Jump to content

Reports of massive data breach at T-Mobile (100 Million users)

Techie_Freak 99

Summary

Reports of a massive data breach at T-Mobile. Post on an underground forum, as reported by Vice, claims that they have customer info (ssn, imei numbers, physical address etc) for 100 Million users.

They are selling some info for Bitcoin equivalent of $270,000. T-Mobile has not confirmed it as they are investigating the reports as of the time of posting. 

 

Keep in mind, this is an unconfirmed and developing story. I will try to update when more info is released!

 

Quotes

Quote

Quote 1: "T-Mobile USA. Full customer info," the seller told Motherboard in an online chat. The seller said they compromised multiple servers related to T-Mobile.

Quote 2: The data includes social security numbers, phone numbers, names, physical addresses, unique IMEI numbers, and driver licenses information, the seller said. They said that although it appears T-Mobile has since kicked them out of the hacked servers, the seller had already downloaded the data locally.

 

My thoughts

Another situation like Experian, a few years ago?

 

Sources

https://www.vice.com/en/article/akg8wg/tmobile-investigating-customer-data-breach-100-million

https://www.reuters.com/business/media-telecom/t-mobile-investigating-claims-customer-data-breach-vice-2021-08-15/

Link to comment
Share on other sites

Link to post
Share on other sites

That's a major yikes if this turns out to all be true. I really hope it doesn't turn into another Experian again but it probably will all things considered and I'm sure it will be blamed on some single employee or someone who forgot to do something or it will turn out they didn't invest it well rounded security practices and whatnot.

Current Network Layout:

Current Build Log/PC:

Prior Build Log/PC:

Link to comment
Share on other sites

Link to post
Share on other sites

Big yikes if true, but seems very very low cost for the data, 270k? With that kind of information and data I would expect to see at least a 7 or 8 figured number. 

Community Standards | Fan Control Software

Please make sure to Quote me or @ me to see your reply!

Just because I am a Moderator does not mean I am always right. Please fact check me and verify my answer. 

 

"Black Out"

Ryzen 9 5900x | Full Custom Water Loop | Asus Crosshair VIII Hero (Wi-Fi) | RTX 3090 Founders | Ballistix 32gb 16-18-18-36 3600mhz 

1tb Samsung 970 Evo | 2x 2tb Crucial MX500 SSD | Fractal Design Meshify S2 | Corsair HX1200 PSU

 

Dedicated Streaming Rig

 Ryzen 7 3700x | Asus B450-F Strix | 16gb Gskill Flare X 3200mhz | Corsair RM550x PSU | Asus Strix GTX1070 | 250gb 860 Evo m.2

Phanteks P300A |  Elgato HD60 Pro | Avermedia Live Gamer Duo | Avermedia 4k GC573 Capture Card

 

Link to comment
Share on other sites

Link to post
Share on other sites

3 minutes ago, Skiiwee29 said:

Big yikes if true, but seems very very low cost for the data, 270k? With that kind of information and data I would expect to see at least a 7 or 8 figured number. 

From the Vice article:

Quote

On the underground forum the seller is asking for 6 bitcoin, around $270,000, for a subset of the data containing 30 million social security numbers and driver licenses. The seller said they are privately selling the rest of the data at the moment.

So it’s 270k for 30 million SSNs and driver licenses and the rest is being sold privately. I was thinking the same thing though, that seems like a low number for that amount of data.

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, The_russian said:

From the Vice article:

So it’s 270k for 30 million SSNs and driver licenses and the rest is being sold privately. I was thinking the same thing though, that seems like a low number for that amount of data.

This is probably a "taste". Next offer would probably substantially more expensive!!!

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, StDragon said:

This is probably a "taste". Next offer would probably substantially more expensive!!!

That and also probably to verify the data is actually legitimate and not just some auto-generated numbers.

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, Techie_Freak 99 said:

data includes social security numbers, phone numbers, names, physical addresses, unique IMEI numbers, and driver licenses information, the seller said.

