SoylentNews
SoylentNews is people
https://soylentnews.org/

Title    New T-Mobile Breach Affects 37 Million Accounts
Date    Monday January 23 2023, @01:41PM
Author    janrinok
Topic   
from the see-what-breach-is-next dept.
https://soylentnews.org/article.pl?sid=23/01/22/1533205

upstart writes:

New T-Mobile Breach Affects 37 Million Accounts:

T-Mobile today disclosed a data breach affecting tens of millions of customer accounts, its second major data exposure in as many years. In a filing with federal regulators, T-Mobile said an investigation determined that someone abused its systems to harvest subscriber data tied to approximately 37 million current customer accounts.

In a filing today with the U.S. Securities and Exchange Commission, T-Mobile said a "bad actor" abused an application programming interface (API) to hoover up data on roughly 37 million current postpaid and prepaid customer accounts. The data stolen included customer name, billing address, email, phone number, date of birth, T-Mobile account number, as well as information on the number of customer lines and plan features.

APIs are essentially instructions that allow applications to access data and interact with web databases. But left improperly secured, these APIs can be leveraged by malicious actors to mass-harvest information stored in those databases. In October, mobile provider Optus disclosed that hackers abused a poorly secured API to steal data on 10 million customers in Australia.

T-Mobile said it first learned of the incident on Jan. 5, 2023, and that an investigation determined the bad actor started abusing the API beginning around Nov. 25, 2022. The company says it is in the process of notifying affected customers, and that no customer payment card data, passwords, Social Security numbers, driver's license or other government ID numbers were exposed.

In August 2021, T-Mobile acknowledged that hackers made off with the names, dates of birth, Social Security numbers and driver's license/ID information on more than 40 million current, former or prospective customers who applied for credit with the company. That breach came to light after a hacker began selling the records on a cybercrime forum.

Last year, T-Mobile agreed to pay $500 million to settle all class action lawsuits stemming from the 2021 breach. The company pledged to spend $150 million of that money toward beefing up its own cybersecurity.

In its filing with the SEC, T-Mobile suggested it was going to take years to fully realize the benefits of those cybersecurity improvements, even as it claimed that protecting customer data remains a top priority.


Original Submission

Links

  1. "upstart" - https://soylentnews.org/~upstart/
  2. "New T-Mobile Breach Affects 37 Million Accounts" - https://krebsonsecurity.com/2023/01/new-t-mobile-breach-affects-37-million-accounts/
  3. "a filing today" - https://www.sec.gov/ix?doc=/Archives/edgar/data/0001283699/000119312523010949/d641142d8k.htm
  4. "a hacker began selling the records on a cybercrime forum" - https://krebsonsecurity.com/2021/08/t-mobile-breach-exposed-ssn-dob-of-40m-people/
  5. "Original Submission" - https://soylentnews.org/submit.pl?op=viewsub&subid=58272

© Copyright 2024 - SoylentNews, All Rights Reserved

printed from SoylentNews, New T-Mobile Breach Affects 37 Million Accounts on 2024-04-25 03:59:17