The scope of a cyberattack at T-Mobile US keeps growing, as the operator today confirmed personal data on at least 54 million people was exposed and stolen. It pegged the number of people affected at nearly 49 million people earlier this week.
This marks the fifth publicly acknowledged data breach for the operator in three years, and the Federal Communications Commission earlier this week opened an investigation into the latest incident.
Hackers claimed personal data on more than 100 million customers was stolen during the attack. T-Mobile had 104.8 million customers at the end of June.
T-Mobile’s continued failure to protect the data of its customers yields some lessons for other operators, but the broader takeaway is that carriers hold some of the largest and most personal data on individuals on the planet.
“Mobile network operators and telecommunications providers are prime targets for cyberattacks because they serve large swaths of the population and have access to a significant amount of information about individuals, like social security numbers,” Forrester Research analyst Allie Mellen wrote in response to questions.
The lesson for T-Mobile customers, according to Mellen: “T-Mobile is not taking appropriate measures to secure their data, despite numerous breaches of increasing magnitude. While every business can and may be affected by a cyberattack, there is a continuous pattern here that indicates that T-Mobile does not seem to find it important to prioritize securing customer data.”
Personal Data Collection Practices QuestionedNotwithstanding operators’ inherent responsibility to secure customer data, this latest breach also calls into question many data collection practices, including long-term storage of such personal information.
“It boggles the mind that T-Mobile is keeping customers’ social security and driver’s license numbers,” wrote Oliver Tavakoli, CTO at Vectra, a threat detection and response vendor.
While those details might be required to run credit checks, “there is little reason to hold on to them after running the credit check. The best way to ensure you don’t leak data is to not collect it in the first place, or to destroy it after it has been used for its intended purpose.”
JupiterOne founder and CEO Erkang Zheng also called for an end to the use of social security numbers and driver’s license information for identity verification. “There would be no point for attackers to steal something of no meaningful value to them,” he wrote.
‘T-Mobile Left a Gate Wide Open’The relative ease with which the attack occurred might be the most damning detail about this latest data breach at T-Mobile. “According to the attackers, this was a configuration issue on an access point T-Mobile used for testing. The configuration issue made this access point publicly available on the internet,” Mellen noted.
“This was not a sophisticated attack; this was not a zero day. T-Mobile left a gate wide open for attackers, and attackers just had to find the gate,” she explained.
T-Mobile’s Response Fall ShortCybersecurity specialists also criticize T-Mobile for its apparent lack of understanding the severity of its responsibilities and a general apathy toward assumed risk it holds on behalf of its customers.
This is further exemplified by T-Mobile’s reaction to the incident thus far. The operator’s latest offer to provide two years of free identity protection to any person who believes they may be impacted falls well short of its obligations.
“Instead of addressing the security gaps that have plagued T-Mobile for years,” this gesture just ultimately pushes the responsibility for the safety of the data on to the user, Mellen said.
“It seems T-Mobile has not learned from these previous breaches, especially considering they didn’t know about the attack until the attackers posted about it in an online forum,” she added. “This signals a lack of security policies and monitoring to prevent or at least detect this attack, which is a huge misstep for T-Mobile given their history of repeated breaches.”
Moreover, many organizations haven’t yet recognized, or at least fail to communicate, that they are reacting to these massive data breaches as one should for critical infrastructure, according to Setu Kulkarni, VP of strategy at NTT Application Security. “It is one thing to be deemed critical infrastructure, it is another thing to act as one,” he wrote in response to questions.
T-Mobile and other businesses that sell access to critical infrastructure need to proactively reach out to affected individuals and enterprises quickly and consistently as more details are uncovered.
“Telecom companies provide infrastructure for every conceivable utility that we need as a society,” Kulkarni explained. “These kinds of data breaches erode trust among the general public and, as a result, the reliability and effectiveness of the communications provided through telecommunications networks dwindles.”
Recurring Reminder of Weak Security PostureThis latest cyberattack also reinforces the need for every organization to maintain visibility into the security posture of its entire infrastructure footprint to understand where vulnerabilities exist and prevent attacks, explained Hank Schless, senior manager of security solutions at Lookout.
“This incident highlights how important visibility and anomalous behavior detection are if an organization wants to implement a security strategy built for today’s threat landscape,” Schless said. The number of telecommunications employees targeted with a mobile phishing link jumped from one in five in fourth-quarter 2020 to one in three in second-quarter 2021, he added, referencing Lookout data.
Reflecting on what’s known about T-Mobile’s data breach thus far, Mellen offered a few tips for operators to follow: properly configure internal-only access points, put appropriate security monitoring in place to detect attacks, use asset management tools to identify risks and misconfigurations, and implement a zero-trust strategy.
“Carriers that build out a strong security program that includes security monitoring and a zero-trust strategy will be able to reduce the risks associated with being hit by a cybercriminal,” Mellen concluded. “This is critical to protecting customer data and maintaining trust with your customers.”
Comments