Who the hell gave them their SSN and Drivers License numbers.

I use T-Mobile and they never asked me that info, had they did, I would not have given it. If people really did, foolish move. 🤦‍♂️

COMMUNITY STANDARDS   |   TECH NEWS POSTING GUIDELINES   |   FORUM STAFF

LTT Folding Users Tips, Tricks and FAQ   |   F@H & BOINC Badge Request   |   F@H Contribution    My Rig   |   Project Steamroller

I am a Moderator, but I am fallible. Discuss or debate with me as you will but please do not argue with me as that will get us nowhere.

 

Spoiler

  

 

Character is like a Tree and Reputation like its Shadow. The Shadow is what we think of it; The Tree is the Real thing.  ~ Abraham Lincoln

Reputation is a Lifetime to create but seconds to destroy.

You have enemies? Good. That means you've stood up for something, sometime in your life.  ~ Winston Churchill

Docendo discimus - "to teach is to learn"

 

 CHRISTIAN MEMBER 

 

 
 
 
 
 
 

 

Link to comment
Share on other sites

Link to post
Share on other sites

Man, I'll be interested to see where this goes. That's a lot of info. 

Phobos: AMD Ryzen 7 2700, 16GB 3000MHz DDR4, ASRock B450 Steel Legend, 8GB Nvidia GeForce RTX 2070, 2GB Nvidia GeForce GT 1030, 1TB Samsung SSD 980, 450W Corsair CXM, Corsair Carbide 175R, Windows 10 Pro

 

Polaris: Intel Xeon E5-2697 v2, 32GB 1600MHz DDR3, ASRock X79 Extreme6, 12GB Nvidia GeForce RTX 3080, 6GB Nvidia GeForce GTX 1660 Ti, 1TB Crucial MX500, 750W Corsair RM750, Antec SX635, Windows 10 Pro

 

Pluto: Intel Core i7-2600, 32GB 1600MHz DDR3, ASUS P8Z68-V, 4GB XFX AMD Radeon RX 570, 8GB ASUS AMD Radeon RX 570, 1TB Samsung 860 EVO, 3TB Seagate BarraCuda, 750W EVGA BQ, Fractal Design Focus G, Windows 10 Pro for Workstations

 

York (NAS): Intel Core i5-2400, 16GB 1600MHz DDR3, HP Compaq OEM, 240GB Kingston V300 (boot), 3x2TB Seagate BarraCuda, 320W HP PSU, HP Compaq 6200 Pro, TrueNAS CORE (12.0)

Link to comment
Share on other sites

Link to post
Share on other sites

T-Mobile got most of their customer DB hacked a couple of years ago. So, it isn't even the first time. But it's the first time after the merger? (Not sure if the systems are all integrated yet.)

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, SansVarnic said:

Who the hell gave them their SSN and Drivers License numbers.

I use T-Mobile and they never asked me that info, had they did, I would not have given it. If people really did, foolish move. 🤦‍♂️

I imagine there is a DB out there with SSNs + Names that could be easily merged with hard name + address data.

Link to comment
Share on other sites

Link to post
Share on other sites

18 minutes ago, Taf the Ghost said:

I imagine there is a DB out there with SSNs + Names that could be easily merged with hard name + address data.

Possible, at least I can rest assured mine won't be one of those. I dont give out my ssn to anyone for any reason. 👍

COMMUNITY STANDARDS   |   TECH NEWS POSTING GUIDELINES   |   FORUM STAFF

LTT Folding Users Tips, Tricks and FAQ   |   F@H & BOINC Badge Request   |   F@H Contribution    My Rig   |   Project Steamroller

I am a Moderator, but I am fallible. Discuss or debate with me as you will but please do not argue with me as that will get us nowhere.

 

Spoiler

  

 

Character is like a Tree and Reputation like its Shadow. The Shadow is what we think of it; The Tree is the Real thing.  ~ Abraham Lincoln

Reputation is a Lifetime to create but seconds to destroy.

