Saturday, January 28, 2023
  • Advertise With Us
  • Write For Us
  • Contact Us
  • About Us
  • Editorial Calendar
Download Free Magazine
The Cyber Express
Ransomware 2023 Report
  • Magazine
  • Firewall Daily
    • All
    • Dark Web News
    • Data Breach News
    • Hacks
    • Ransomware
    • Vulnerabilities
    cybersecurity

    ‘You are Essentially Funding Criminals When You Pay Ransom’

    Dr Pepper Russian Branch

    Data Breach at Dr Pepper Russian Branch, Mystery Hacker Steals Confidential Info

    Amadey Botnet

    Old Bot in New Bottle: Amadey Botnet Back in Action Via Phishing Sites

    Verizon

    Verizon Customer Data for Sale on Dark Web, New Data Breach Suspected

    GoTo Confirms User Data Stolen With Encryption Key

    GoTo Confirms User Data Stolen With Encryption Key

    HIVE Ransomware

    Hive Ransomware Servers Taken Down in FBI-led Global Law Enforcement Action

    porsche nft

    Porsche NFT Hits Pit Stop, Fake NFT Sale On With Malvertising and Fraud Domains

    Hilton Hotels

    Hilton Hotels Loyalty Program Data Breached, Customer Info for Sale

    League of Legends

    League of Legends Source Code Up For Sale a Day After $10m Ransom Demand, Riot Games Confirm Leak

  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    TRAI

    TRAI Asked to Involve MoD in Drafting Big Data Regulations & Policies

    cybersecurity

    Cybersecurity incidents may soon be ‘uninsurable’

    Australia

    Australia Ropes in Tech Veterans to Set Up Cyber Action Plan

    Active Directory

    Prevent Ransomware: Save the Active Directory

    Privacy Penalty Bill

    Privacy Penalty Bill: Australian Parliament Approves Heavy Fines

    Zero Trust Strategy

    US Department of Defense to Embrace Zero Trust Strategy

    browser hijackers

    Researchers Find Browser Hijackers on Google Chrome Web Store

    DORA proposal

    DORA Proposal for Cybersecurity Awaits Full Approval by Council and ESAs

    Privacy penalty bill

    Australia Privacy Penalty Bill 2022: Pay a $50 Million Fine for Data Breaches

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business News
    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Webinars
    • World CyberCon Middle East 2023
    • Endorsed Events
  • Advertise
No Result
View All Result
The Cyber Express
  • Magazine
  • Firewall Daily
    • All
    • Dark Web News
    • Data Breach News
    • Hacks
    • Ransomware
    • Vulnerabilities
    cybersecurity

    ‘You are Essentially Funding Criminals When You Pay Ransom’

    Dr Pepper Russian Branch

    Data Breach at Dr Pepper Russian Branch, Mystery Hacker Steals Confidential Info

    Amadey Botnet

    Old Bot in New Bottle: Amadey Botnet Back in Action Via Phishing Sites

    Verizon

    Verizon Customer Data for Sale on Dark Web, New Data Breach Suspected

    GoTo Confirms User Data Stolen With Encryption Key

    GoTo Confirms User Data Stolen With Encryption Key

    HIVE Ransomware

    Hive Ransomware Servers Taken Down in FBI-led Global Law Enforcement Action

    porsche nft

    Porsche NFT Hits Pit Stop, Fake NFT Sale On With Malvertising and Fraud Domains

    Hilton Hotels

    Hilton Hotels Loyalty Program Data Breached, Customer Info for Sale

    League of Legends

    League of Legends Source Code Up For Sale a Day After $10m Ransom Demand, Riot Games Confirm Leak

  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    TRAI

    TRAI Asked to Involve MoD in Drafting Big Data Regulations & Policies

    cybersecurity

    Cybersecurity incidents may soon be ‘uninsurable’

    Australia

    Australia Ropes in Tech Veterans to Set Up Cyber Action Plan

    Active Directory

    Prevent Ransomware: Save the Active Directory

    Privacy Penalty Bill

    Privacy Penalty Bill: Australian Parliament Approves Heavy Fines

    Zero Trust Strategy

    US Department of Defense to Embrace Zero Trust Strategy

    browser hijackers

    Researchers Find Browser Hijackers on Google Chrome Web Store

    DORA proposal

    DORA Proposal for Cybersecurity Awaits Full Approval by Council and ESAs

    Privacy penalty bill

    Australia Privacy Penalty Bill 2022: Pay a $50 Million Fine for Data Breaches

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business News
    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Webinars
    • World CyberCon Middle East 2023
    • Endorsed Events
  • Advertise
No Result
View All Result
The Cyber Express
No Result
View All Result
Home Firewall Daily Data Breach News

Data Breach at T-Mobile, Again!

