Chema Alonso
This article has multiple issues. Please help improve it or discuss these issues on the talk page. (Learn how and when to remove these messages)
|
Chema Alonso | |
|---|---|
Alonso speaking at a cyberâsecurity conference (2019) | |
| Born | JosĂ© MarĂa Alonso CebriĂĄn 1975 (age 49–50) Madrid, Spain |
| Alma mater | Polytechnic University of Madrid (B.Eng.) Rey Juan Carlos University (M.Sc., Ph.D.) |
| Occupations | Computerâsecurity researcher; technology executive |
| Known for | ElevenPaths; FOCA metadata tool; Latch app; Cloudflare executive |
| Awards | Civil Guard Cross of Merit (2017); Forbes Worldâs 50 Most Influential CMOs (2022) |
| Website | elladodelmal |
JosĂ© MarĂa "Chema" Alonso CebriĂĄn (born 1975) is a Spanish computerâsecurity researcher and technology executive. He founded TelefĂłnicaâs cyberâsecurity unit ElevenPaths in 2013 and later served on the executive committee of TelefĂłnica as Chief Data Officer and Chief Digital Officer (2016â2025).[1][2]
In August 2025 he joined Cloudflare as Vice President, Head of International Development.[3][4] Alonso is a frequent speaker at international security conferences (including Black Hat, DEF CON and Troopers) and is associated with research and tools such as the FOCA metadataâanalysis suite, the Latch âdigital padlockâ app, and work on connectionâstring parameter pollution.[5][6][7]
Early life and education
[edit]Alonso was born in 1975 and grew up in MĂłstoles, in Spainâs Community of Madrid.[8][9] He holds a B.Eng. in Computer Systems Engineering from the Polytechnic University of Madrid and an M.Sc./Ph.D. in Computer Security from the Rey Juan Carlos University.[10][11]
Career
[edit]InformĂĄtica 64 and ElevenPaths (1999â2016)
[edit]In June 2013 TelefĂłnica created the cyberâsecurity unit ElevenPaths and appointed Alonso as its chief executive; the new unit drew staff from his earlier consultancy InformĂĄtica 64.[12][13] At ElevenPaths he increased awareness about tools and products such as the FOCA (Fingerprinting Organizations with Collected Archives) metadataâanalysis suite,[14] and Latch, a mobile âdigital padlockâ that lets users toggle access to online services.[15]
TelefĂłnica executive roles (2016â2025)
[edit]Alonso joined TelefĂłnicaâs executive committee in 2016 as Chief Data Officer, later serving as Chief Digital Consumer Officer and then Chief Digital Officer.[16] In this period he spoke publicly about returning control of personal data to users and TelefĂłnicaâs âfourth platformâ.[17] From 2023, he was a prominent executive voice around the GSMA Open Gateway programme, which exposes standardised network APIs; TelefĂłnica and the GSMA announced deployments and partnerships during MWC Barcelona.[18][19]
TelefĂłnica was among the first large companies affected when the WannaCry ransomware attack began on 12 May 2017.[20]
Cloudflare (2025âpresent) and CTA episode
[edit]In August 2025 Alonso joined Cloudflare as Vice President, Head of International Development.[21][22] The move was followed by his resignation, after two weeks, from an advisory role on artificial intelligence at Spainâs Technical Committee of Referees (CTA).[23]
Research and selected projects
[edit]- DirtyTooth (2017): coâdisclosure of a Bluetooth issue affecting iOS whereby a paired speaker could switch from A2DP to PBAP and exfiltrate contacts without user awareness; presented at ToorCon 19.[24][25]