You have enemies? Good. That means you've stood up for something, sometime in your life.  ~ Winston Churchill

Docendo discimus - "to teach is to learn"

 

 CHRISTIAN MEMBER 

 

 
 
 
 
 
 

 

Link to comment
Share on other sites

Link to post
Share on other sites

i'm so glad Australia doesn't have an equivalent of an SSN, too much power is given to a single number and is always the target in attacks like this.

🌲🌲🌲

 

 

 

◒ ◒ 

Link to comment
Share on other sites

Link to post
Share on other sites

Well fuck me. I am a t-mobile customer...

This looks really bad and can allow someone to do some nasty shit.

Be sure to @Pickles von Brine if you want me to see your reply!

Stopping by to praise the all mighty jar Lord pickles... * drinks from a chalice of holy pickle juice and tossed dill over shoulder* ~ @WarDance
3600x | NH-D15 Chromax Black | 32GB 3200MHz | ASUS KO RTX 3070 UnderVolted and UnderClocked | Gigabyte Aorus Elite AX X570S | Seasonic X760w | Phanteks Evolv X | 500GB WD_Black SN750 x2 | Sandisk Skyhawk 3.84TB SSD 

Link to comment
Share on other sites

Link to post
Share on other sites

mmmmmmmmmmmmmm don't like this one bit

Main rig on profile

VAULT - File Server

Spoiler

Intel Core i5 11400 w/ Shadow Rock LP, 2x16GB SP GAMING 3200MHz CL16, ASUS PRIME Z590-A, 2x LSI 9211-8i, Fractal Define 7, 256GB Team MP33, 3x 6TB WD Red Pro (general storage), 3x 1TB Seagate Barracuda (dumping ground), 3x 8TB WD White-Label (Plex) (all 3 arrays in their respective Windows Parity storage spaces), Corsair RM750x, Windows 11 Education

Sleeper HP Pavilion A6137C

Spoiler

Intel Core i7 6700K @ 4.4GHz, 4x8GB G.SKILL Ares 1800MHz CL10, ASUS Z170M-E D3, 128GB Team MP33, 1TB Seagate Barracuda, 320GB Samsung Spinpoint (for video capture), MSI GTX 970 100ME, EVGA 650G1, Windows 10 Pro

Mac Mini (Late 2020)

Spoiler

Apple M1, 8GB RAM, 256GB, macOS Sonoma

Consoles: Softmodded 1.4 Xbox w/ 500GB HDD, Xbox 360 Elite 120GB Falcon, XB1X w/2TB MX500, Xbox Series X, PS1 1001, PS2 Slim 70000 w/ FreeMcBoot, PS4 Pro 7015B 1TB (retired), PS5 Digital, Nintendo Switch OLED, Nintendo Wii RVL-001 (black)

Link to comment
Share on other sites

Link to post
Share on other sites

I never gave T-Mobile my SSN. Don't think Sprint has it either...

Laptop: 2019 16" MacBook Pro i7, 512GB, 5300M 4GB, 16GB DDR4 | Phone: iPhone 13 Pro Max 128GB | Wearables: Apple Watch SE | Car: 2007 Ford Taurus SE | CPU: R7 5700X | Mobo: ASRock B450M Pro4 | RAM: 32GB 3200 | GPU: ASRock RX 5700 8GB | Case: Apple PowerMac G5 | OS: Win 11 | Storage: 1TB Crucial P3 NVME SSD, 1TB PNY CS900, & 4TB WD Blue HDD | PSU: Be Quiet! Pure Power 11 600W | Display: LG 27GL83A-B 1440p @ 144Hz, Dell S2719DGF 1440p @144Hz | Cooling: Wraith Prism | Keyboard: G610 Orion Cherry MX Brown | Mouse: G305 | Audio: Audio Technica ATH-M50X & Blue Snowball | Server: 2018 Core i3 Mac mini, 128GB SSD, Intel UHD 630, 16GB DDR4 | Storage: OWC Mercury Elite Pro Quad (6TB WD Blue HDD, 12TB Seagate Barracuda, 1TB Crucial SSD, 2TB Seagate Barracuda HDD)
Link to comment
Share on other sites

Link to post
Share on other sites

14 hours ago, SansVarnic said:

Who the hell gave them their SSN and Drivers License numbers.

