Might it be time for the US government to step in using eminent domain, seize the company and merge it into a different provider? Are other providers more secure or do we just hear about T-Mobile the most? Who should take over T-Mobile? [Edit] The more I think about this, perhaps another path to resolution would be to remove limited liability protections from companies that repeatedly put their customers at risk, esp…
What should not have happened is the Sprint T-Mobile merger. Like when Wells Fargo bought the failed bank (forget which one) after 2008, Wells Fargo went from a reliable company to all kinds of suspect things going on with our account. So far T-Mobile has been fine for us but we are seeing some marketing things floating around suggesting the Sprint influence might be having a negative impact on T-Mobile. I miss John…
Hackers claim they breached T-Mobile more than 100 times in 2022
111–120 of 342 posts
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#112I was a victim of this last October and November on a T-Mobile number. This is what occurred: - My Gmail account was compromised - My Amazon account was compromised In Gmail, they added a filter to hide any shipping or customer service messages from Amazon. In Amazon, every other day, they placed an order for a ~500 USD GoPro device, delivered to an address in NYC. This address changed with every order. Both password…
I use Google voice for everything... except my bank because they said using T-Mobile is so much more safer than Google so I had to switch back
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#113The field of competition is very limited, and most consumers I'd guess are either unaware of these problems, feel helpless about them, or don't understand their significance. So what's the pressure exerted on T-Mobile to invest in this problem? There's very little.
Unfortunately, for a system with such a big footprint and given the complexity, you'd need a huge amount of pressure to have a meaningful impact on the problem.
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#114Earlier quoted context omitted.
No 2FA on your GMail? Any idea how G and A were compromised, password reuse?
2FA on everything. No password reused. Only similarity is both had the T-Mobile number attached to them. I initially thought only Amazon was compromised. I thought it was due to us throwing away a FireTV device (assumption: we didn't log out and de-register) that was then used to order items. And then I found they added filters to my Gmail account to hide the Amazon orders, and went into full panic mode.
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#115I was a victim of this last October and November on a T-Mobile number. This is what occurred: - My Gmail account was compromised - My Amazon account was compromised In Gmail, they added a filter to hide any shipping or customer service messages from Amazon. In Amazon, every other day, they placed an order for a ~500 USD GoPro device, delivered to an address in NYC. This address changed with every order. Both password…
[flagged]
15 * 500 = 7,500 USD. Having a steady job should put that within reach.
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#116Earlier quoted context omitted.
2FA on everything. No password reused. Only similarity is both had the T-Mobile number attached to them. I initially thought only Amazon was compromised. I thought it was due to us throwing away a FireTV device (assumption: we didn't log out and de-register) that was then used to order items. And then I found they added filters to my Gmail account to hide the Amazon orders, and went into full panic mode.
Interesting. Was your 2FA setup to use Google Authenticator or regular SMS? It's been a while since I used Google services but from what I recall from a previous company where we used Gmail was that the only way to do 2FA with Google Authenticator if you lost access to the phone was with a backup code you are given at 2FA setup time. Is that no longer the case?
Edit: I can't actually find a help article, but it's under "Try another way to sign-in" and they'll text you a verification code to your registered account phone number.
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#117The cool thing about T-Mobile is they don't ask for your SSN or care about what name you give if you do pre-paid in cash. This anonymity means that if the bad guys call up T-Mobile and know all your details and they even have a compromised employee with full access, the bad guys still can't find out your real IMEI or phone number and do a sim swap. Another benefit is that, with all the cell phone location selling goi…
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#118Earlier quoted context omitted.
Heads up that US mobile is an MVNO operating on T-Mobile and Verizon, so how good their 2FA system is irrelevant if hackers get deep enough into tmobile.
“Deep enough” would be true of any mobile carrier, to date all of these attacks are SIM swapping, with social engineering/phishing being the attack vector. Not particularly deep. Attackers would have to social engineer the MVNO directly, which is certainly easier if they have data they’ve stolen from t-mobile first, but this isn’t a “they’ll get in no matter what because they’ve pwned T-Mobile so bad” scenario.
This article says that Google Fi customers were SIM swapped due to a T-Mobile breach. Even though "[t]here was no access to Google's systems or any systems overseen by Google."
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#119Earlier quoted context omitted.
No 2FA on your GMail? Any idea how G and A were compromised, password reuse?
2FA on everything. No password reused. Only similarity is both had the T-Mobile number attached to them. I initially thought only Amazon was compromised. I thought it was due to us throwing away a FireTV device (assumption: we didn't log out and de-register) that was then used to order items. And then I found they added filters to my Gmail account to hide the Amazon orders, and went into full panic mode.
I wonder then what the point is of having 2FA at all if you can just click a few buttons to bypass them with an SMS.
Were you specifically targeted in any way that would make the attackers go find your phone number and perform the swap?
Re: Hackers claim they breached T-Mobile more than 100 times in 2022
#120The cool thing about T-Mobile is they don't ask for your SSN or care about what name you give if you do pre-paid in cash. This anonymity means that if the bad guys call up T-Mobile and know all your details and they even have a compromised employee with full access, the bad guys still can't find out your real IMEI or phone number and do a sim swap. Another benefit is that, with all the cell phone location selling goi…
You can put a customer service password on your tmobile account to avoid anyone calling customer service without that password to make any changes. This is separate from your online portal password.