bk99.de entertain the web since 1997

Data breach at T-Mobile US: hacker exploited devastating security hole

Summary

In August 2021 John Binns claimed responsibility for the break-in at T-Mobile US, in which data of more than 50 million customers and prospects was leaked. According to the Wall Street Journal, the attacker used a publicly available scanner to find an unprotected router and penetrated the network from there. Stolen data included names, addresses, social security, driving licence and IMEI numbers.

Ideas

  • A single unprotected device opened the way into the network of a large provider.
  • Freely available scanners were enough to find the vulnerability.
  • Data of former and potential customers was also stored and stolen.

Insights

  • Data that is no longer needed is pure risk.
  • Large organisations often fail because of simple holes at the network edge, not sophisticated attacks.

Facts

  • T-Mobile confirmed the theft of sensitive data of 7.8 million contract customers.
  • Around 100 million records had initially been offered on the darknet.

References

Critique

  • The technical account is based on the perpetrator’s own statements and has not been independently confirmed.

Remarks

  • In 2022 T-Mobile US agreed to pay 350 million US dollars in a class action settlement.

Recommendations

  • Regularly scan your own publicly reachable addresses the way attackers would.
  • Delete customer data as soon as there is no longer a business purpose.

Read the original article

Search the Web Archive