I use T-Mobile and they never asked me that info, had they did, I would not have given it. If people really did, foolish move. 🤦‍♂️

Credit checks is the only thing I can think of for some customers or plans?

Current Network Layout:

Current Build Log/PC:

Prior Build Log/PC:

Link to comment
Share on other sites

Link to post
Share on other sites

Meh, really doesn't matter, all our data everywhere is hacked.

Link to comment
Share on other sites

Link to post
Share on other sites

16 hours ago, SansVarnic said:

Possible, at least I can rest assured mine won't be one of those. I dont give out my ssn to anyone for any reason. 👍

I was thinking the exact same thing.  At least here, there isn't any reason to give out your SSN unless if it's for literally a job.

 

2 hours ago, Lurick said:

Credit checks is the only thing I can think of for some customers or plans?

hmm maybe...but do the phone carriers in the US do that?  Even on my plan, where I got a credit card...it was only putting in my SIN with the associated bank (and my carrier didn't get my SIN number)

3735928559 - Beware of the dead beef

Link to comment
Share on other sites

Link to post
Share on other sites

19 hours ago, SansVarnic said:

Who the hell gave them their SSN and Drivers License numbers.

I use T-Mobile and they never asked me that info, had they did, I would not have given it. If people really did, foolish move. 🤦‍♂️

You would be surprised how many people with poor credit sign up for accounts. These providers are demanding information up-front so they can later go after them for collections if they default on their account.

Link to comment
Share on other sites

Link to post
Share on other sites

20 hours ago, Skiiwee29 said:

Big yikes if true, but seems very very low cost for the data, 270k? With that kind of information and data I would expect to see at least a 7 or 8 figured number. 

I thought it was rather low as well, considering the potential value of the alleged data contained. 

Link to comment
Share on other sites

Link to post
Share on other sites

39 minutes ago, lostcattears said:

Thank god I never used T-mobile 

Thank god I didnt use <insert latest company data breach> ... 🙄

Ok.

COMMUNITY STANDARDS   |   TECH NEWS POSTING GUIDELINES   |   FORUM STAFF

LTT Folding Users Tips, Tricks and FAQ   |   F@H & BOINC Badge Request   |   F@H Contribution    My Rig   |   Project Steamroller

I am a Moderator, but I am fallible. Discuss or debate with me as you will but please do not argue with me as that will get us nowhere.

 

Spoiler

  

 

Character is like a Tree and Reputation like its Shadow. The Shadow is what we think of it; The Tree is the Real thing.  ~ Abraham Lincoln

Reputation is a Lifetime to create but seconds to destroy.

You have enemies? Good. That means you've stood up for something, sometime in your life.  ~ Winston Churchill

Docendo discimus - "to teach is to learn"

 

 CHRISTIAN MEMBER 

 

 
 
 
 
 
 

 

Link to comment
Share on other sites

Link to post
Share on other sites

For anyone keeping an eye on this, T-Mobile confirmed in a blog post that customer data was accessed/stolen. 

 

