TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

T-Mobile Database Breach Exposes 2M Customers' Data

113 pointsby Nazzarenoover 6 years ago

13 comments

seibeljover 6 years ago
I have T-Mobile. 6 weeks ago my phone could no longer access the cell network. The support agent told me that someone went into a store, claimed to be me, and was able to change the SIM card. The history showed the employee in the store verified me by my driver&#x27;s license. We changed the SIM back and supposedly locked the account.<p>I use Google Auth OTP for all the accounts that I can, and as far as I can tell nothing was breached or stolen, but I wouldn&#x27;t rely on your cell phone or number for anything whatsoever, it&#x27;s way too easy to socially engineer, or have some easily corruptible retail employee steal from you.
评论 #17860305 未加载
评论 #17859299 未加载
评论 #17859303 未加载
评论 #17859609 未加载
评论 #17859356 未加载
评论 #17862969 未加载
heywotover 6 years ago
My favorite part about all of this is that, as a T-Mobile customer, this is how I find out about the leak. There&#x27;s not even an alert when I log into my account. Why can&#x27;t companies be more responsible about these situations?
评论 #17859468 未加载
wegsover 6 years ago
A while back, I ran into a security hole in T-Mobile. Confidential customer data was quite literally available on the Internet via a Google search. This was due to a half-dozen missing very basic security precautions (forms using GET instead of POST, no CSRF, etc., etc., etc.).<p>I emailed the CEO. It got moved to a team who assured him there were no problems. The pages got taken down, but the underlying issues were, as far as I know, ignored (the communication to the CEO was essentially that there were no issues, and he believed his team over me).<p>I still trust T-Mobile more than Spring&#x2F;AT&amp;T&#x2F;Verizon as a company, but data security is non-existent.<p>I&#x27;m not quite sure what to do with that.
kevin_thibedeauover 6 years ago
&gt; But a T-Mobile spokeswoman later told news site Motherboard that &quot;encrypted&quot; passwords were in the batch of data.<p>T-mobile stores plaintext passwords. They recently invalidated a password I had been using with them for some time because they changed their rules and disallowed special characters (tons of stupid there). They wouldn&#x27;t have known to do that if the passwords were properly hashed.
评论 #17860493 未加载
评论 #17860033 未加载
评论 #17859939 未加载
评论 #17860626 未加载
评论 #17860036 未加载
评论 #17862928 未加载
mrepover 6 years ago
&gt; T-Mobile&#x27;s assertion that no password information was stolen - and later clarification that encrypted passwords were exposed<p>Call me skeptical considering they said 4 months ago that they store part of their passwords in plain text: <a href="https:&#x2F;&#x2F;motherboard.vice.com&#x2F;en_us&#x2F;article&#x2F;7xdeby&#x2F;t-mobile-stores-part-of-customers-passwords-in-plaintext-says-it-has-amazingly-good-security" rel="nofollow">https:&#x2F;&#x2F;motherboard.vice.com&#x2F;en_us&#x2F;article&#x2F;7xdeby&#x2F;t-mobile-s...</a>
评论 #17859523 未加载
ourmandaveover 6 years ago
Only 2 million?<p>Seems low. I wonder if they&#x27;ll adjust it upwards <i>like every other data breach that happens every week since I can remember?</i><p>Sadly, I don&#x27;t even care since I was never a T-Mobile customer and they already have my entire life like f*cking Keyser Soze 50x times over.
bogomipzover 6 years ago
And it was only 3 years ago that T-mobile that affected 15 million, which they largely blamed on Experian at the time.<p>&quot;On Sept. 15, 2015 Experian discovered an unauthorized party accessed T-Mobile data housed in an Experian server. Records containing a name, address, Social Security number, date of birth, identification number (typically a driver’s license, military ID, or passport number) and additional information used in T-Mobile&#x27;s own credit assessment were accessed.&quot;<p>T-Mobiles response to that incident was to offer customers 2 years of free credit monitoring service from Experian. That free service would have ended a year ago, just in time for the T-Mobile&#x27;s next breach.<p>Clearly nothing has changed at T-Mobile.<p><a href="https:&#x2F;&#x2F;www.t-mobile.com&#x2F;customers&#x2F;experian-data-breach-faq" rel="nofollow">https:&#x2F;&#x2F;www.t-mobile.com&#x2F;customers&#x2F;experian-data-breach-faq</a>
RobertRobertsover 6 years ago
Anyone have any good suggestions for what a customer should do when their service provider has been breached?
评论 #17859449 未加载
评论 #17859258 未加载
评论 #17859987 未加载
kodablahover 6 years ago
&gt; Ceraolo, who says he was not involved in the breach, says he was able to confirm that the hacker accessed T-Mobile via a vulnerable API.<p>I want some details here. Just the other day we had a blog post lauding fairly open API approaches for client UIs (in GraphQL, but I see similar arguments elsewhere). Lock your shit down, don&#x27;t give the frontend more than it needs, and if you&#x27;re in a company with some type of ridiculous team separation where the backend has to treat the frontend as a customer that doesn&#x27;t work for the company it&#x27;s just a matter of time.<p>Not saying this was a frontend API, just saying it&#x27;s a frequent vector due to the lax auth requirements and &quot;internal&quot; query-like approach they often take.
akshayBover 6 years ago
I think its about time US passes laws that any company that suffers a data breach is mandated to give a identity theft protection for 1 year to people who&#x27;s information was compromised.
评论 #17859276 未加载
评论 #17859598 未加载
评论 #17859869 未加载
评论 #17859214 未加载
评论 #17859277 未加载
评论 #17859278 未加载
评论 #17859320 未加载
评论 #17859579 未加载
评论 #17860167 未加载
bogomipzover 6 years ago
In looking at T-mobile&#x27;s home page there is no mention of the breach. Wouldn&#x27;t the responsible thing for them to do is post it somewhere high profile that their customer&#x27;s might see it?<p>Instead the notice is buried here which doesn&#x27;t even appear to be a linked to on their home page.<p><a href="https:&#x2F;&#x2F;www.t-mobile.com&#x2F;customers&#x2F;6305378821" rel="nofollow">https:&#x2F;&#x2F;www.t-mobile.com&#x2F;customers&#x2F;6305378821</a>
MrEfficiencyover 6 years ago
After being a Tmobile customer for 6 years(and leaving this year), I do not trust a word they say.<p>Here is a list of unethical things they&#x27;ve done-<p>&gt;Claim UNLIMITED when restricting people at 10gb hotspot and 50gb data. Their depriortization is unusable, but they claim otherwise.<p>&gt;They sent their social media marketing team to astroturf in an &#x2F;r&#x2F;frugal thread critical of tmobile.<p>&gt;Their customer service person canceled a plan and added a plan when moving around numbers. I dont know if this was intended or an accident, but after 2 months of paying extra, I asked for a refund, the store wouldnt do it. I had to call. This was a 2 hour process.<p>So 2M customer data? Says tmobile.<p>So no passwords stolen? Says tmobile.<p>I remember when they were &#x27;the good guys&#x27;.
评论 #17859136 未加载
评论 #17859213 未加载
评论 #17859725 未加载
评论 #17859038 未加载
评论 #17859212 未加载
m52goover 6 years ago
Purism&#x27;s carrier-less phone cannot come fast enough.
评论 #17859189 未加载