T-Mobile says network was not hacked or breached
A T-Mobile spokesman said on Tuesday that data someone posted to a security e-mail list over the weekend was legitimate T-Mobile data but not customer information, and that the phone company's network was not hacked or breached as the poster claimed.
The statement raises more questions than it answers. If indeed there was no network hack, could there have been an inside leak? Or could it have been something as low-tech as dumpster diving, in which records are obtained from trash bins outside a company's offices?
All T-Mobile would say is that it is investigating how the information was obtained.
On Saturday, someone posted to the Full Disclosure e-mail list claiming to have hacked into T-Mobile's computer network.
"We have everything, their databases, confidential documents, scripts and programs from their servers, financial documents up to 2009," the poster wrote, adding that the data was being offered up to the highest bidder. As evidence of the hack the post included a bunch of lines of codes that look like they reference some operating systems and possibly IP addresses.
T-Mobile said the data is not customer data, but declined to say what it is. On Monday, T-Mobile said it was investigating the situation.
Then late on Monday, the company issued a statement that said: "Regarding the recent claim on a Web site, we've identified the document from which information was copied, and believe possession of this alone is not enough to cause harm to our customers."
On Tuesday, T-Mobile issued an updated statement that removed that wording and added: "The company is conducting a thorough investigation and at this time has found no evidence that customer information, or other company information, has been compromised. Reports to the contrary are inaccurate and should be corrected."
T-Mobile says the data isn't customer data. So what is it?
(Credit: T-Mobile)
Elinor Mills covers Internet security and privacy. She joined CNET News in 2005 after working as a foreign correspondent for Reuters in Portugal and writing for The Industry Standard, the IDG News Service, and the Associated Press. E-mail Elinor. 






<strong>Johnny B
Founder, <a rel="" href="http://www.halocigs.com">Halo Electronic Cigarettes</a></strong>
Hostname, Environment (production), ??, Application Name, AppName, IP, LOCATION?, ??, ??, ?
Looks like the results of some kind of vendor audit or some document enumerating nodes and their application function within a data center...
Do you freaking business people really believe that you can outsource your inner operations... and remain safe? LOL what vested interest does an H1B contractor have beyond the term of his VISA... I guess your hoping that your half-implemented processes are going to protect your customer's data.
Do you outsource your finance and executive functions too? Perhaps you should start...
There needs to be stiff penalties for the exposure/compromise of personal information at the hands of a business entity, and criminal penalties for executives that supress the disclosure of it.
Exactly. I mean, you could pull this same data from nmap or spiceworks on any internally connected computer. Hell, you could walk into their lobby, plug into their wall jack, and get this information from a network scan. This doesn't mean you've got access to anything. This data is like claiming you broke into the white house because you were able to zoom in via Google maps or grabbed a new employee's guide.
- by johnfranks1234 June 10, 2009 11:58 AM PDT
- In the realm of risk, unmanaged possibilities become probabilities: These data breaches and thefts are due to a lagging business culture. As CIO, I'm always looking for ways to help my team, business teams, and ad hoc measures of various vendors, contractors and internal team members. A book that is required reading (specific chapters, depending on nature of projects) is "I.T. Wars: Managing the Business-Technology Weave in the New Millennium." It has a great chapter regarding security (among others).
- Like this Reply to this comment
-
(10 Comments)We keep a few copies kicking around - it would be a bit much to expect outside agencies to purchase it on our say-so. But, particularly when entertaining bids for projects, we ask potential solutions partners to review relevant parts of the book, and it ensures that these agencies understand our values and practices.
The author, David Scott, has an interview here that is a great exposure: http://businessforum.com/DScott_02.html
The book came to us as a tip from one of our interns who attended a course at University of Wisconsin, where the book is in use; I like to pass along things that work, in the hope that good ideas continue to make their way to me. I hope you can make use of this info...