Live data from Hacker News

Hackers claim they breached T-Mobile more than 100 times in 2022

krebsonsecurity.com

111–120 of 342 posts

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#111
post #30

Might it be time for the US government to step in using eminent domain, seize the company and merge it into a different provider? Are other providers more secure or do we just hear about T-Mobile the most? Who should take over T-Mobile? [Edit] The more I think about this, perhaps another path to resolution would be to remove limited liability protections from companies that repeatedly put their customers at risk, esp…

What should not have happened is the Sprint T-Mobile merger. Like when Wells Fargo bought the failed bank (forget which one) after 2008, Wells Fargo went from a reliable company to all kinds of suspect things going on with our account. So far T-Mobile has been fine for us but we are seeing some marketing things floating around suggesting the Sprint influence might be having a negative impact on T-Mobile. I miss John…

Washington Mutual maybe? Bank of America is in a similar situation, they're just NationsBank with a friendlier name on them now. NationsBank acquired BOFA in 1998 after BOFA lost a bundle on Russian bonds. The speed run on becoming one of the shittiest banks around continued in 2005 when they (NB/BOFA) acquired MBNA.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#112
post #73
post #65

I was a victim of this last October and November on a T-Mobile number. This is what occurred: - My Gmail account was compromised - My Amazon account was compromised In Gmail, they added a filter to hide any shipping or customer service messages from Amazon. In Amazon, every other day, they placed an order for a ~500 USD GoPro device, delivered to an address in NYC. This address changed with every order. Both password…

I use Google voice for everything... except my bank because they said using T-Mobile is so much more safer than Google so I had to switch back

I used to as well, but lots of places have stopped accepting VoIP numbers now. A bunch of them actually just silently fail to send messages, so you can be clicking SMS password reset and get nothing in your texts.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#113
Look at Equifax. The government imposes no penalties on these corporations (i.e. who own the government) for this kind of negligence, or worse.

The field of competition is very limited, and most consumers I'd guess are either unaware of these problems, feel helpless about them, or don't understand their significance. So what's the pressure exerted on T-Mobile to invest in this problem? There's very little.

Unfortunately, for a system with such a big footprint and given the complexity, you'd need a huge amount of pressure to have a meaningful impact on the problem.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#114
post #108
post #96

Earlier quoted context omitted.

No 2FA on your GMail? Any idea how G and A were compromised, password reuse?

2FA on everything. No password reused. Only similarity is both had the T-Mobile number attached to them. I initially thought only Amazon was compromised. I thought it was due to us throwing away a FireTV device (assumption: we didn't log out and de-register) that was then used to order items. And then I found they added filters to my Gmail account to hide the Amazon orders, and went into full panic mode.

Interesting. Was your 2FA setup to use Google Authenticator or regular SMS? It's been a while since I used Google services but from what I recall from a previous company where we used Gmail was that the only way to do 2FA with Google Authenticator if you lost access to the phone was with a backup code you are given at 2FA setup time. Is that no longer the case?

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#115
post #65

I was a victim of this last October and November on a T-Mobile number. This is what occurred: - My Gmail account was compromised - My Amazon account was compromised In Gmail, they added a filter to hide any shipping or customer service messages from Amazon. In Amazon, every other day, they placed an order for a ~500 USD GoPro device, delivered to an address in NYC. This address changed with every order. Both password…

[flagged]

> BTW - give me some of that big-swinging-credit-balls you seem to gotts...

15 * 500 = 7,500 USD. Having a steady job should put that within reach.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#116
post #108

Earlier quoted context omitted.

2FA on everything. No password reused. Only similarity is both had the T-Mobile number attached to them. I initially thought only Amazon was compromised. I thought it was due to us throwing away a FireTV device (assumption: we didn't log out and de-register) that was then used to order items. And then I found they added filters to my Gmail account to hide the Amazon orders, and went into full panic mode.

Interesting. Was your 2FA setup to use Google Authenticator or regular SMS? It's been a while since I used Google services but from what I recall from a previous company where we used Gmail was that the only way to do 2FA with Google Authenticator if you lost access to the phone was with a backup code you are given at 2FA setup time. Is that no longer the case?

2FA with authenticator. As someone correctly points out, Google appears to keep SMS as a recovery option unless you specifically opt out?

Edit: I can't actually find a help article, but it's under "Try another way to sign-in" and they'll text you a verification code to your registered account phone number.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#117

The cool thing about T-Mobile is they don't ask for your SSN or care about what name you give if you do pre-paid in cash. This anonymity means that if the bad guys call up T-Mobile and know all your details and they even have a compromised employee with full access, the bad guys still can't find out your real IMEI or phone number and do a sim swap. Another benefit is that, with all the cell phone location selling goi…

You can put a customer service password on your tmobile account to avoid anyone calling customer service without that password to make any changes. This is separate from your online portal password.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#118
post #27

Earlier quoted context omitted.

Heads up that US mobile is an MVNO operating on T-Mobile and Verizon, so how good their 2FA system is irrelevant if hackers get deep enough into tmobile.

“Deep enough” would be true of any mobile carrier, to date all of these attacks are SIM swapping, with social engineering/phishing being the attack vector. Not particularly deep. Attackers would have to social engineer the MVNO directly, which is certainly easier if they have data they’ve stolen from t-mobile first, but this isn’t a “they’ll get in no matter what because they’ve pwned T-Mobile so bad” scenario.

https://www.bleepingcomputer.com/news/security/google-fi-dat...

This article says that Google Fi customers were SIM swapped due to a T-Mobile breach. Even though "[t]here was no access to Google's systems or any systems overseen by Google."

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#119
post #108
post #96

Earlier quoted context omitted.

No 2FA on your GMail? Any idea how G and A were compromised, password reuse?

2FA on everything. No password reused. Only similarity is both had the T-Mobile number attached to them. I initially thought only Amazon was compromised. I thought it was due to us throwing away a FireTV device (assumption: we didn't log out and de-register) that was then used to order items. And then I found they added filters to my Gmail account to hide the Amazon orders, and went into full panic mode.

So both were compromised through TMobile sim swap, which was the backup for not having access to your 2FA?

I wonder then what the point is of having 2FA at all if you can just click a few buttons to bypass them with an SMS.

Were you specifically targeted in any way that would make the attackers go find your phone number and perform the swap?

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#120

The cool thing about T-Mobile is they don't ask for your SSN or care about what name you give if you do pre-paid in cash. This anonymity means that if the bad guys call up T-Mobile and know all your details and they even have a compromised employee with full access, the bad guys still can't find out your real IMEI or phone number and do a sim swap. Another benefit is that, with all the cell phone location selling goi…

You can put a customer service password on your tmobile account to avoid anyone calling customer service without that password to make any changes. This is separate from your online portal password.

That still doesn't fix the compromised employee problem. If they can match your identity with your phone number, and have full access to t-mobile they can sim swap. Sure, Google could have compromised employees, but I trust Google's security, especially their internal security, much more than T-Mobile.
Post reply on HN