Un-carrier? Definitely Unsecure: T-Mobile US admits 48m customers' details stolen after downplaying reports
- Reference: 1629290223
- News link: https://www.theregister.co.uk/2021/08/18/t_mobile_us_admits_hack_48m_users/
- Source link:
In a statement the American mobile operator said: "Yesterday, we were able to verify that a subset of T-Mobile data had been accessed by unauthorized individuals. We also began coordination with law enforcement as our forensic investigation continued."
The story was broken earlier this week by US lifestyle magazine Vice's Motherboard tech offshoot, which [1]spoke to a criminal who posted on a dark web-hosted forum that he had access to 100 million people's data. Vice verified that at least some of the data looked genuine.
[2]
At the time, two days ago, T-Mobile [3]confirmed to The Register : "We have determined that unauthorized access to some T-Mobile data occurred, however we have not yet determined that there is any personal customer data involved."
[4]
[5]
Overnight, that position of "no personal data breached" became something much less concrete:
Our preliminary analysis is that approximately 7.8 million current T-Mobile postpaid customer accounts' information appears to be contained in the stolen files, as well as just over 40 million records of former or prospective customers who had previously applied for credit with T-Mobile.
In addition, around 850,000 PAYG customers have, so far, been confirmed by the mobile network operator to have had their names, numbers, and online account PINs compromised.
[6]Blackbaud – firm that paid off crooks after 2020 ransomware attack – fails to get California privacy law claim dropped
[7]T-Mobile US probes claims of 100m stolen customer records up for sale on dark web
[8]Singaporean telco leaked personal data of over 57,000 customers
[9]Das tut mir leid! Germany's ruling party sorry for calling cops on researcher after she outed canvassing app flaws
[10]'I am so TIRED of your bullsh*t...' Sprint boss flips lid at T-Mobile US CEO
"No Metro by T-Mobile, former Sprint prepaid, or Boost customers had their names or PINs exposed," said T-Mobile in its [11]statement .
Data stolen by criminals included customers' first and last names, date of birth, social security numbers, and "driver's license/ID information for a subset of current and former Postpay customers and prospective T-Mobile customers." Postpay is the American term for a standard mobile phone contract, contrasting with pre-paid/pay-as-you-go.
On the current direction of travel, readers might expect the number publicly confirmed by T-Mobile to slowly creep upwards, though the full 100 million would comprise about a third of the population of the United States.
[12]
No information was given by T-Mobile about the attackers' method of entry, though it claimed to have closed off their entry point.
People affected by the breach are being advised by the self-styled " [13]Un-carrier " to change their online PINs. Customers can also sign up for McAfee's ID theft protection service at T-Mobile's expense, the telco said.
While 100 million seems like a large number, it has been dwarfed by other breaches – most notably including [14]the compromise of three billion Yahoo ! accounts in 2017 . ®
Get our [15]Tech Resources
[1] https://www.vice.com/en/article/akg8wg/tmobile-investigating-customer-data-breach-100-million
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YR0uuTiGhmPLFCf@37QSpAAAAI8&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://www.theregister.com/2021/08/16/in_brief_security/
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YR0uuTiGhmPLFCf@37QSpAAAAI8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YR0uuTiGhmPLFCf@37QSpAAAAI8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2021/08/17/ccpa_blackbaud/
[7] https://www.theregister.com/2021/08/16/in_brief_security/
[8] https://www.theregister.com/2021/08/12/singapore_telecom_breach_leaked_personal/
[9] https://www.theregister.com/2021/08/05/germany_responsible_disclosure_cdu/
[10] https://www.theregister.com/2015/07/02/claure_snaps_over_legere/
[11] https://www.t-mobile.com/news/network/additional-information-regarding-2021-cyberattack-investigation
[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YR0uuTiGhmPLFCf@37QSpAAAAI8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[13] https://www.theregister.com/2020/06/15/tmobile_us_outage/
[14] https://www.theregister.com/2017/10/03/yahoo_says_one_beeelion_user_hack_figure_wrong_its_three/
[15] https://whitepapers.theregister.com/
Re: What's the problem?
Not sure how anyone can describe T-Mobile's pricing as "confusing" (at least, not compared with the other carriers).
Here's how it works: you buy a phone. They'll let you pay for it over 24 or so months with no interest as long as you have a service plan. If it's locked to them, they'll send you the unlock code on request.
Then you buy a service plan. Some have features others don't, some are only available to eligible customers. If you don't like the plan you selected, change it.
No contracts, no "free phones", no crap.
Don't get me wrong: they're a phone company so there are all sorts of oddities, annoyances and so on. But that's the case with all US "postpaid" providers. T-Mobile just has fewer than AT&T and Verizon...
Pay as you Go
I use a 'Pay as you Go' plan. This means I buy the phone at retail upfront and pay an open ended subscription to my credit card. But I do not have a formal contract nor does the carrier require any information for credit approval. I got away from contracts when I could because the games played to extend the contract. I have had the same carrier for several years now (no plans to switch).
"we have not yet determined that there is any personal customer data involved"
We have not yet determined that the stolen personal customer data includes credit card numbers and unencrypted passwords.
We have not yet determined that the personal customer credit card data has been used.
We have not yet determined that the customers' bank accounts have been emptied.
We have not yet determined that the customers' credit ratings have been demolished.
We have not yet determined whether we will sue a surprisingly large amount of customers that haven't honored their contractual obligations and appear to have a very bad credit rating.
Re: "we have not yet determined that there is any personal customer data involved"
Your satire describes nicely how the poor(er) might will pay the price.
Well, we wouldn't want those unfortunate profit makers of the world to suffer just because of their own shenanigans - would we?!
[1]Please Help George!
[1] https://www.youtube.com/watch?v=e7cWCz96JU4
I've had a mobile for years in the US and I don't think any carrier has asked for my SSN. Was this part of a credit check process and T-Mobile kept the number on file for some mis-guided reason?
customer
I'm a customer and have had 0 contact from T-Mobile about this. Good thing I read El Reg. I mentioned in an earlier article that I would be surprised if they did contact me, so I guess I'm right so far.
Re: customer
I hope Troy Hunt has reserved some extra bandwidth to handle the incoming for you and others.
Just US subscribers?
It would be interesting to know whether the data of subscribers outside the US landed up in the repository prior to the breach, and thus might have been leaked alongside that of US subscribers.
Shouldn't I be hearing this first from T-Mobile?
I'm a T-Mo customer. Almost 20 years now... Why do am I learning about this from the news instead of the company that I supposedly have a longstanding business relationship with?
Disappointing but not surprising.
Whew, so glad I didn't sign up with these folks. I was turned off by their disgusting website and confusing pricing models. It seems MVNOs were not affected either, so anyone using T-Mobile service without actually being signed up for T-Mobile is safe... Gotta love how that works.