Live data from Hacker News

Hackers claim they breached T-Mobile more than 100 times in 2022

krebsonsecurity.com

21–30 of 342 posts

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#22
post #12

You know, I’m starting to become slightly more serious about switching carriers solely based on how terrible it would be to experience SMS/Call diverting of my number. While I use a yubikey, OTP (where possible), and unique passwords…there’s still places where I have no choice and my number is my auth (or stupidly a reset option). I genuinely am happy with TMO service in the US, and frankly abroad it’s excellent…but…

Unfortunately, most carriers (except ATT & Verizon) are just T-Mobile resellers... so you might think you're not using T-Mobile but you're still affected. Even if you use ATT or Verizon, the article mentions they're also hacked and SMS intercepted often.

Honestly, I’d assume being on a MVNO carrier would actually protect you from this, as you’re simply roaming on the T-Mobile network through the carrier agreement. Even ATT and Verizon have roaming agreements.

The issue is for T-Mobile direct customers, which obviously their internal systems have access to. I see no reason why T-Mobile would have access to users accounts at another company…

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#24

Might it be time for the US government to step in using eminent domain, seize the company and merge it into a different provider? Are other providers more secure or do we just hear about T-Mobile the most? Who should take over T-Mobile? [Edit] The more I think about this, perhaps another path to resolution would be to remove limited liability protections from companies that repeatedly put their customers at risk, esp…

And then we'd be down to what, two wireless carries in the US? AT&T already tried to acquire/merge with T-Mobile some years ago but it didn't go through. I forget why, but probably due to antitrust issues. And wasn't Sprint just acquired/merged with not long ago, by T-Mobile IIRC?

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#25
It is an open secret that criminal groups also pay unscrupulous T-Mobile employees to assist with SIM-swap attacks. I am not sure at what scale this happens, as those instances _should_ be easy to trace and prosecute. But I have seen evidence of criminals reaching out and offering "side work" on the T-mobile subreddits, as an example.

In those cases, hardware keys for employees would not help.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#26

> Phish T-Mobile employees for access to internal company tools, and then convert that access into a cybercrime service that could be hired to divert any T-Mobile user’s text messages and phone calls to another device. If they are doing all this through phishing and aren't being as successful with other networks there's some serious issue that's being overlooked. It's unclear from the article if this is due to traini…

> But there's still a large number of sites and services that rely on SMS.

I avoid using my actual phone number whenever possible and use a Google Voice number. Hacking Google Voice would require hacking my actual Google account instead of just tricking someone at the phone company.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#27

Which cell phone network would you guys recommend for people who care about security?

US mobile has good 2FA.

Heads up that US mobile is an MVNO operating on T-Mobile and Verizon, so how good their 2FA system is irrelevant if hackers get deep enough into tmobile.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#28
post #12

You know, I’m starting to become slightly more serious about switching carriers solely based on how terrible it would be to experience SMS/Call diverting of my number. While I use a yubikey, OTP (where possible), and unique passwords…there’s still places where I have no choice and my number is my auth (or stupidly a reset option). I genuinely am happy with TMO service in the US, and frankly abroad it’s excellent…but…

Unfortunately, most carriers (except ATT & Verizon) are just T-Mobile resellers... so you might think you're not using T-Mobile but you're still affected. Even if you use ATT or Verizon, the article mentions they're also hacked and SMS intercepted often.

So that leaves Verizon, AT&T, and Dish networks[1]

And all of them have supposedly been compromised, but T-Mobile is the most compromised.

> While it is true that each of these cybercriminal actors periodically offer SIM-swapping services for other mobile phone providers — including AT&T, Verizon and smaller carriers — those solicitations appear far less frequently in these group chats than T-Mobile swap offers. And when those offers do materialize, they are considerably more expensive.

So the choice is, which one is the least compromised, unfortunately

1. https://en.wikipedia.org/wiki/List_of_United_States_wireless...

technically there are a bunch other small carriers that run their own equipment (not resellers), more than I thought there were: https://en.wikipedia.org/wiki/List_of_United_States_wireless...

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#30

Might it be time for the US government to step in using eminent domain, seize the company and merge it into a different provider? Are other providers more secure or do we just hear about T-Mobile the most? Who should take over T-Mobile? [Edit] The more I think about this, perhaps another path to resolution would be to remove limited liability protections from companies that repeatedly put their customers at risk, esp…

What should not have happened is the Sprint T-Mobile merger. Like when Wells Fargo bought the failed bank (forget which one) after 2008, Wells Fargo went from a reliable company to all kinds of suspect things going on with our account. So far T-Mobile has been fine for us but we are seeing some marketing things floating around suggesting the Sprint influence might be having a negative impact on T-Mobile. I miss John Legere as the CEO, he had it going on.
Post reply on HN