June 8, 2009 10:59 AM PDT

T-Mobile investigates possible security breach

by Marguerite Reardon
  • Font size
  • Print
  • 7 comments

Updated at 2:30 p.m. PST with security source comment.

T-Mobile USA is looking into claims that a hacker has broken into its data bases and stolen customer and company information.

Someone anonymously posted the claims on the security mailing list Full Disclosure on Saturday. In that post, the hacker claims to have gotten access to "everything, their databases, confidential documents, scripts and programs from their servers, financial documents up to 2009."

The poster said he had offered the information to T-Mobile competitors, but they supposedly didn't show any interest. Now he says he is offering the information to the highest bidder.

T-Mobile issued a statement that the company is looking into the matter.

"The protection of our customers' information, and the safety and security of our systems, is absolutely paramount at T-Mobile," the company said. "Regarding the recent claim, we are fully investigating the matter. As is our standard practice, if there is any evidence that customer information has been compromised, we would inform those affected as soon as possible."

Some security experts were skeptical of the claims.

"The way this data has been offered is not the way the Underground Economy usually works," said Steve Santorelli, a former Scotland Yard detective who is director of global outreach at security research firm Team Cymru. "Such a highly public offer certainly tends to suggest that this is a hoax or a scam. Many things don't add up: for example, if you'd spent the time to get all this data, surely you'd have a buyer lined up or at least the connections to discretely find a buyer. Now that 'the cat's out of the bag,' the data is worth significantly less on the open market as T-Mobile will be able to put countermeasures in place such as changing passwords."

Kelly Todd, chief communications officer at the Open Security Foundation, said there wasn't enough information publicly available to determine at this time whether the breach is legitimate or not.

"At initial glance I'd say a list like that could be legitimate," he said. However, "I would have to question their comment that they had contacted T-Mobile competitors...You'd think that in order to cover their tracks they would want to take a different route than to contact the competitors."

T-Mobile has had three prior data breaches recorded on the DataLossdb.org site, which the Open Security Foundation runs. In 2005, a teenager was able to get phone numbers of celebrities who use the service; in 2006 a laptop was reported lost that contained social security numbers and addresses of about 45,000 T-Mobile customers; and in October 2008 a disc was reported lost that contained data on about 17 million T-Mobile customers, according to Todd.

CNET News' Elinor Mills contributed to this report.

Marguerite Reardon has been a CNET News reporter since 2004, covering cell phone services, broadband, citywide Wi-Fi, the Net neutrality debate, as well as the ongoing consolidation of the phone companies. E-mail Maggie.
Recent posts from Security
Q&A: Researcher Karsten Nohl on mobile eavesdropping
RockYou sued over data breach
Hacker Gonzalez pleads guilty in Heartland breach
Microsoft rebuts IIS vulnerability claims
More attacks expected on Facebook, Twitter in 2010
GSM crypto code cracked, engineer says
Web-based Lookout protects mobile devices, data
Hackers claim to crack Kindle copyright armor
Add a Comment (Log in or register) (7 Comments)
  • prev
  • 1
  • next
by Michichael June 8, 2009 11:33 AM PDT
Wouldn't surprise me.
Reply to this comment
by gerrrg June 8, 2009 12:39 PM PDT
I wonder if EPIC will actually mention this?
Reply to this comment
by globalist_agenda June 8, 2009 1:44 PM PDT
Another reason to use pre-paid. You give the carriers your SSN, drivers license, birthdate, address, etc. just to get mobile service to send tweets? Are you nuts? Why don't you just put a sign on your door that says "Steal my stuff."?
Reply to this comment
by JCPayne June 8, 2009 5:36 PM PDT
There is NO reason for Mobile carriers to have social security numbers etc. on Laptops. All they need is to verify your information when you sign up. And retrieve it if you don't pay your bill and they have to cancel your account. The T-Mobile is completely liable here. That info should be on computers not connected to the Internet.
Reply to this comment
by globalist_agenda June 8, 2009 11:28 PM PDT
The pukes at Verizon wanted my SSN when they bought out AT&T wireless. I said hell no. I went with T-Mobile pre-paid and never looked back. Just say NO to corporate oligarchs knowing your life history. They are slime who will sell their mothers for a dime. If the president of Verizon will tell me HIS SSN then I will think about telling him mine.
by gordon_geeko June 8, 2009 7:20 PM PDT
Outsourcing can fix everything. They should just hire some hackers to track them down and hire some ex-Navy Seal or Delta Force private military contractors to apprehend them and render them to the nearest CIA interrogation site.
Reply to this comment
by guvenlik-sistemleri July 15, 2009 9:28 AM PDT
Thanks for putting up the information.

<a href="http://www.guvenliksistemleri.info" title="güvenlik sistemi" target=_blank>güvenlik sistemi</a>
Reply to this comment
(7 Comments)
  • prev
  • 1
  • next
advertisement

15 sites that went kaput in 2009

Web sites launch all the time, but they also shut their doors. We highlight 15 that bit the dust this year.

Top 10 news stories of the decade

Let the debate begin: Was the iPhone more important than iTunes? Was anything bigger than Google finding a great business model? CNET offers its list of the 10 most important stories of the '00s.

About Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

Security topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right