Live data from Hacker News

Hackers claim they breached T-Mobile more than 100 times in 2022

krebsonsecurity.com

151–160 of 342 posts

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#151
post #115

Earlier quoted context omitted.

> BTW - give me some of that big-swinging-credit-balls you seem to gotts... 15 * 500 = 7,500 USD. Having a steady job should put that within reach.

[flagged]

How would you know unless you check your credit card statement every day?

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#152
post #73
post #65

I was a victim of this last October and November on a T-Mobile number. This is what occurred: - My Gmail account was compromised - My Amazon account was compromised In Gmail, they added a filter to hide any shipping or customer service messages from Amazon. In Amazon, every other day, they placed an order for a ~500 USD GoPro device, delivered to an address in NYC. This address changed with every order. Both password…

I use Google voice for everything... except my bank because they said using T-Mobile is so much more safer than Google so I had to switch back

The prohibition against using a VoIP number for banking purposes is stupid. They already have the full battery of KYC info on me: if I want to use a VoIP number for 2FA (because they are so behind the times they don't support FIDO or even TOTP) then unless law says they cannot they need to allow it.

And while on the topic of banks, most will suspend access to your online portal if you log in with a VPN. Give me a bank that allows VoIP phone numbers, VPN access, and TOTP and/or FIDO support for 2FA and I'll ditch Schwab right now.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#153
post #96

Earlier quoted context omitted.

No 2FA on your GMail? Any idea how G and A were compromised, password reuse?

Probably SMS as a 2FA option on Gmail, which is the real problem. Once you add your Yubikey and set up TOTP as a backup, you need to go back and delete SMS as a 2FA option. Had gmail been configured correctly, the SIM swap would have far less serious.

No the other problem is Google allows adding recovery phone numbers that bypass 2FA :D

https://support.google.com/accounts/answer/183723?hl=en

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#154
post #118

Earlier quoted context omitted.

“Deep enough” would be true of any mobile carrier, to date all of these attacks are SIM swapping, with social engineering/phishing being the attack vector. Not particularly deep. Attackers would have to social engineer the MVNO directly, which is certainly easier if they have data they’ve stolen from t-mobile first, but this isn’t a “they’ll get in no matter what because they’ve pwned T-Mobile so bad” scenario.

https://www.bleepingcomputer.com/news/security/google-fi-dat... This article says that Google Fi customers were SIM swapped due to a T-Mobile breach. Even though "[t]here was no access to Google's systems or any systems overseen by Google."

> These attacks are conducted using social engineering, where the threat actor impersonates the customer and requests that the number be ported to a new device for some reason. To convince the mobile carrier that they are the customer, they provide personal information exposed to phishing attacks and data breaches.

> As the Google Fi data breach includes phone numbers, which can easily be linked to a customer's name, and the serial number of SIM cards, it would have made it even more convincing when contacting a mobile customer support representative.

They used the data in the breach to social engineer the Google fi reps. Attackers still needed to get through Google’s customer support system to perform the SIM swaps.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#155
post #97

Earlier quoted context omitted.

TMobile seems to be particularly bad right now, but Verizon and AT&T aren’t necessarily good. The weak link is usually retail or channel. TMobile is in a high growth phase, so I’d hazard to guess they are more disorganized. Switching to Verizon may reduce exposure, but they have their own similar issues - an aggressively dumb carrier employee is capable of almost anything.

I think the issue is that phone companies weren’t prepared for their services to be used for such high security tasks. For many decades, your phone was just mostly for keeping up with friends and family. 2FA wasn’t even that popular until maybe in the last 10 years. Just like how the locks we buy for our exterior doors are really weak but that’s currently fine for the status quo. You’re not going to preemptively spen…

Yep, using SMS for 2FA is the same as colleges using your social security number as ID on everything back in the day. It absolutely was never intended for the use case.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#156

Earlier quoted context omitted.

Probably SMS as a 2FA option on Gmail, which is the real problem. Once you add your Yubikey and set up TOTP as a backup, you need to go back and delete SMS as a 2FA option. Had gmail been configured correctly, the SIM swap would have far less serious.

