Live data from Hacker News

Hackers claim they breached T-Mobile more than 100 times in 2022

krebsonsecurity.com

71–80 of 342 posts

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#71

I don’t doubt it. My cell phone stopped working for a day, I called in and talked to somebody who I could barely understand and knew very little about basic security. I tried to explain multiple times that my account was probably SIM swapped and the support person completely ignored this security concern and just said I have fixed the issue on my end anything else I can help you with? Please rate me 5 star in the com…

Was this on T-Mobile? In my experience their support is actually quite good. I always get connected to someone in the US.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#72

In fairness, T-Mobile (and other phone companies) don't really want to provide no cost authentication for other entities. SIM swapping wouldn't be an issue if forces outside the control of the phone companies were not making it so profitable. If we need to legislate something, perhaps we should try to discourage this sort of thing in the first place. One company should not be allowed to paint a target on an uninvolve…

> don't really want to provide no cost authentication for other entities

Is the customer not paying for the cell phone plan? Nothing is “no cost” in this situation. The cost is just shifted to the consumer from the company in the form of requiring a phone number.

> One company should not be allowed to paint a target on an uninvolved company for financial gain.

Or, if T-Mobile and others did a good job in security for their networks and in turn their customers communications maybe they wouldn’t have this issue.

IMO this comparison would be like claiming a gas station is responsible for your cars electronics not functioning properly.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#73
post #65

I was a victim of this last October and November on a T-Mobile number. This is what occurred: - My Gmail account was compromised - My Amazon account was compromised In Gmail, they added a filter to hide any shipping or customer service messages from Amazon. In Amazon, every other day, they placed an order for a ~500 USD GoPro device, delivered to an address in NYC. This address changed with every order. Both password…

I use Google voice for everything... except my bank because they said using T-Mobile is so much more safer than Google so I had to switch back

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#74

I'm a Google Fi customer and experienced a very disconcerting fraud attack a year or 2 ago. I made an outbound call to the support number for my bank (I triple-checked that it was the correct number for the bank's support line). My call was routed to fraudsters impersonating my bank's support and I gave them all of my debit card information through what I initially thought was an authentication process. The 1) strang…

That could have actually been on your bank's side. An attacker could have compromised their phone system and is intermittently redirecting calls externally.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#75

I've been thinking about this a bit more and I think the right path forward is to impose the same fiduciary liabilities and regulations on cellular providers that banks enjoy . Phones are used as authentication devices for bank transactions. If cellular providers have to go through all the same audits of controls as banks and share the same fiduciary liabilities that may raise the bar for phishing attempts. This may…

> phones are used as authentication devices for banking transactions That’s the banks’ choice though. Are cellular providers selling them a secure authentication service? Or just an insecure best effort message delivery channel? But then of course the banks can ping that liability further upstream: as a customer, when you choose to opt in to SMS authentication, you’re the one vouching for the security of your cellpho…

I think the legislation should be worded so that if a cellular provider does not want the fiduciary and regulatory requirements imposed on them, they must disable all SS7-to-MAPI SMS/text message gateways or any other form of non-E2EE unencrypted and unauthenticated communication. SIM swapping becomes less useful as encrypted applications take over MFA/2FA authentication meaning the attacker must acquire and unlock the phone itself rather than being able to impersonate it.

Even voice communication must be encrypted when cell-to-cell so that Joe-Blow-Nobody and the President of the United States have exactly the same protection on their personal cell phones. If a company key use used for lawful intercept there must be a massive audit trail that makes it crystal clear who monitored what and for how long. No more pressuring people like me to give authorities unfettered and un-monitored lawful monitoring access.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#76

You know, I’m starting to become slightly more serious about switching carriers solely based on how terrible it would be to experience SMS/Call diverting of my number. While I use a yubikey, OTP (where possible), and unique passwords…there’s still places where I have no choice and my number is my auth (or stupidly a reset option). I genuinely am happy with TMO service in the US, and frankly abroad it’s excellent…but…

On that topic, does anyone know about a good alternative that can be used just for a secure SMS number? Google Voice has been mentioned several times but it's unclear to me how that helps.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#77

It is an open secret that criminal groups also pay unscrupulous T-Mobile employees to assist with SIM-swap attacks. I am not sure at what scale this happens, as those instances _should_ be easy to trace and prosecute. But I have seen evidence of criminals reaching out and offering "side work" on the T-mobile subreddits, as an example. In those cases, hardware keys for employees would not help.

Not only sim swaps, but also phone unlock codes IIRC.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#79
post #62

Earlier quoted context omitted.

yup https://www.bleepingcomputer.com/news/security/google-fi-dat... my friend had google fi and was caught in this, among other things they had their instagram taken over. scary few days. thankfully their roommate works at meta... I think the only way to be really safe is to use one of the smaller MVNOs and never ever ever reveal who your carrier is

I've always figured I should have two numbers—one I let people know, and one for 2fa. But that's ~$20/mo and a moderate annoyance, so for now mostly just fingers crossed that eventually everywhere that matters will allow me to switch fully to authentication apps and hardware keys.

I don't think that having two numbers will help much. I'd guess that most sim-swapped cell numbers are leaked in data breaches or acquired through data brokering. Enrolling a number in 2fa is letting people know your number, because you're tying that number to the account.

A separate number for each account might help. Maybe.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#80

It is an open secret that criminal groups also pay unscrupulous T-Mobile employees to assist with SIM-swap attacks. I am not sure at what scale this happens, as those instances _should_ be easy to trace and prosecute. But I have seen evidence of criminals reaching out and offering "side work" on the T-mobile subreddits, as an example. In those cases, hardware keys for employees would not help.

> those instances _should_ be easy to trace and prosecute I suspect that the employees aren't merely doing a sim swap attack with their work login credentials. Like you say, they'd clearly get fired/prosecuted for that. Instead, I suspect criminal X buys a nice thing delivered to employee Y's house. Then, criminal X phones the helpdesk repeatedly till they get connected to employee Y during working hours. Then, they…

I imagine getting someone job-fair hired under assumed credentials and ghosting after one full shift of abusing their access, or giving a very poorly paid CSR just enough cash to make it worth the risk is probably more straightforward, but I don't know anything about that stuff. Most restaurants/bars I worked at had hourly staff working under 'borrowed' SSNs and names for years, though.
Post reply on HN