T-Mobile US has an unmitigated security mess on its hands, leaving its entire customer base in the lurch. 

The operator suffered a massive data breach over the weekend that threatens to put it in unprecedented territory. Hackers breached T-Mobile US servers over the weekend and reportedly obtained personal information on more than 100 million customers. 

Roughly 32 hours after the data breach was first reported by Vice, T-Mobile confirmed that “unauthorized access to some T-Mobile data occurred,” but it has yet to determine the extent of the damage or if any personal customer information was compromised during the attack.

“I believe this is the largest carrier breach on record,” Zeus Kerravala, principal analyst at ZK Research, wrote in response to questions. 

Stéphane Téral, chief analyst at LightCounting, agreed with that assessment, and both analysts noted that this marks T-Mobile’s sixth-known data breach in four years. 

“T-Mobile has been a favorite target of hackers over the past few years, and they really need a complete rethink of security,” Kerravala said.

‘Shocking’ Lack of Details from T-Mobile

“One of the things I find most concerning is that T-Mobile can’t yet verify what has or has not been stolen. Right now customers are left wondering if this is something they should be concerned about,” he added. “Breaches happen, but the fact that T-Mobile can’t provide any details as to the scope of it is shocking.”

T-Mobile claims “the entry point used to gain access has been closed,” but the damage has been done, according to the hackers, which claim to have downloaded the data locally and backed it up in multiple locations. 

That data includes a wide swatch of personal information, including names, phone numbers, social security numbers, physical addresses, unique device identifier data, security PINs, and drivers license information, according to Vice, which viewed samples of the data and confirmed the information contains accurate information on T-Mobile customers.

“If this is true, according to my understanding of the incident, the most concerning detail about this data breach is access to a database that ties names and phone numbers together, and the ability to identify someone’s carrier and fixed address,” Téral wrote in an email to SDxCentral. “This is, I believe, what makes it unique and damaging.”

Crisis management fundamentals call for T-Mobile to be as transparent as possible and set up a helpline to address the deluge of customers’ concerns, he added. 

Will Townsend, senior analyst at Moor Insights & Strategy, said he’s confident T-Mobile will be transparent as the investigation unfolds and details of the breach become clear. 

Hacker Exploits Misconfigured 3G Mobile Core

It remains unclear, or at least unconfirmed, how the attackers gained access to T-Mobile’s servers containing customer data, and “the problem is: T-Mobile doesn’t know either,” Kerravala said. “Until they can definitely tell us what data was stolen, I think we assume the hackers have the info.”

Overall, the attack “points to the growing issues tied to ransomware and the sophistication of hackers. This wasn’t a traditional ransomware attack given the hacker offered to sell the data versus approaching T-Mobile, but it’s a similar situation,” Townsend explained. 

Brian Krebs, an investigative cybersecurity journalist, reported that the person behind the hack is tied to the Satori IoT botnet. “The intrusion came to light on Twitter when the account @und0xxed started tweeting the details,” he wrote in a blog post.

When reached via direct message by Krebs, the account holder said they weren’t involved in the theft, but rather tasked with finding buyers for the stolen T-Mobile customer data. 

“Und0xxed said the hackers found an opening in T-Mobile’s wireless data network that allowed access to two of T-Mobile’s customer data centers. From there, the intruders were able to dump a number of customer databases totaling more than 100 gigabytes,” Krebs reported. 

Telecom networks are monitored 24 hours a day, 365 days a year, and large networks encounter many attacks each day that are mitigated with specific tools and security gateways, Téral explained. “However, it works as long as each network element is properly configured. If just one network element is not properly configured, it provides an entry point that hackers will eventually find.”

IT security journalist Jeremy Kirk reported that the person responsible for the hack claimed they gained unauthorized access by exploiting a misconfigured GPRS support gateway node that was exposed to the internet. Kirk posted a screenshot on Twitter indicating how the 3G mobile core was compromised.

The Belarus-based hacker also told Kirk they used credential stuffing via secure shell (SSH) on more than 100 servers, including some made by Oracle. 

“Unfortunately, this is the world we live in and no matter the G — 5G is supposed to be more secure because network functions are disaggregated and therefore can be easily isolated when a failure or a breach is automatically detected — human error will never disappear,” Téral explained.

Townsend noted that T-Mobile uses various tools to safeguard subscriber data, prevent malware, and neutralized phishing, including its artificial intelligence (AI)-infused Scam Shield technology that is designed to mitigate the latter. 

Unfortunately, for T-Mobile and its customers, these measures and tools did not prevent the attack.

Where Does the Buck Stop at T-Mobile?

Of the 16 highest-ranking executives at T-Mobile, none appear to be directly responsible for network security. Indeed, the only mention of “security” appears on the bio page for SVP and CIO Brian King, referencing his previous work as chair of the Federal Communications Commission’s Security, Reliability, and Interoperability Council.

T-Mobile SVP and CSO Timothy Youngblood is likely the senior-most executive responsible for the operator’s network security. Bill Boni retired from his position as SVP of digital security at T-Mobile last month. He joined the company as its CISO in late 2009.

“At a very basic level, T-Mobile needs to find a way to segment customer data to minimize the impact of a breach. I also think it needs to change the way users authenticate to prevent the data being used for SMS-swap attacks,” Kerravala said. 

SMS-based authentication remains “a huge problem for the mobile industry and it’s time to change this,” he added. 

“Preventing it is a much bigger problem that requires sophisticated AI tools to find the needle in a stack of needles. I’m sure T-Mobile has state of the art stuff, but it needs to turn identification and response over to AI systems,” Kerravala concluded.