Bluesnarfing
Unauthorised access to data on a Bluetooth device, such as contacts, messages or the device identifier, by forcing a connection through firmware flaws found in some older devices.
Bluesnarfing is the theft of data from a Bluetooth device over the radio link, without the owner’s authorisation. NIST SP 800-121 Rev 2, Guide to Bluetooth Security, describes it as forcing a connection to the device by exploiting a firmware flaw in older devices, from around 2003, which gives access to the data stored on it. That data can include contacts, calendars and messages, and also the device’s IMEI (international mobile equipment identity), a unique identifier that could be misused to reroute the user’s calls.
Study sources commonly teach bluesnarfing with bluejacking and bluebugging. Bluejacking only sends messages; bluesnarfing reads and copies data, which is a breach of confidentiality; bluebugging goes further and uses the device’s own functions. Because bluesnarfing depends on specific firmware flaws, it is taught for recognition rather than as a picture of how current devices are attacked. The lasting controls still apply: keep device firmware updated, keep devices non-discoverable when they do not need to be found, and pair only with known devices.
Exam relevance: a scenario is likely to describe contacts or messages copied from a phone over Bluetooth without the user noticing. The word to match is data theft. Candidates are expected to separate it from bluejacking, where messages arrive but nothing is taken, and from bluebugging, where the attacker controls the device.