The Cybernews research team uncovered that MagentaTV, Deutsche Telekom’s TV and streaming platform, exposed over 324 million log entries — totaling 729GB of data — via an ad delivery platform. MagentaTV is estimated to have around 4.4 million users.
Researchers also claim that the exposed instance received new log entries every day, with anywhere from 4 to 18 million logs being added daily.
Moreover, the team believes that the instance was publicly accessible at least since early February 2025, with the company removing it from public view after our team contacted them in June.
What details did the MagentaTV leak?
While the majority of the information accessible via the exposed instance could be considered non-sensitive, some of the leaked logs contained HTTP headers from requests sent by MagentaTV customers.
According to the researchers, some user data was also exposed in the leak, including:
- IP addresses
- MAC addresses
- Session IDs
- Customer IDs
- User agents
Potential risks for users
Attackers could potentially utilize leaked data to track user locations, identify them, and direct targeted attacks against specific devices.
Additionally, customers may face additional risks if attackers cross-reference the leaked data with older breaches, especially using IP addresses to identify users.
To read the full research report, please click here.
Related
This entry was posted on August 6, 2025 at 9:11 am and is filed under Commentary with tags Cybernews. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Deutsche Telekom‘s streaming service MagentaTV leaks over 324 million log entries
The Cybernews research team uncovered that MagentaTV, Deutsche Telekom’s TV and streaming platform, exposed over 324 million log entries — totaling 729GB of data — via an ad delivery platform. MagentaTV is estimated to have around 4.4 million users.
Researchers also claim that the exposed instance received new log entries every day, with anywhere from 4 to 18 million logs being added daily.
Moreover, the team believes that the instance was publicly accessible at least since early February 2025, with the company removing it from public view after our team contacted them in June.
What details did the MagentaTV leak?
While the majority of the information accessible via the exposed instance could be considered non-sensitive, some of the leaked logs contained HTTP headers from requests sent by MagentaTV customers.
According to the researchers, some user data was also exposed in the leak, including:
Potential risks for users
Attackers could potentially utilize leaked data to track user locations, identify them, and direct targeted attacks against specific devices.
Additionally, customers may face additional risks if attackers cross-reference the leaked data with older breaches, especially using IP addresses to identify users.
To read the full research report, please click here.
Share this:
Like this:
Related
This entry was posted on August 6, 2025 at 9:11 am and is filed under Commentary with tags Cybernews. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.