Live data from Hacker News

Hackers claim they breached T-Mobile more than 100 times in 2022

krebsonsecurity.com

11–20 of 342 posts

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#11
> Phish T-Mobile employees for access to internal company tools, and then convert that access into a cybercrime service that could be hired to divert any T-Mobile user’s text messages and phone calls to another device.

If they are doing all this through phishing and aren't being as successful with other networks there's some serious issue that's being overlooked. It's unclear from the article if this is due to training, lax security on internal tools, lack of two factor (as claimed in the article) or something else (even insiders).

That's too bad, I've been on T-Mobile for years. Whenever I can I'll use yubikeys or OTP. But there's still a large number of sites and services that rely on SMS.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#12

You know, I’m starting to become slightly more serious about switching carriers solely based on how terrible it would be to experience SMS/Call diverting of my number. While I use a yubikey, OTP (where possible), and unique passwords…there’s still places where I have no choice and my number is my auth (or stupidly a reset option). I genuinely am happy with TMO service in the US, and frankly abroad it’s excellent…but…

Unfortunately, most carriers (except ATT & Verizon) are just T-Mobile resellers... so you might think you're not using T-Mobile but you're still affected.

Even if you use ATT or Verizon, the article mentions they're also hacked and SMS intercepted often.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#13
post #3

[flagged]

I mean, you get no compensation from your data being sold.

This case is notably different from hackers stealing your data. Instead, they could steal your identity. With this type of access, they could impersonate you at your bank, your email, anything that uses SMS as a form of verification.

This isn't a "whoops, people know your birthday now (again)." This is "whoops, someone hacked into your bank account." All because TMobile's security practices (or at least Employee training) are extremely lacking.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#14

I don’t doubt it. My cell phone stopped working for a day, I called in and talked to somebody who I could barely understand and knew very little about basic security. I tried to explain multiple times that my account was probably SIM swapped and the support person completely ignored this security concern and just said I have fixed the issue on my end anything else I can help you with? Please rate me 5 star in the com…

Pretty typical for most first line support though. Especially outsourced.

It's hard to find people with languages and tech skills so most outsourcers just fulfill the former and cover the latter with endless infernal flowcharts. Really sucks when your problem is not on the chart. Escalating is usually discouraged by giving targets per day to the agents.

I guess you're in the US so perhaps language isn't as much of an issue but a lot of US companies support from the Philippines now because they have a favourably perceived accent (unlike Indians which a lot of customers have come to associate with 'poor support' so it leads to kneejerk reactions *). But anyway in the Philippines it's now hard to find staff too.

But anyway my point is that the support experience is not really related to internal IT competence.

*) not my personal opinion but I have seen US companies in particular use this argument. Unlike in the UK where Indian accents are common. I worked on the contact center tech realm for 20 years.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#15
post #9

Earlier quoted context omitted.

You didn't read the article. This isn't about a data leak, it's about being able to intercept SMS for any T-Mobile phone number.

Surely any enterprising criminal would do both sell and exploit users data…

Not if they are doing a SIM swap. If they are paying $1k as claimed they are after far more interesting things in your accounts than just basic information to sell.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#16

Earlier quoted context omitted.

Surely any enterprising criminal would do both sell and exploit users data…

Not if they are doing a SIM swap. If they are paying $1k as claimed they are after far more interesting things in your accounts than just basic information to sell.

It's common to target high value accounts for BTC.

https://www.coindesk.com/policy/2022/10/20/two-us-men-senten...

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#17
Might it be time for the US government to step in using eminent domain, seize the company and merge it into a different provider? Are other providers more secure or do we just hear about T-Mobile the most? Who should take over T-Mobile?

[Edit] The more I think about this, perhaps another path to resolution would be to remove limited liability protections from companies that repeatedly put their customers at risk, especially given that phones are used as financial transaction authenticators. Perhaps some bank regulations need to find their way onto cellular providers.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#20
post #12

You know, I’m starting to become slightly more serious about switching carriers solely based on how terrible it would be to experience SMS/Call diverting of my number. While I use a yubikey, OTP (where possible), and unique passwords…there’s still places where I have no choice and my number is my auth (or stupidly a reset option). I genuinely am happy with TMO service in the US, and frankly abroad it’s excellent…but…

Unfortunately, most carriers (except ATT & Verizon) are just T-Mobile resellers... so you might think you're not using T-Mobile but you're still affected. Even if you use ATT or Verizon, the article mentions they're also hacked and SMS intercepted often.

Can you source "most" and define "carrier" specifically for your comment?

Verizon and AT&T are the other of the big 3 carriers in the US, and they're not reselling T-Mobile. And all 3 have MNVOs (mobile virtual network operator) that resell and/or combine the networks of the big 3.

Post reply on HN