T-Mobile US CEO Mike Sievert today apologized for the operator’s inability to stop a cyberattack that exposed personal data on at least 54 million people.
“To say we are disappointed and frustrated that this happened is an understatement,” he wrote in a blog post. “Keeping our customers’ data safe is a responsibility we take incredibly seriously and preventing this type of event from happening has always been a top priority of ours. Unfortunately, this time we were not successful.”
Now that the breach is contained and T-Mobile’s investigation is “substantially complete,” Sievert committed to improve T-Mobile’s security efforts in a bid to rebuild trust.
“We know we need additional expertise to take our cybersecurity efforts to the next level — and we’ve brought in the help,” he wrote, adding that the operator signed long-term contracts with Mandiant and KPMG. “These arrangements are part of a substantial multi-year investment to adopt best-in-class practices and transform our approach.”
T-Mobile Adds Cybersecurity MuscleT-Mobile will lean on Mandiant to “develop an immediate and longer-term strategic plan to mitigate and stabilize cybersecurity risks across our enterprise,” Sievert wrote. Moreover, he added KPMG’s cybersecurity team will “perform a thorough review of all T-Mobile security policies and performance measurement.”
The cybersecurity and consulting firms will work together and with T-Mobile’s security team to identify gaps and actions designed to improve the operator’s security posture, according to Sievert.
Meanwhile, T-Mobile’s more immediate response and communication with customers remains limited. The operator reiterated its offer to provide two years of identity protection, and encouraged customers to sign up for its scam-blocking tool, and reset PINs and passwords.
Sievert noted that ongoing coordination with law enforcement on a criminal investigation prevents the operator from disclosing many details, but he did admit a “bad actor illegally gained entry to our servers.” Those access points are now closed, and “we are confident that there is no ongoing risk to customer data from this breach,” he wrote.
“In simplest terms, the bad actor leveraged their knowledge of technical systems, along with specialized tools and capabilities, to gain access to our testing environments and then used brute force attacks and other methods to make their way into other IT servers that included customer data,” Sievert explained.
“In short, this individual’s intent was to break in and steal data, and they succeeded,” he wrote.
T-Mobile claims it was victim of a “highly sophisticated attack,” but the hacker John Binns, after claiming responsibility for the breach, told The Wall Street Journal he gained access with ease after discovering an unprotected router with a simple, publicly available tool.
Forrester Research analyst Allie Mellen concurred with that assessment. “This was not a sophisticated attack; this was not a zero day. T-Mobile left a gate wide open for attackers, and attackers just had to find the gate,” she explained in an interview with SDxCentral.
Sievert concluded his mea culpa by noting “we’re starting on this path with humility,” and warned that T-Mobile’s security improvements will take time.
Comments