Surveillance Tech Provider Protei Was Hacked, Its Data Stolen And Its Website Defaced

Trending 1 day ago
flashing LEDs connected a bunch of cables successful a darkened datacenterImage Credits:Artem Bruk / Getty Images

5:09 AM PST · November 17, 2025

A Russian telecom institution that develops exertion to let telephone and net companies to behaviour web surveillance and censorship was hacked, had its website defaced, and had information stolen from its servers, TechCrunch has learned.

Founded successful Russia, Protei makes telecommunications systems for telephone and net providers crossed dozens of countries, including Bahrain, Italy, Kazakhstan, Mexico, Pakistan and overmuch of cardinal Africa. The company, now headquartered successful Jordan, sells video conferencing exertion and net connectivity solutions, arsenic good arsenic surveillance instrumentality and web-filtering products, specified arsenic heavy packet inspection systems.

It’s not clear precisely erstwhile aliases really Protei was hacked, but a copy of nan company’s website saved connected nan Internet Archive’s Wayback Machine shows it was defaced connected November 8. The website was restored soon after.

During nan breach, nan hacker obtained nan contents of Protei’s web server — astir 182 gigabytes of files — including emails making love backmost years.

A transcript of Protei’s information was provided to DDoSecrets, a non-profit transparency corporate that indexes leaked datasets successful nan nationalist interest, including information from rule enforcement, authorities agencies, and companies progressive successful nan surveillance industry.

a screenshot of Protei's hacked website and defacementImage Credits:TechCrunch (screenshot)

Mohammad Jalal, nan managing head of Protei’s branch successful Jordan, did not respond to a petition for remark astir nan breach. 

The personality of nan hacker is not known, nor their motivations, but nan defaced website read: “another DPI/SORM supplier bites nan dust.” The connection apt references nan company’s income of heavy packet inspection systems and different net filtering exertion for nan Russian-developed lawful intercept strategy known arsenic SORM.

SORM is nan main lawful intercept strategy utilized crossed Russia arsenic good arsenic several different countries which usage Russian technology. Phone and net providers instal SORM instrumentality connected their networks, which allows their country’s governments to get nan contents of calls, matter messages and web browsing information of nan networks’ customers. 

Deep-packet inspection devices let telecom companies to place and select web postulation depending connected its source, specified arsenic a societal media website aliases a circumstantial messaging app, and selectively artifact access. These systems are utilized for surveillance and censorship successful regions wherever state of reside and look are limited.

Citizen Lab reported successful 2023 that Iranian telecoms elephantine Ariantel had consulted pinch Protei astir exertion for logging net postulation and blocking entree to definite websites. Documents seen and published by Citizen Lab show that Protei touted its technology’s expertise to restrict aliases artifact entree to websites for circumstantial group aliases full swathes of nan population.

Zack Whittaker is nan information editor astatine TechCrunch. He besides authors nan play cybersecurity newsletter, this week successful security.

He tin beryllium reached via encrypted connection astatine zackwhittaker.1337 connected Signal. You tin besides interaction him by email, aliases to verify outreach, astatine zack.whittaker@techcrunch.com.

More