Live data from Hacker News

Hackers claim they breached T-Mobile more than 100 times in 2022

krebsonsecurity.com

321–330 of 342 posts

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#321
post #280
post #278

Earlier quoted context omitted.

If you believe Apple's marketing that iPhones are unhackable, I have a bridge to sell you.

Why would someone burn a device level exploit for $5k when you could sell the exploit for 10x or even 100x more? Sounds like an easy way to burn your exploit after using it a few times to get electronics off Amazon.

What makes you think this was used for only $5k? In these cases, hackers usually target many victims, not just one.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#322

I worked for TMobile for 4 days in 2021. I don't usually apply to big companies but money was tight because pandemic and I needed a job quick. I was assigned to work on the config server (think in-house developed consul or etcd) and it was awful. "If this specific config value is being set by Service A then what is actually written should be twice the given value, but if Service B is reading the value, return 1/3 of…

> TMobile getting hacked is a "when" not an "if"

I think something more accurate is

> TMobile getting hacked is a 'how many times', not a when

But adjust further...

> All cell providers getting hacked is a 'how many times', not a 'which'

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#323
post #65

I was a victim of this last October and November on a T-Mobile number. This is what occurred: - My Gmail account was compromised - My Amazon account was compromised In Gmail, they added a filter to hide any shipping or customer service messages from Amazon. In Amazon, every other day, they placed an order for a ~500 USD GoPro device, delivered to an address in NYC. This address changed with every order. Both password…

So if you didn't have a credit card, nothing would have happened? Why do people still use credit cards if they are so fucking leaky and easy to exploit?

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#324

Earlier quoted context omitted.

There must be something especially lucrative about GoPros as stolen devices. I’ve heard multiple independent stories from a few friends in Law Enforcement about cases involving trafficking of large quantities of stolen GoPros (obtained via methods not unlike what happened to you). Interesting you mention NYC - at least one of these cases involved a very high volume fencing syndicate operating as a legitimate storefro…

If you go on ebay, you can find tons of shady gopro listings. They'll have all the original packaging and put it up as a "pre-owned" unit, but then you open the listing and they have 20 of them for sale. We also had a local hotel/waterpark that was running a burglary/fencing operation in the mid aughts. The room cleaners would look for gopros, iphones and other electronics. If they found anything, they'd take it and…

It sounds like an example where review sites help warn others where management and the local police do nothing.

If you're the victim of a crime, you should do the police report yourself - also for things like insurance claims.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#325

Earlier quoted context omitted.

an executive or two in jail and we'll sure enough see security magically happen.

Should we throw the President in jail if the government gets breached?

If he incited the breach, sure.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#326

I worked for TMobile for 4 days in 2021. I don't usually apply to big companies but money was tight because pandemic and I needed a job quick. I was assigned to work on the config server (think in-house developed consul or etcd) and it was awful. "If this specific config value is being set by Service A then what is actually written should be twice the given value, but if Service B is reading the value, return 1/3 of…

> By Thursday I got a call about a new position and I left so quick that the recruiters black listed me.

That's one way to reduce headhunting spam.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#327

This follows on the unpopular news story that T-Mobile will be requiring you to give them your debit card or bank account information to continue to qualify for their Autopay discount. https://www.cnet.com/tech/mobile/t-mobile-is-dropping-its-au...

How would you do autopay without giving them either a credit card or bank wire info? Seems at least one of those is required.

The story is that they’re no longer allowing you to get the AutoPay discount with a credit card so you’ll have to set up AutoPay with a debit card or bank account by May to continue to receive the discount.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#328

Earlier quoted context omitted.

What is "Google prompt" here?

It’s a notification pop-up the Google mobile app can send, asking for login confirmation.

I see, but doesn't have the same issue as sending an SMS to the phone if the phone has been stolen in that the thief can just say "yes" to the prompt?

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#329

I worked for TMobile for 4 days in 2021. I don't usually apply to big companies but money was tight because pandemic and I needed a job quick. I was assigned to work on the config server (think in-house developed consul or etcd) and it was awful. "If this specific config value is being set by Service A then what is actually written should be twice the given value, but if Service B is reading the value, return 1/3 of…

> By Thursday I got a call about a new position and I left so quick that the recruiters black listed me. That's one way to reduce headhunting spam.

Meh, I never worked with that recruiter before. Turns out they have a policy that if you quit without a 2 weeks notice you're black listed which to be fair makes a lot of sense. But I didn't just get a call about a new job, it was a previous boss I really respect starting up a new company.

Re: Hackers claim they breached T-Mobile more than 100 times in 2022

#330
post #65

I was a victim of this last October and November on a T-Mobile number. This is what occurred: - My Gmail account was compromised - My Amazon account was compromised In Gmail, they added a filter to hide any shipping or customer service messages from Amazon. In Amazon, every other day, they placed an order for a ~500 USD GoPro device, delivered to an address in NYC. This address changed with every order. Both password…

This is why you don’t use sms as 2FA. And use iOS. We’re you using android?

Or GrapheneOS. Or just stop visiting sketchy sites and running sketchy applications. That will eliminate 98% of your problems.
Post reply on HN