T-Mobile breach exposes data on 2 million customers
Full article564 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Hackers have breached T-Mobile servers, exposing personal information on roughly 2 million customers, the mobile carrier has confirmed.
Hackers have breached T-Mobile servers, exposing personal information on roughly 2 million customers, the mobile carrier has confirmed.
Affected customers’ names, phone numbers, billing zip codes, email addresses, account numbers and account types may have been accessed, T-Mobile said. However, financial data, such as credit card or social security numbers, were not exposed.
“On August 20, our cybersecurity team discovered and shut down an unauthorized access to certain information, including yours, and we promptly reported it to authorities,” T-Mobile said in a statement.
“This was quickly discovered by our security team and shut down very fast,” a T-Mobile spokesperson told CyberScoop. “There’s no additional threat.”
Asked who was responsible for the breach, the spokesperson said “it was an international group” of hackers who accessed the company’s servers through an API. “It was a small percentage of our 77 million customers that was affected (about 3 percent),” the spokesperson said.
Mobile carriers store troves of personal data, and have been known to sell or provide that data to third parties like marketers and data vendors. Those practices came under scrutiny following a New York Times report in May showing that vendor Securus Technologies could use data from mobile carriers to pinpoint nearly any phone user in the country. The security and privacy implications of Securus’s surveillance tool came into sharp focus when the company was breached by hackers, as Vice’s Motherboard reported.
In June, T-Mobile, AT&T, Verizon, and Sprint said they would stop providing real-time location information on phone users to data brokers following pressure from Sen. Ron Wyden, D-Ore., to end those practices.
After this week’s breach, T-Mobile emphasized that it had strong security practices in place.
“We take the security of your information very seriously and have a number of safeguards in place to protect your personal information from unauthorized access,” T-Mobile’s statement says. “We truly regret that this incident occurred and are so sorry for any inconvenience this has caused you.”
Motherboard was first to report on the data breach.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/t-mobile-breach-exposes-data-on-2-million-customers/