Live data from Hacker News

Hackers claim they breached T-Mobile more than 100 times in 2022

krebsonsecurity.com

281–290 of 342 posts

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#281
post #65

I was a victim of this last October and November on a T-Mobile number. This is what occurred: - My Gmail account was compromised - My Amazon account was compromised In Gmail, they added a filter to hide any shipping or customer service messages from Amazon. In Amazon, every other day, they placed an order for a ~500 USD GoPro device, delivered to an address in NYC. This address changed with every order. Both password…

Something doesn't add up here because last I checked Amazon made you put the credit card number in again if you want to ship to a new address. Just breaking in to your amazon account wouldn't be sufficient to ship stuff to random addresses using your credit card.

> Something doesn't add up here because last I checked Amazon made you put the credit card number in again if you want to ship to a new address.

Not always.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#282
post #278

Earlier quoted context omitted.

Honestly I’m a bit concerned an infosec professional has reached for “iOS device compromise” over a…more common and lower-effort explanation.

If you believe Apple's marketing that iPhones are unhackable, I have a bridge to sell you.

No need to be aggro about it. No one’s suggesting iPhones are unhackable, just that realistically utilizing an iOS or Android exploit like that is a bit much for something simple like credit card fraud. Those exploits are valuable.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#283

Earlier quoted context omitted.

Simjacking. https://en.wikipedia.org/wiki/SIM_swap_scam

Wait. Isn't it painfully obvious when you've been simjacked? If your phone suddenly loses signal and refuses to register with the network, you know something is up. You may think it was a malfunction of your phone or your network, but it's pretty much a definition of a modern-day "drop everything you're doing and deal with it" emergency. You can't not be aware of it, or be unsure if it happened to you.

So maybe the attackers just wait for the right moment to strike. Like say Feb 13th. https://www.reuters.com/business/media-telecom/t-mobile-down...

But if the attacker already has your info, then couldn't they just add another line to your mobile plan, so your handset continues working, just with a new, unbeknownst to you phone number? That way it wouldn't be noticable on the handset.

The real question is how long do you think it would take you to break into your own Gmail account after the passwords been changed and the attached phone numbers also been changed?

Probably longer than it would take an attacker to drain bank accounts, I figure.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#284

My approach to this is to use a google voice phone number where all SMS get sent to email. The voice account and the gmail account are the same google account which is secure by hardware 2FA yubikey login. I have a cell phone with an entirely different number that I use for non-2FA things so if it gets compromised i'm OK. I do access that email from that phone, so I suppose i'm a bit vulnerable to targeted phone thef…

This works pretty well until google decides to block your account randomly one day.

Is this something that happens sometimes? I guess I hadn't considered that very likely but maybe I should be more concerned.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#285
post #65

I was a victim of this last October and November on a T-Mobile number. This is what occurred: - My Gmail account was compromised - My Amazon account was compromised In Gmail, they added a filter to hide any shipping or customer service messages from Amazon. In Amazon, every other day, they placed an order for a ~500 USD GoPro device, delivered to an address in NYC. This address changed with every order. Both password…

I no longer have SMS enabled as a MFA for this exact reason on services. Only physical or digital authenticator where necessary.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#286

Earlier quoted context omitted.

Remove it from both. However make sure that you have quite a lot of backups of your 2FA backup keys, and maybe even one offline backup of your seed, if you lose them, the account is gone (which is a good thing, I guess).

Thanks. I have Google backup codes as well as multiple Authy installations, Google prompt and a recovery email address so I guess I should be covered :)

What is "Google prompt" here?

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#287

Earlier quoted context omitted.

I was about to comment the same thing. It's very simple but I don't think I would have thought of it

It's quite common, in fact my "go-to" hacked account rule in Office 365 is "alert me, system admin, anytime anyone creates an outlook/exchange rule". Our group is small enough that I get very few alerts at all, and I've caught two compromises that way.

Do you know if those alerts can also be set up on Google Admin?

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#288
post #76

You know, I’m starting to become slightly more serious about switching carriers solely based on how terrible it would be to experience SMS/Call diverting of my number. While I use a yubikey, OTP (where possible), and unique passwords…there’s still places where I have no choice and my number is my auth (or stupidly a reset option). I genuinely am happy with TMO service in the US, and frankly abroad it’s excellent…but…

On that topic, does anyone know about a good alternative that can be used just for a secure SMS number? Google Voice has been mentioned several times but it's unclear to me how that helps.

It helps. I try to use an authenticator app whenever possible, but use a Google Voice number if a service requires SMS-based auth. The trick is to not forward the texts to another cell number. You can either view them using the Voice web interface, or forward them to your Gmail on the same account. Then lock that Google account down as much as possible. I use Advanced Protection (https://landing.google.com/advancedprotection/). This is WAY more secure than using T-Mobile or another cell provider's SMS.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#289

Earlier quoted context omitted.

TMobile seems to be particularly bad right now, but Verizon and AT&T aren’t necessarily good. The weak link is usually retail or channel. TMobile is in a high growth phase, so I’d hazard to guess they are more disorganized. Switching to Verizon may reduce exposure, but they have their own similar issues - an aggressively dumb carrier employee is capable of almost anything.

Also consider that T-Mobile as it exists is the result of years/decades of mergers and acquisitions so they have decades of legacy and non-conforming systems. This situation is bound to cause security issues as well. I had a family member work for an MVNO that interfaced with them and this is what she saw.

>"Also consider that T-Mobile as it exists is the result of years/decades of mergers and acquisitions so they have decades of legacy and non-conforming systems."

This is true of just about every single mobile carrier today. In fact this is true of all telecom companies for most of their history from mobile carriers, to cable companies to ISPs. The entire telecom industry is an unending series of consolidation and acquisition of assets. This is already 12 years out of date but this should give you an idea:

https://archive.is/fjZQ0

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#290
post #278

Earlier quoted context omitted.

Honestly I’m a bit concerned an infosec professional has reached for “iOS device compromise” over a…more common and lower-effort explanation.

If you believe Apple's marketing that iPhones are unhackable, I have a bridge to sell you.

Would you cite the marketing to which you referred? I’ve never seen it.
Post reply on HN