SMS 2FA is a security risk! I used to work tech support for cell phone providers, and while we were trained about fraud, the nature of the industry low wages, high turnover, makes this a security flaw that financial institutions should not risk.

How is SMS a security risk? As far as I know, SMS is closely tied to a person's identity, especially 'know your customer' regulations. I'm curious how it's a security risk; as far as I know they have to be unique, which is good

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#157
post #12

Earlier quoted context omitted.

Unfortunately, most carriers (except ATT & Verizon) are just T-Mobile resellers... so you might think you're not using T-Mobile but you're still affected. Even if you use ATT or Verizon, the article mentions they're also hacked and SMS intercepted often.

Honestly, I’d assume being on a MVNO carrier would actually protect you from this, as you’re simply roaming on the T-Mobile network through the carrier agreement. Even ATT and Verizon have roaming agreements. The issue is for T-Mobile direct customers, which obviously their internal systems have access to. I see no reason why T-Mobile would have access to users accounts at another company…

Eg in the 2021 T-Mobile breach, Ting MVNO claimed their users' data was not affected: https://help.ting.com/hc/en-us/community/posts/4405384603291...

Of course you'll still be affected by SIM-swapping etc that just change how your number itself is routed.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#158
post #84
post #8

> T-Mobile declined to answer questions about what it may be doing to beef up employee authentication. But Nicholas Weaver, a researcher and lecturer at University of California, Berkeley’s International Computer Science Institute, said T-Mobile and all the major wireless providers should be requiring employees to use physical security keys for that second factor when logging into company resources. > “These breaches…

I think why regulation hasn’t happened is because the computer industry has changed so quickly. Two-factor auth wasn’t even a commonly accepted best practice two decades ago. And regulation takes a while to create and put into practice and with the rate things are going, by the time regulation has been out in place, the current best practices will have changed. Whereas writing regulation on building bridges is easy b…

That’s assuming you regulate a very specific thing versus the end goal. To me the appropriate regulation is to find a way to cause real harm to T-Mobile when they are breached. When repeated like this or if done through effectively negligence, then they shouldn’t be allowed to be in business anymore. We gotta stop the tiny fines.. jail, billions of dollars in fines, remove their business license… something large needs to happen. Once that’s in place, you won’t need specific regulations as the incentive structure will be there to do the right thing.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#159
post #152
post #73

Earlier quoted context omitted.

I use Google voice for everything... except my bank because they said using T-Mobile is so much more safer than Google so I had to switch back

The prohibition against using a VoIP number for banking purposes is stupid. They already have the full battery of KYC info on me: if I want to use a VoIP number for 2FA (because they are so behind the times they don't support FIDO or even TOTP) then unless law says they cannot they need to allow it. And while on the topic of banks, most will suspend access to your online portal if you log in with a VPN. Give me a ban…

I have Ally and Chime and I’m extremely disappointed neither accepts a Yubikey or something. Older banks like Schwab or US Bank I could see being behind the times, but I’d expect fintech or something more modern to be more sensible.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#160
post #84

Earlier quoted context omitted.

I think why regulation hasn’t happened is because the computer industry has changed so quickly. Two-factor auth wasn’t even a commonly accepted best practice two decades ago. And regulation takes a while to create and put into practice and with the rate things are going, by the time regulation has been out in place, the current best practices will have changed. Whereas writing regulation on building bridges is easy b…

> Two-factor auth wasn't even a commonly accepted best practice two decades ago. Maybe, had you said three decades? But not two. It was already mature by then. Two decades ago was 2003. Even consumer banking was online, and in many countries exclusively 2FA. I've worked the banking space then and we absolutely had smart cards. Military and defense had them everywhere. Proprietary solutions had already gone away repla…

Sure. My dad had a 2FA dongle in the 90s too

But outside of government, defense and banking, who exactly was using it?

It was not on the radar of the vast majority of people. Most technology takes decades to filter through the world

Post reply on HN