T-Mobile is the third-largest wireless carrier in the United States, with over 110 million subscribers

Editorial by Editorial
January 20, 2023
in Data Breach News, Firewall Daily
0
Data Breach T-Mobile
604
SHARES
3.4k
VIEWS
Share on LinkedInShare on Twitter

US-based telecommunication service T-Mobile has disclosed a data breach that affected 37 million postpaid and prepaid accounts.  

In a regulatory filing on 19 January, the company said that it is investigating the matter and that it expects to incur significant costs related to the incident.  

You might also like

‘You are Essentially Funding Cybercriminals When You Pay Ransom’

Data Breach at Dr Pepper Russian Branch, Mystery Hacker Steals Confidential Info

Old Bot in New Bottle: Amadey Botnet Back in Action Via Phishing Sites

T-Mobile claims to have identified the malicious activity on January 5 and contained it within 24 hours. According to the company, no sensitive information such as financial data was compromised.  

Breaking News

Verizon Customer Data for Sale on Dark Web, New Data Breach Suspected

Threat actor claims to have access to a database of 7.5 million customers belonging to Verizon, stolen by hackers in January 2023. Read More...

“We promptly commenced an investigation with external cybersecurity experts and within a day of learning of the malicious activity, we were able to trace the source of the malicious activity and stop it,” the company disclosure said. 

“Our investigation is still ongoing, but the malicious activity appears to be fully contained at this time, and there is currently no evidence that the bad actor was able to breach or compromise our systems or our network.” 

However, basic customer information, such as names, billing addresses, email addresses, and phone numbers, were obtained.

The company stated that the investigation is ongoing and that the malicious activity appears to be fully contained at this time.  

T-Mobile data breach and attack vector 

T-Mobile is the third-largest wireless carrier in the United States, with over 110 million subscribers. According to the company disclosure, a bad actor was obtaining data through a single Application Programming Interface (“API”) without authorization. 

The data breached included customers’ names, billing addresses, email addresses, phone numbers, dates of birth, T-Mobile account numbers, and details about the number of lines and plan features for each account. 

APIs are sets of instructions that enable applications to access data and interact with web databases. However, if not properly secured, these APIs can be exploited by malicious actors to collect large amounts of information stored in those databases.  

In October, mobile provider Optus reported that hackers took advantage of a weakly secured API to steal data on 10 million customers in Australia. 

The disclosure stressed that the leak was blocked on time and currently there is no evidence that the bad actor was able to breach or compromise their systems or network.  

However, the markets did not take these assurances kindly. In after-hours trade, the company’s shares fell 2%.  

T-Mobile and earlier data breaches 

It’s been hardly a year since T-Mobile was in the cybersecurity news for a major cyber incident.  

In April 2022, Krebsonsecurity reported that the Lapsus$ hacking group successfully breached T-Mobile’s systems and stole the company’s source code. Lapsus’s recent targets include Samsung, Uber, and Cisco. 

T-Mobile confirmed the attack in a statement to The Verge and stated that the systems accessed did not contain any customer or government information or other sensitive information. 

According to private messages obtained by Krebs, the Lapsus$ group had planned to target T-Mobile in the week prior to the arrest of seven of its teenage members.  

The group purchased employees’ credentials online and used T-Mobile’s internal tools, such as the Atlas customer management system, to perform SIM swaps.  

A SIM swap is a type of attack in which the attacker hijacks a target’s mobile phone number by transferring it to a device owned by the attacker.  

This allows the attacker to intercept texts or calls received by that phone number, including any messages sent for multi-factor authentication. 

In 2021, T-Mobile agreed to pay $350 million and spend an additional $150 million to upgrade data security to settle litigation over a cyberattack that compromised information belonging to an estimated 76.6 million people.  

Share this:

  • Click to share on LinkedIn (Opens in new window)
  • Click to share on Reddit (Opens in new window)
  • Click to share on Twitter (Opens in new window)
  • Click to share on Facebook (Opens in new window)
  • More
  • Click to email a link to a friend (Opens in new window)
  • Click to share on WhatsApp (Opens in new window)

Related

Tags: Data Breach T-Mobile
Previous Post

German Institute GIGA Allegedly Attacked by KelvinSecurity

Next Post

PayPal Cyberattack: Firm Alerts 35,000 Users, Researcher Says More Than a Million at Risk

Editorial

Editorial

The Cyber Express is a publication that aims to provide the latest news and analysis about the information security industry. The news comes from a variety of sources and is updated regularly so that readers can stay up to date with the latest happenings in this rapidly growing field.

