Live data from Hacker News

Hackers claim they breached T-Mobile more than 100 times in 2022

krebsonsecurity.com

61–70 of 342 posts

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#61

They will pay the fines and keep doing business happily and another "we're sorry, it won't happen again..." The joys of being too big to fail.

Increase the fines tenfold or up them an order of magnitude till it’s no longer just a negligible cost of doing business

Increase the fines tenfold or up them an order of magnitude...

We get it, no need to repeat yourself. ;-)

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#62
post #21

Was thinking about moving a line to Google Fi for this reason. I know they just resell T-Mobile bandwidth, but would they provide better account level security? Is it common for Google Fi customers to get SIM swapped?

yup https://www.bleepingcomputer.com/news/security/google-fi-dat... my friend had google fi and was caught in this, among other things they had their instagram taken over. scary few days. thankfully their roommate works at meta... I think the only way to be really safe is to use one of the smaller MVNOs and never ever ever reveal who your carrier is

I've always figured I should have two numbers—one I let people know, and one for 2fa.

But that's ~$20/mo and a moderate annoyance, so for now mostly just fingers crossed that eventually everywhere that matters will allow me to switch fully to authentication apps and hardware keys.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#63
post #49

Earlier quoted context omitted.

yup https://www.bleepingcomputer.com/news/security/google-fi-dat... my friend had google fi and was caught in this, among other things they had their instagram taken over. scary few days. thankfully their roommate works at meta... I think the only way to be really safe is to use one of the smaller MVNOs and never ever ever reveal who your carrier is

Thanks! Based on that article it seems that anyone who's reselling T-Mobile service would be vulnerable.

Do we know if Google Voice also uses T-Mobile? If not, might be worthwhile to switch SMS 2FA to the Voice number if a service allows voip numbers.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#64

I've been thinking about this a bit more and I think the right path forward is to impose the same fiduciary liabilities and regulations on cellular providers that banks enjoy . Phones are used as authentication devices for bank transactions. If cellular providers have to go through all the same audits of controls as banks and share the same fiduciary liabilities that may raise the bar for phishing attempts. This may…

> phones are used as authentication devices for banking transactions

That’s the banks’ choice though. Are cellular providers selling them a secure authentication service? Or just an insecure best effort message delivery channel?

But then of course the banks can ping that liability further upstream: as a customer, when you choose to opt in to SMS authentication, you’re the one vouching for the security of your cellphone provider, telling your bank ‘I trust their account security enough that if you send a message to this number you can assume the recipient is me’

So now you’re left going to your cell company and saying ‘since the bank said I could use you for auth, you’re properly secure right?’

And their answer is ‘lol no. check our t’s and c’s.’

And then you wind up saying ‘but I want to be able to assume that and I think my cell company should be liable if they aren’t’, and asking for the cellphone company to be regulated like a bank.

Because banks are that good at deflecting liability.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#65
I was a victim of this last October and November on a T-Mobile number. This is what occurred:

- My Gmail account was compromised

- My Amazon account was compromised

In Gmail, they added a filter to hide any shipping or customer service messages from Amazon.

In Amazon, every other day, they placed an order for a ~500 USD GoPro device, delivered to an address in NYC. This address changed with every order.

Both passwords to both accounts were kept the same.

After I caught on to the above once I received my credit card statement, in November:

- They attempted to purchase something with my credit card. Security mechanisms triggered, and a verification code was sent to my phone at 4am in the morning. They successfully validated and placed the order. My credit card company assures me they input the right verification code.

- They applied for an Amazon credit card using my identity. It was auto approved, and they used the credit card to purchase ~5k worth of items.

I moved everything off of that T-Mobile number, and switched over to GoogleFi (only to learn GoogleFi uses T-Mobile also... still better than T-Mobile directly I'm hoping).

Edit:

I also wiped my phone, eventually thought that wasn't far enough, and switched to a new device entirely. I'm still unsure how the above occurred, because some of it feels beyond the scope of a SIM-swap.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#66
I'm a Google Fi customer and experienced a very disconcerting fraud attack a year or 2 ago. I made an outbound call to the support number for my bank (I triple-checked that it was the correct number for the bank's support line). My call was routed to fraudsters impersonating my bank's support and I gave them all of my debit card information through what I initially thought was an authentication process. The 1) strange call quality, 2) that they asked for all of my card details and 3) the lack of an automated menu tipped me off and I realized pretty much immediately after the call was over that I had been scammed. I called the exact same support line a second time and got the actual customer service for my bank, at which point I promptly canceled my debit card (but not before the fraudsters performed what appeared to be a test charge of my card for $5 to a random merchant name in Connecticut).

I had no idea this kind of attack was possible and I don't know how it works or whether it was related to the T-Mobile breach. Had the hackers attempted an account takeover using the information they collected from me they could conceivably have stolen all of my savings.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#67
This is an interesting development.

We've always known that sim swap attacks weren't hard. But I've largely understood them to be not scalable. You can sim swap almost anybody by calling Verizon on the phone. But you needed to call them. This, in my mind, largely meant that the risk of sim swap for most people was pretty low - certainly far lower than the risk of phishing.

With this method, it scales. Pwn one person who has relevant system access and then you can sim swap as many people as you want. Now there really is a meaningful difference in security posture between sms and otp.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#68
post #27

Earlier quoted context omitted.

US mobile has good 2FA.

Heads up that US mobile is an MVNO operating on T-Mobile and Verizon, so how good their 2FA system is irrelevant if hackers get deep enough into tmobile.

“Deep enough” would be true of any mobile carrier, to date all of these attacks are SIM swapping, with social engineering/phishing being the attack vector. Not particularly deep.

Attackers would have to social engineer the MVNO directly, which is certainly easier if they have data they’ve stolen from t-mobile first, but this isn’t a “they’ll get in no matter what because they’ve pwned T-Mobile so bad” scenario.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#69
post #12

Earlier quoted context omitted.

Unfortunately, most carriers (except ATT & Verizon) are just T-Mobile resellers... so you might think you're not using T-Mobile but you're still affected. Even if you use ATT or Verizon, the article mentions they're also hacked and SMS intercepted often.

So that leaves Verizon, AT&T, and Dish networks[1] And all of them have supposedly been compromised, but T-Mobile is the most compromised. > While it is true that each of these cybercriminal actors periodically offer SIM-swapping services for other mobile phone providers — including AT&T, Verizon and smaller carriers — those solicitations appear far less frequently in these group chats than T-Mobile swap offers. And…

Speaking of Dish, the entire company and their services just breached this past week..

https://www.theverge.com/2023/2/28/23617347/dish-cybersecuri...

Post reply on HN