Data breach at T-Mobile US: hacker exploited devastating security hole
Summary
In August 2021 John Binns claimed responsibility for the break-in at T-Mobile US, in which data of more than 50 million customers and prospects was leaked. According to the Wall Street Journal, the attacker used a publicly available scanner to find an unprotected router and penetrated the network from there. Stolen data included names, addresses, social security, driving licence and IMEI numbers.
Ideas
- A single unprotected device opened the way into the network of a large provider.
- Freely available scanners were enough to find the vulnerability.
- Data of former and potential customers was also stored and stolen.
Insights
- Data that is no longer needed is pure risk.
- Large organisations often fail because of simple holes at the network edge, not sophisticated attacks.
Facts
- T-Mobile confirmed the theft of sensitive data of 7.8 million contract customers.
- Around 100 million records had initially been offered on the darknet.
References
Critique
- The technical account is based on the perpetrator’s own statements and has not been independently confirmed.
Remarks
- In 2022 T-Mobile US agreed to pay 350 million US dollars in a class action settlement.
Recommendations
- Regularly scan your own publicly reachable addresses the way attackers would.
- Delete customer data as soon as there is no longer a business purpose.
Links to the original source and the Web Archive open in a new tab.