Related Posts

cybersecurity
Firewall Daily

‘You are Essentially Funding Cybercriminals When You Pay Ransom’

by Chandu Gopalakrishnan
January 28, 2023
Dr Pepper Russian Branch
Data Breach News

Data Breach at Dr Pepper Russian Branch, Mystery Hacker Steals Confidential Info

by Ashish Khaitan
January 27, 2023
Amadey Botnet
Firewall Daily

Old Bot in New Bottle: Amadey Botnet Back in Action Via Phishing Sites

by Editorial
January 27, 2023
Verizon
Dark Web News

Verizon Customer Data for Sale on Dark Web, New Data Breach Suspected

by Editorial
January 27, 2023
GoTo Confirms User Data Stolen With Encryption Key
Data Breach News

GoTo Confirms User Data Stolen With Encryption Key

by Vishwa Pandagle
January 27, 2023
Next Post
PayPal Cyberattack

PayPal Cyberattack: Firm Alerts 35,000 Users, Researcher Says More Than a Million at Risk

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Latest Issue is Out. Subscribe Now

Cybersecurity Person of The Year 2023
Download Now

Sign Up For Newsletter

Name*

Recommended

Scammers Infect Keygen Offering Websites with NullMixer Dropper to Hack Devices

Scammers Infect Keygen Offering Websites with NullMixer Dropper to Hack Devices

September 28, 2022
Apple security flaw

New Security Flaw in Apple Enables Full Access to Hackers

August 22, 2022

Categories

  • Appointments
  • Budgets
  • Business News
  • Compliance
  • Cyber Essentials
  • Cyber Warfare
  • Cybersecurity News
  • Dark Web News
  • Data Breach News
  • DDoS Attacks
  • Espionage
  • Features
  • Firewall Daily
  • Gitex2022
  • Governance
  • Hacks
  • How to
  • Interviews
  • Learning & Development
  • Main Story
  • Malware News
  • Mergers & Aquisitions
  • Partnerships
  • Podcast
  • Policy Updates
  • Press Release
  • Ransomware
  • Regulations
  • Research
  • Resources
  • Startups
  • Vulnerabilities
  • Workforce

Don't miss it

SOCs
Features

SOCs to Face Greater Challenges from Cybercriminals Targeting Govt. and Media in 2023

January 28, 2023
cybersecurity
Firewall Daily

‘You are Essentially Funding Criminals When You Pay Ransom’

January 28, 2023
Dr Pepper Russian Branch
Data Breach News

Data Breach at Dr Pepper Russian Branch, Mystery Hacker Steals Confidential Info

January 27, 2023
How to protect and recover your Facebook and Instagram accounts – a complete guide
Resources

How to protect and recover your Facebook and Instagram accounts – a complete guide

January 27, 2023
Amadey Botnet
Firewall Daily

Old Bot in New Bottle: Amadey Botnet Back in Action Via Phishing Sites

January 27, 2023
Verizon
Dark Web News

Verizon Customer Data for Sale on Dark Web, New Data Breach Suspected

January 27, 2023

About

The Cyber Express

Cybersecurity News and Magazine

The Cyber Express is a handbook for all stakeholders of the internet that provides information security professionals with the latest news, updates and knowledge they need to combat cyber threats.

Follow The Cyber Express

Contact

For editorial queries: [email protected]

For marketing, PR & media partnerships: [email protected]

For media kit and digitals sales: [email protected]

For Sponsorship/Event Partnership: [email protected]

For Conferences related information: [email protected]

Our Address

We’re remote friendly, with office locations around the world:

San Francisco, Atlanta, Rome,
Dubai, Mumbai, Bangalore, Hyderabad,  Singapore, Jakarta, Sydney, and Melbourne

 

Headquarters:

The Cyber Express LLC
555 North Point Center E
Alpharetta, GA 30022, USA.

Tel: (678) 578-8838

Subscribe to Our Feed

RSS Feeds

© 2022 The Cyber Express | By Cyble Inc.

No Result
View All Result
  • Firewall Daily
  • Business News
  • Cyber Essentials
  • Features
  • Cybersecurity Magazine
  • Events
    • World CyberCon Middle East 2023
    • Webinars

© 2022 The Cyber Express | By Cyble Inc.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.