HomeIntelligenceBrief
BREACH BRIEF 🟠 High Breach

Norwegian Authorities Investigate Telenor for Supplying 18 Million Myanmar Customers’ Data to Military Regime

Norwegian police and security services are probing Telenor for handing over historic traffic data on more than 18 million Myanmar users to the junta that seized power in 2021. The case highlights gaps in third‑party oversight and data‑handling controls that continuous assurance programs must address.

Verisq™ Intelligence · 📅 September 16, 2026 · 📰 therecord.media
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
therecord.media

Norway Investigations Reveal Telenor Handed Over 18 Million Myanmar Customers’ Data to Military Regime

What Happened — Norwegian law‑enforcement agencies announced investigations into whether Telenor supplied historic traffic data on more than 18 million Myanmar customers to the military junta that seized power in February 2021. The probes cover the period from the coup until Telenor sold its Myanmar unit in March 2022 and also examine possible sanctions violations linked to the sale of surveillance equipment.

Why It Matters for Trust & Control Assurance

  • This scenario exemplifies a failure to enforce third‑party oversight and data‑handling controls that continuous assurance programs are built to detect and document.
  • Without auditable evidence of due‑diligence and real‑time monitoring of partner activities, organizations risk legal exposure, sanctions, and reputational damage.
  • A robust vendor‑risk management capability provides the defensible audit trail needed to demonstrate responsible stewardship of customer data across borders.

Who Is Affected — Telecommunications providers, multinational enterprises operating in politically unstable regions, and any organization that outsources network services to third parties.

Recommended Actions

  • Map the incident to your third‑party risk‑management controls and verify that evidence of data‑sharing approvals, sanctions checks, and human‑rights due‑diligence is collected.
  • Initiate a focused audit of historic data‑transfer logs for all high‑risk vendors and remediate any undocumented disclosures.
  • Update contracts to include explicit clauses on lawful data handling, sanctions compliance, and mandatory reporting of government data‑request incidents.

Technical Notes — The alleged data hand‑over involved historical call‑detail records (CDRs) spanning 2021‑2022; no specific software vulnerability was cited. The investigation also targets the transfer of sanctioned surveillance hardware sold without foreign‑ministry approval. Source: The Record

📰 Original Source
https://therecord.media/norway-investigations-telenor-telecom-myanmar-regime

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →