Live data from Hacker News

Hackers claim they breached T-Mobile more than 100 times in 2022

krebsonsecurity.com

51–60 of 342 posts

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#51
I've been thinking about this a bit more and I think the right path forward is to impose the same fiduciary liabilities and regulations on cellular providers that banks enjoy. Phones are used as authentication devices for bank transactions. If cellular providers have to go through all the same audits of controls as banks and share the same fiduciary liabilities that may raise the bar for phishing attempts. This may also change the employment requirements for people at T-Mobile and there would be more scrutiny to weed out some of the bad apples or at least increase monitoring and auditing of transactions to provide more visibility to forensic teams.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#52

It is an open secret that criminal groups also pay unscrupulous T-Mobile employees to assist with SIM-swap attacks. I am not sure at what scale this happens, as those instances _should_ be easy to trace and prosecute. But I have seen evidence of criminals reaching out and offering "side work" on the T-mobile subreddits, as an example. In those cases, hardware keys for employees would not help.

> those instances _should_ be easy to trace and prosecute I suspect that the employees aren't merely doing a sim swap attack with their work login credentials. Like you say, they'd clearly get fired/prosecuted for that. Instead, I suspect criminal X buys a nice thing delivered to employee Y's house. Then, criminal X phones the helpdesk repeatedly till they get connected to employee Y during working hours. Then, they…

Out of high school I've worked a couple of years for A1 telecom(in Croatia) in customer service. When someone called, all I was required to ask is their OIB(Personal identification number) and they could literally ask me for anything if it's a residential user.

Want to cancel 20 numbers that still got 2 years until the contracts expire? Sure, let me do that for you. Want to change sim? Sure, just give me the new sim number. Want to add 5 tariffs to your plan? Sure, do you want phones with that?

That was 6 years ago but I still got friends I talk to there, and not much has changed.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#53
>“A huge reason this problem has been allowed to spiral out of control is because children play such a prominent role in this form of breach,” Nixon said.

>Nixon said SIM-swapping groups often advertise low-level jobs on places like Roblox and Minecraft, online games that are extremely popular with young adolescent males.

>… “They recruit children because they’re naive, you can get more out of them, and they have legal protections that other people over 18 don’t have.”

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#54
The rise of SMS as a second factor for security across the web has raised the incentive for SIM-swapping tremendously. No one should be shocked that when tech companies start outsourcing their identity verification to cell phone providers those providers come under attack.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#55
post #8

> T-Mobile declined to answer questions about what it may be doing to beef up employee authentication. But Nicholas Weaver, a researcher and lecturer at University of California, Berkeley’s International Computer Science Institute, said T-Mobile and all the major wireless providers should be requiring employees to use physical security keys for that second factor when logging into company resources. > “These breaches…

You assume that regulation can just make security magically happen. I see no reason to assume that premise to be correct in practice. It's not like the US Government hasn't been breached countless times or had Supreme Court opinions leaked; and it's not like corporations that really tried and should be examples of best practice haven't also been breached. Also, what law can prevent insider attacks? There's already pl…

You’re forgetting an important aspect of making stuff like this law - accountability and recourse. Sure, laws won’t magically make security happen, but it will provide tools against companies that don’t follow outlined laws or regulations to suffer consequences for mishandling data. Companies shouldn’t just be “expected” to do the right thing, because often doing the right thing cuts into profits.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#56

It is an open secret that criminal groups also pay unscrupulous T-Mobile employees to assist with SIM-swap attacks. I am not sure at what scale this happens, as those instances _should_ be easy to trace and prosecute. But I have seen evidence of criminals reaching out and offering "side work" on the T-mobile subreddits, as an example. In those cases, hardware keys for employees would not help.

IIRC, on Darknet Diaries podcast they shared that one of the approaches is that someone comes to a location that services T-Mobile customers and has T-Mobile terminal (not necessarily a T-Mobile brand boutique shop). They come with a random request and wait for an employee to sign into the terminal and then pull it out of their hands and run away. They then run against the clock (whatever time it takes to report theft to central T-Mobile office and block the device) to perpetrate the fraud.

I guess a second factor confirmation on every modifying request would solve the issue?

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#58
In fairness, T-Mobile (and other phone companies) don't really want to provide no cost authentication for other entities. SIM swapping wouldn't be an issue if forces outside the control of the phone companies were not making it so profitable.

If we need to legislate something, perhaps we should try to discourage this sort of thing in the first place. One company should not be allowed to paint a target on an uninvolved company for financial gain.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#59
post #12

Earlier quoted context omitted.

Unfortunately, most carriers (except ATT & Verizon) are just T-Mobile resellers... so you might think you're not using T-Mobile but you're still affected. Even if you use ATT or Verizon, the article mentions they're also hacked and SMS intercepted often.

Honestly, I’d assume being on a MVNO carrier would actually protect you from this, as you’re simply roaming on the T-Mobile network through the carrier agreement. Even ATT and Verizon have roaming agreements. The issue is for T-Mobile direct customers, which obviously their internal systems have access to. I see no reason why T-Mobile would have access to users accounts at another company…

https://www.theverge.com/2023/2/1/23580947/google-fi-mobile-...

"Google says that hackers may have accessed limited customer information via the compromised system, which includes phone numbers, SIM card serial numbers, account status, and mobile service plan data. The system did not contain personal customer information such as names, email addresses, payment card data, government IDs, passwords, or pin numbers."

It's something, but not perfect.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#60
post #8

> T-Mobile declined to answer questions about what it may be doing to beef up employee authentication. But Nicholas Weaver, a researcher and lecturer at University of California, Berkeley’s International Computer Science Institute, said T-Mobile and all the major wireless providers should be requiring employees to use physical security keys for that second factor when logging into company resources. > “These breaches…

You assume that regulation can just make security magically happen. I see no reason to assume that premise to be correct in practice. It's not like the US Government hasn't been breached countless times or had Supreme Court opinions leaked; and it's not like corporations that really tried and should be examples of best practice haven't also been breached. Also, what law can prevent insider attacks? There's already pl…

an executive or two in jail and we'll sure enough see security magically happen.
Post reply on HN