Live data from Hacker News

Hackers claim they breached T-Mobile more than 100 times in 2022

krebsonsecurity.com

101–110 of 342 posts

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#101
Wasn't just t-mobile, some of the 3rd party connected services ran by other companies that tie into the mobile networks for most major carriers got hacked also.

Caller ID services and Iphone Provisioning.

Its way worse than the media/public even knows. Its networks built on networks, with api's everywhere.

Also, TMO allows you to enable 2FA but ignores it when enabled, still allows you to sign on with email/pass.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#102

It is an open secret that criminal groups also pay unscrupulous T-Mobile employees to assist with SIM-swap attacks. I am not sure at what scale this happens, as those instances _should_ be easy to trace and prosecute. But I have seen evidence of criminals reaching out and offering "side work" on the T-mobile subreddits, as an example. In those cases, hardware keys for employees would not help.

IIRC, on Darknet Diaries podcast they shared that one of the approaches is that someone comes to a location that services T-Mobile customers and has T-Mobile terminal (not necessarily a T-Mobile brand boutique shop). They come with a random request and wait for an employee to sign into the terminal and then pull it out of their hands and run away. They then run against the clock (whatever time it takes to report thef…

not sure if a yubikey or similar would help here because they would probably just steal that as well, no?

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#103
post #96
post #65

I was a victim of this last October and November on a T-Mobile number. This is what occurred: - My Gmail account was compromised - My Amazon account was compromised In Gmail, they added a filter to hide any shipping or customer service messages from Amazon. In Amazon, every other day, they placed an order for a ~500 USD GoPro device, delivered to an address in NYC. This address changed with every order. Both password…

No 2FA on your GMail? Any idea how G and A were compromised, password reuse?

Probably SMS as a 2FA option on Gmail, which is the real problem. Once you add your Yubikey and set up TOTP as a backup, you need to go back and delete SMS as a 2FA option. Had gmail been configured correctly, the SIM swap would have far less serious.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#104
post #96
post #65

I was a victim of this last October and November on a T-Mobile number. This is what occurred: - My Gmail account was compromised - My Amazon account was compromised In Gmail, they added a filter to hide any shipping or customer service messages from Amazon. In Amazon, every other day, they placed an order for a ~500 USD GoPro device, delivered to an address in NYC. This address changed with every order. Both password…

No 2FA on your GMail? Any idea how G and A were compromised, password reuse?

[deleted]

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#105
post #8

> T-Mobile declined to answer questions about what it may be doing to beef up employee authentication. But Nicholas Weaver, a researcher and lecturer at University of California, Berkeley’s International Computer Science Institute, said T-Mobile and all the major wireless providers should be requiring employees to use physical security keys for that second factor when logging into company resources. > “These breaches…

You assume that regulation can just make security magically happen. I see no reason to assume that premise to be correct in practice. It's not like the US Government hasn't been breached countless times or had Supreme Court opinions leaked; and it's not like corporations that really tried and should be examples of best practice haven't also been breached. Also, what law can prevent insider attacks? There's already pl…

[deleted]

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#106
The cool thing about T-Mobile is they don't ask for your SSN or care about what name you give if you do pre-paid in cash. This anonymity means that if the bad guys call up T-Mobile and know all your details and they even have a compromised employee with full access, the bad guys still can't find out your real IMEI or phone number and do a sim swap. Another benefit is that, with all the cell phone location selling going on, they can't find your true location either!

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#107
post #84

Earlier quoted context omitted.

I think why regulation hasn’t happened is because the computer industry has changed so quickly. Two-factor auth wasn’t even a commonly accepted best practice two decades ago. And regulation takes a while to create and put into practice and with the rate things are going, by the time regulation has been out in place, the current best practices will have changed. Whereas writing regulation on building bridges is easy b…

I agree completely. I didn't ask why government enforced regulation hasn't happened. I asked why industry self-regulation has failed. I've worked in a regulatory/security role for a major conglomerate before. I'm not saying I expected self-regulation to work. But, if you are in a position of customers seeing direct harm every day , it's not unreasonable to ask why there is a failure here.

You can find an answer in their profitability in spite of repeated negligence.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#108
post #96
post #65

I was a victim of this last October and November on a T-Mobile number. This is what occurred: - My Gmail account was compromised - My Amazon account was compromised In Gmail, they added a filter to hide any shipping or customer service messages from Amazon. In Amazon, every other day, they placed an order for a ~500 USD GoPro device, delivered to an address in NYC. This address changed with every order. Both password…

No 2FA on your GMail? Any idea how G and A were compromised, password reuse?

2FA on everything. No password reused. Only similarity is both had the T-Mobile number attached to them.

I initially thought only Amazon was compromised. I thought it was due to us throwing away a FireTV device (assumption: we didn't log out and de-register) that was then used to order items.

And then I found they added filters to my Gmail account to hide the Amazon orders, and went into full panic mode.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#109
post #65

I was a victim of this last October and November on a T-Mobile number. This is what occurred: - My Gmail account was compromised - My Amazon account was compromised In Gmail, they added a filter to hide any shipping or customer service messages from Amazon. In Amazon, every other day, they placed an order for a ~500 USD GoPro device, delivered to an address in NYC. This address changed with every order. Both password…

[flagged]

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#110

Earlier quoted context omitted.

I agree completely. I didn't ask why government enforced regulation hasn't happened. I asked why industry self-regulation has failed. I've worked in a regulatory/security role for a major conglomerate before. I'm not saying I expected self-regulation to work. But, if you are in a position of customers seeing direct harm every day , it's not unreasonable to ask why there is a failure here.

I think it has failed because the industry is moving way faster than most people can keep up. Even your average developer isn’t going to be aware of security changes in the industry to know what’s important or not. It’s going to be even less likely they someone not in engineering to remotely know what’s important or not. Security professionals know but do you seek out a cardiologist first before you ask your GP? Prob…

"People" don't need to keep up, the internal controls team needs to keep up, and it's possible to staff such a team with people who know how to mitigate phishing attacks when you are one of the largest corporate targets of phishing by volume on the earth.
Post reply on HN