Live data from Hacker News

Hackers claim they breached T-Mobile more than 100 times in 2022

krebsonsecurity.com

271–280 of 342 posts

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#271

How does one protect themselves from this? I have an iphone with esim and 2FA on most things, but there are still use cases that send codes via text.

Most of these breaches happen because someone gets targeted - something about their public profile lands them on the radar of the hackers. Then the hackers dig into the profile looking for associated phone numbers. So to mitigate this, you could (1) reduce your public profile, which is out of scope here, and/or (2) minimize phone number exposure. You want to make it impossible for someone targeting you to locate the…

I guess I am screwed. Breaches for lastpass and twitter alone link my phone and email and websites :(

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#272

You know, I’m starting to become slightly more serious about switching carriers solely based on how terrible it would be to experience SMS/Call diverting of my number. While I use a yubikey, OTP (where possible), and unique passwords…there’s still places where I have no choice and my number is my auth (or stupidly a reset option). I genuinely am happy with TMO service in the US, and frankly abroad it’s excellent…but…

It's the sole reason I'm still with Google Fi, the fear of sim swaps and my (hopefully not mistaken) belief that Google Fi is less hackable than the big 3. I've certainly read that here, many times.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#273
post #242
post #65

I was a victim of this last October and November on a T-Mobile number. This is what occurred: - My Gmail account was compromised - My Amazon account was compromised In Gmail, they added a filter to hide any shipping or customer service messages from Amazon. In Amazon, every other day, they placed an order for a ~500 USD GoPro device, delivered to an address in NYC. This address changed with every order. Both password…

As an InfoSec professional, what you describe sounds more like a device-level compromise of your iphone, perhaps through a malicious app, or link you clicked. What your experienced can't be done with just a sim swap attack, as you would have lost access to your phone number. And it can't be done with the described T-Mobile hack, as it would have given the hackers silent access to your texts, so they could have reset…

Honestly I’m a bit concerned an infosec professional has reached for “iOS device compromise” over a…more common and lower-effort explanation.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#274
post #73
post #65

I was a victim of this last October and November on a T-Mobile number. This is what occurred: - My Gmail account was compromised - My Amazon account was compromised In Gmail, they added a filter to hide any shipping or customer service messages from Amazon. In Amazon, every other day, they placed an order for a ~500 USD GoPro device, delivered to an address in NYC. This address changed with every order. Both password…

I use Google voice for everything... except my bank because they said using T-Mobile is so much more safer than Google so I had to switch back

Ally forced me recently to get rid of the Google Voice (GV) number and email for two-factor and use a 'real' mobile number. It is pretty awful how they offer no other two-factor mechanism except a non-GV mobile number.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#275

Earlier quoted context omitted.

> they pay-off / trick a T-Mobile employee into re-assigning your Google Voice number to them. Are you saying the Google Voice phone number lock is useless and that any carrier can just steal Google Voice numbers regardless of the lock status?

here is a link to a report of that happening to a Google Fi customer: https://old.reddit.com/r/GoogleFi/comments/10pjtie/google_fi... I don't work at Google and don't know if this is possible with Google Voice. However, Google Fi is their paid service, so I would assume that's the one they'd want to protect the most.

Google Fi has actual SIM cards and behaves like a regular carrier, Voice does not.

There arent any SIM cards to be hijacked with Voice because it don't provide cell service.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#276
post #65

I was a victim of this last October and November on a T-Mobile number. This is what occurred: - My Gmail account was compromised - My Amazon account was compromised In Gmail, they added a filter to hide any shipping or customer service messages from Amazon. In Amazon, every other day, they placed an order for a ~500 USD GoPro device, delivered to an address in NYC. This address changed with every order. Both password…

Googlefi just uses their towers, your telecom data isn’t communicated with T-Mobile just the data of whatever you’re using (calls Netflix browsing porn)

Recently Googlefi also reported that as a result of a likely T-Mobile related breach, they also lost data including sim numbers: https://www.reddit.com/r/GoogleFi/comments/10pjtie/google_fi... .

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#277
post #8

> T-Mobile declined to answer questions about what it may be doing to beef up employee authentication. But Nicholas Weaver, a researcher and lecturer at University of California, Berkeley’s International Computer Science Institute, said T-Mobile and all the major wireless providers should be requiring employees to use physical security keys for that second factor when logging into company resources. > “These breaches…

This "UnCarrier" should be forced to "UnExist". Their leaks are numerous and the pathetic amounts they pay in damages do nothing to adequately compensate for the risk and inconvenience they impose on their hapless customers. Their insistence on doing credit checks for everything instead of allowing cash customers to skip it is I think part of the problem.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#278
post #242

Earlier quoted context omitted.

As an InfoSec professional, what you describe sounds more like a device-level compromise of your iphone, perhaps through a malicious app, or link you clicked. What your experienced can't be done with just a sim swap attack, as you would have lost access to your phone number. And it can't be done with the described T-Mobile hack, as it would have given the hackers silent access to your texts, so they could have reset…

Honestly I’m a bit concerned an infosec professional has reached for “iOS device compromise” over a…more common and lower-effort explanation.

If you believe Apple's marketing that iPhones are unhackable, I have a bridge to sell you.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#279
post #26

> Phish T-Mobile employees for access to internal company tools, and then convert that access into a cybercrime service that could be hired to divert any T-Mobile user’s text messages and phone calls to another device. If they are doing all this through phishing and aren't being as successful with other networks there's some serious issue that's being overlooked. It's unclear from the article if this is due to traini…

> But there's still a large number of sites and services that rely on SMS. I avoid using my actual phone number whenever possible and use a Google Voice number. Hacking Google Voice would require hacking my actual Google account instead of just tricking someone at the phone company.

Same here, but note that a lot of banks have now started to look at the underlying carrier and often deny the use 'voip-like' services such as GV.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#280
post #278

Earlier quoted context omitted.

Honestly I’m a bit concerned an infosec professional has reached for “iOS device compromise” over a…more common and lower-effort explanation.

If you believe Apple's marketing that iPhones are unhackable, I have a bridge to sell you.

Why would someone burn a device level exploit for $5k when you could sell the exploit for 10x or even 100x more?

Sounds like an easy way to burn your exploit after using it a few times to get electronics off Amazon.

Post reply on HN