulnerable to eavesdropping hacks. 

The vulnerability was discovered by doctoral candidate Ang Cui and Professor Sal Stolfo of Columbia University while they were working on a grant from the U.S. Defense Department.

Professor Stolfo warned, “On the dark side, these phones are sold worldwide. Any government that would like to peer into the private lives of citizens could use this.” 

He called it a “great opportunity to create a low-cost surveillance system that is already deployed.”

Cui demonstrated the hack for NBC News, revealing that in a matter of seconds, a small device pre-loaded with software could be plugged into a port on the phone and rewrite its IP software. This vulnerability exists because the phones make routine connections with a central server looking for updated instructions.

According to Bob Sullivan of NBC News, Cisco listed 15 phone models impacted by the threat in an announcement sent to their customers in December. Despite the implications of this announcement, Cisco maintains that, with only a few exceptions, hackers would need physical access to a telephone in order to execute the attack.

The team at Columbia says that these “rare” exceptions are not as innocuous as Cisco might have consumers believe; an e-mail attachment with a virus could easily execute the attack. 

Cui said, “You could attack the network, and then attack a single person’s phone – say, the CEO, at home.”

This potential threat is a great reminder for all companies, not just those using the popular phone system, to keep their employees apprised of online safety. Companies should evaluate their user privileges, host regular employee training on network safety, and consider revising their BYOD policies to ensure that they are safe from outside attacks.




Edited by Braden Becker
Get stories like this delivered straight to your inbox. [Free eNews Subscription]

TechZone360 Contributor

SHARE THIS ARTICLE
Related Articles

Your Post-Quantum Readiness Starts at Y2Q Summit

By: TMCnet News    5/27/2026

Y2Q Summit is an executive conference focused on helping enterprises prepare for the coming era of quantum computing disruption, cybersecurity transfo…

Read More

Why Award Marketing Should Be Part of Every B2B Tech Company's Growth Strategy

By: Erik Linask    5/20/2026

Award marketing matters for B2B tech companies because industry recognition can strengthen trust, support sales and partner relationships, improve con…

Read More

Why Email Is Still the Most Underrated Layer of Modern Software Infrastructure

By: Contributing Writer    5/15/2026

Take, for example, the following scenario. A user requests a password reset, waits a few seconds, refreshes their inbox and nothing arrives. They try …

Read More

Jitterbit's Visionary Status Signals a Shift in the iPaaS Market

By: Contributing Writer    4/7/2026

As enterprise ecosystems grow more complex, integration has become less of a backend IT function and more of a strategic driver of business performanc…

Read More

Cyber Extortion over hoax Breach: Lessons from a Fabricated story about IDMERIT

By: Contributing Writer    3/3/2026

Cybercriminals are increasingly staging fake data breaches to launch extortion attempts against KYC-AML companies. Recently, hackers devised a new met…

Read More