Quote
  • Late last week we were informed of claims made in an online forum that a bad actor had compromised T-Mobile systems. We immediately began an exhaustive investigation into these claims and brought in world-leading cybersecurity experts to help with our assessment.
  • We then located and immediately closed the access point that we believe was used to illegally gain entry to our servers.
  • Yesterday, we were able to verify that a subset of T-Mobile data had been accessed by unauthorized individuals. We also began coordination with law enforcement as our forensic investigation continued.
  • While our investigation is still underway and we continue to learn additional details, we have now been able to confirm that the data stolen from our systems did include some personal information.
  • We have no indication that the data contained in the stolen files included any customer financial information, credit card information, debit or other payment information.
  • Some of the data accessed did include customers’ first and last names, date of birth, SSN, and driver’s license/ID information for a subset of current and former postpay customers and prospective T-Mobile customers. 
  • Our preliminary analysis is that approximately 7.8 million current T-Mobile postpaid customer accounts’ information appears to be contained in the stolen files, as well as just over 40 million records of former or prospective customers who had previously applied for credit with T-Mobile. Importantly, no phone numbers, account numbers, PINs, passwords, or financial information were compromised in any of these files of customers or prospective customers.
  • As a result of this finding, we are taking immediate steps to help protect all of the individuals who may be at risk from this cyberattack. Communications will be issued shortly to customers outlining that T-Mobile is:
    • Immediately offering 2 years of free identity protection services with McAfee’s ID Theft Protection Service.
    • Recommending all T-Mobile postpaid customers proactively change their PIN by going online into their T-Mobile account or calling our Customer Care team by dialing 611 on your phone. This precaution is despite the fact that we have no knowledge that any postpaid account PINs were compromised.
    • Offering an extra step to protect your mobile account with our Account Takeover Protection capabilities for postpaid customers, which makes it harder for customer accounts to be fraudulently ported out and stolen.
    • Publishing a unique web page later on Wednesday for one stop information and solutions to help customers take steps to further protect themselves. 
  • At this time, we have also been able to confirm approximately 850,000 active T-Mobile prepaid customer names, phone numbers and account PINs were also exposed. We have already proactively reset ALL of the PINs on these accounts to help protect these customers, and we will be notifying accordingly right away. No Metro by T-Mobile, former Sprint prepaid, or Boost customers had their names or PINs exposed.
  • We have also confirmed that there was some additional information from inactive prepaid accounts accessed through prepaid billing files. No customer financial information, credit card information, debit or other payment information or SSN was in this inactive file.

 

Source: 

https://www.t-mobile.com/news/network/additional-information-regarding-2021-cyberattack-investigation

Link to comment
Share on other sites

Link to post
Share on other sites

On 8/15/2021 at 7:54 PM, SansVarnic said:

Possible, at least I can rest assured mine won't be one of those. I dont give out my ssn to anyone for any reason. 👍

Have you never financed anything? All credit inquires will require your ssn.

Primary Gaming Rig:

Ryzen 5 5600 CPU, Gigabyte B450 I AORUS PRO WIFI mITX motherboard, PNY XLR8 16GB (2x8GB) DDR4-3200 CL16 RAM, Mushkin PILOT 500GB SSD (boot), Corsair Force 3 480GB SSD (games), XFX RX 5700 8GB GPU, Fractal Design Node 202 HTPC Case, Corsair SF 450 W 80+ Gold SFX PSU, Windows 11 Pro, Dell S2719DGF 27.0" 2560x1440 155 Hz Monitor, Corsair K68 RGB Wired Gaming Keyboard (MX Brown), Logitech G900 CHAOS SPECTRUM Wireless Mouse, Logitech G533 Headset

 

HTPC/Gaming Rig:

Ryzen 7 3700X CPU, ASRock B450M Pro4 mATX Motherboard, ADATA XPG GAMMIX D20 16GB (2x8GB) DDR4-3200 CL16 RAM, Mushkin PILOT 1TB SSD (boot), 2x Seagate BarraCuda 1 TB 3.5" HDD (data), Seagate BarraCuda 4 TB 3.5" HDD (DVR), PowerColor RX VEGA 56 8GB GPU, Fractal Design Node 804 mATX Case, Cooler Master MasterWatt 550 W 80+ Bronze Semi-modular ATX PSU, Silverstone SST-SOB02 Blu-Ray Writer, Windows 11 Pro, Logitech K400 Plus Keyboard, Corsair K63 Lapboard Combo (MX Red w/Blue LED), Logitech G603 Wireless Mouse, Kingston HyperX Cloud Stinger Headset, HAUPPAUGE WinTV-quadHD TV Tuner, Samsung 65RU9000 TV

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×