- RansomCloud (2017â2018): a proofâofâconcept demonstrating how a rogue OAuth application could encrypt email in cloud services such as Office 365 in real time; later popularised in demos with Kevin Mitnick.[26]
Selected conference talks and papers
[edit]| Year | Conference | Talk / paper | Reference |
|---|---|---|---|
| 2008 | DEF CON 16 | TimeâBased Blind SQL Injection Using Heavy Queries | "DEF CON 16 slide deck" (PDF). Retrieved 1 November 2025. |
| 2008 | Black Hat Europe | Blind LDAP Injection | "Black Hat Europe 2008 â speakers". Retrieved 1 November 2025. |
| 2009 | DEF CON 17 | Tactical Fingerprinting Using Metadata, Hidden Info and Lost Data | "DEF CON 17 â Tactical Fingerprinting slide deck" (PDF). Retrieved 1 November 2025. |
| 2009 | ShmooCon | ReâPlaying with (Blind) SQL Injection | "ShmooCon 2009 talk (video)". YouTube. 20 May 2014. Retrieved 1 November 2025. |
| 2010 | Troopers 10 | Parameter Pollution in Connection Strings Attack | "Troopers archive â speaker page". Retrieved 1 November 2025. |
| 2010 | Black Hat DC | Connection String Parameter Pollution (CSPP) | "Black Hat DC 2010 white paper" (PDF). Retrieved 1 November 2025. "Researchers reveal connectionâstring pollution attack". Dark Reading. 20 January 2010. Retrieved 1 November 2025. |
| 2010 | DEF CON 18 | FOCA 2: The FOCA Strikes Back | "DEF CON 18 white paper" (PDF). Retrieved 1 November 2025. |
| 2012 | DEF CON 20 | Owning Bad Guys {And Mafia} with JavaScript Botnets | "DEF CON 20 paper â Owning Bad Guys Using JavaScript Botnet" (PDF). Retrieved 1 November 2025. |
| 2012 | Black Hat USA | Owning Bad Guys {And Mafia} with JavaScript Botnets | "Black Hat USA 2012 â talk (video)". YouTube. 18 May 2014. Retrieved 1 November 2025. |
| 2013 | DEF CON 21 | Fear the Evil FOCA: IPv6 Attacks in Internet Connections | "DEF CON 21 â speakers". Retrieved 1 November 2025. |
| 2014 | Troopers 14 | How I Latch on Me and Protect My Digital Life against Passwords | "Troopers 14 talk (video)". YouTube. 29 April 2014. Retrieved 1 November 2025. |
| 2017 | ToorCon 19 | DirtyTooth: Put Music & Lose Your Contacts | "ToorCon 19 â DirtyTooth session". Retrieved 1 November 2025. |
| 2021 | HITB CyberWeek | Gremlin Apps & Gremlin Botnets | "HITB CyberWeek 2021 (video)". YouTube. January 2022. Retrieved 1 November 2025. |
Media
[edit]Alonso has appeared frequently in Spanishâlanguage media to explain cyberâsecurity topics, including demonstrations on the TV show El Hormiguero.[27] He also hosted the 12âepisode web series Risk Alert (Atresmedia/Flooxer, 2018).[28]
Awards and honours
[edit]- Civil Guard Cross of Merit (Distintivo Blanco, 2017).[29]
- Doctor honoris causa, Rey Juan Carlos University (2020).[30]
- #16 on Forbes Worldâs 50 Most Influential CMOs list (2022).[31]
See also
[edit]References
[edit]- ^ Scott, Jennifer (10 June 2013). "Telefonica Digital forms security group Eleven Paths". Computer Weekly. Retrieved 1 November 2025.
- ^ "Chema Alonso â TelefĂłnica author page". TelefĂłnica. 4 May 2023. Retrieved 1 November 2025.
- ^ "Former TelefĂłnica data chief Alonso named Cloudflare VP". Telecompaper. 8 August 2025. Retrieved 1 November 2025.
- ^ Muñoz, RamĂłn (7 August 2025). "Chema Alonso desata un conflicto en el fĂștbol tras fichar por el "pirata" enemigo de LaLiga". El PaĂs (in Spanish). Retrieved 1 November 2025.
- ^ Higgins, Kelly Jackson (30 June 2009). "'FOCA' and the power of metadata analysis". Dark Reading. Retrieved 1 November 2025.
- ^ Gibbs, Samuel (26 February 2014). "Lock up your digital valuables with Latch, the digital padlock". The Guardian. Retrieved 1 November 2025.
- ^ "Connection String Parameter Pollution â white paper" (PDF). Black Hat DC 2010. Retrieved 1 November 2025.
- ^ "Chema Alonso, doctor honoris causa por la URJC". Cadena SER (in Spanish). 28 January 2020. Retrieved 1 November 2025.
- ^ "La URJC inviste doctor honoris causa a Chema Alonso" (in Spanish). Universidad Rey Juan Carlos. 28 January 2020. Retrieved 1 November 2025.
- ^ "Chema Alonso â speaker profile". MWC Barcelona. Retrieved 1 November 2025.
- ^ "La URJC inviste doctor honoris causa a Chema Alonso" (in Spanish). Universidad Rey Juan Carlos. 28 January 2020. Retrieved 1 November 2025.
- ^ "Telefónica y el «hacker» Chema Alonso lanzan la empresa de ciberseguridad Eleven Paths". ABC (in Spanish). 7 June 2013. Retrieved 1 November 2025.
- ^ Scott, Jennifer (10 June 2013). "Telefonica Digital forms security group Eleven Paths". Computer Weekly. Retrieved 1 November 2025.
- ^ Higgins, Kelly Jackson (30 June 2009). "'FOCA' and the power of metadata analysis". Dark Reading. Retrieved 1 November 2025.
- ^ Gibbs, Samuel (26 February 2014). "Lock up your digital valuables with Latch, the digital padlock". The Guardian. Retrieved 1 November 2025.
- ^ "Chema Alonso â TelefĂłnica author page". TelefĂłnica. 4 May 2023. Retrieved 1 November 2025.
- ^ "Take back your data: how TelefĂłnica is on a quest to return our information". Wired. 5 November 2016. Retrieved 1 November 2025.
- ^ "TelefĂłnica accelerates global rollout of Open Gateway with agreements with tech firms and companies from around the world" (Press release). TelefĂłnica. 3 March 2025. Retrieved 1 November 2025.
- ^ "Mobile industry deploys open network APIs and prepares for mass adoption" (Press release). GSMA. 27 February 2023. Retrieved 1 November 2025.
- ^ "A massive cyberattack using leaked NSA exploits has hit companies around the world". Business Insider. 12 May 2017. Retrieved 1 November 2025.
- ^ "Former TelefĂłnica data chief Alonso named Cloudflare VP". Telecompaper. 8 August 2025. Retrieved 1 November 2025.
- ^ "Chema Alonso se marcha del CTA". AS (in Spanish). 7 August 2025. Retrieved 1 November 2025.
- ^ Muñoz, RamĂłn (7 August 2025). "Chema Alonso desata un conflicto en el fĂștbol tras fichar por el "pirata" enemigo de LaLiga". El PaĂs (in Spanish). Retrieved 1 November 2025.
- ^ "DirtyTooth: extracting vCard data from Bluetooth iOS profiles" (PDF). Exploit-DB. Retrieved 1 November 2025.
- ^ "DirtyTooth: Put Music & Lose Your Contacts (ToorCon 19)". InfoConDB. Retrieved 1 November 2025.
- ^ "Ransomcloud demo with Kevin Mitnick". Datto. 29 October 2018. Retrieved 1 November 2025.
- ^ "Chema Alonso: "Hay que diferenciar entre hackers y cibercriminales"". Antena 3 (in Spanish). 18 February 2014. Retrieved 1 November 2025.
- ^ "Risk Alert â complete series". Atresplayer (in Spanish). 12 July 2018. Retrieved 1 November 2025.
- ^ "La Guardia Civil condecora a Chema Alonso, el 'hacker' de TelefĂłnica". 20minutos (in Spanish). 19 May 2017. Retrieved 1 November 2025.
- ^ "La URJC inviste doctor honoris causa a Chema Alonso" (in Spanish). Universidad Rey Juan Carlos. 28 January 2020. Retrieved 1 November 2025.
- ^ Matlins, Seth (23 June 2022). "The Forbes World's Most Influential CMOs List: 2022". Forbes. Retrieved 1 November 2025.