Vulnerabilities at AT&T, T-Mobile and Sprint Could Have Exposed Customer Data

Vulnerabilities at AT&T, T-Mobile and Sprint Could Have Exposed Customer Data

Last week was not a good week for telecommunications companies.

Security researchers have uncovered security flaws with systems at AT&T, Sprint and T-Mobile that could have left customer data accessible to bad actors.

The flaws impacting AT&T and T-Mobile were first reported. In T-Mobile's case, an "engineer mistake" between Apple's online storefront and T-Mobile's account validation API allowed for an unlimited number of attempts on an online form, which would allow a hacker to use commonly-available tools to guess an account PIN or the last four digits in a customer's social security numbers, in what's called a brute-force attack. The vulnerability has since been fixed.

A similar problem occurred with phone insurance company Asurion and its AT&T customers. An online form would allow anyone with a customer's phone number to access a form that allowed them unlimited guesses to guess a customer's passcode, leaving it vulnerable to another brute-force attack. The vulnerability has since been fixed.

At Sprint, security researchers were able to access an internal portal because of a "weak, easy-to-use usernames and passwords," compounded with the lack of two-factor authentication. Once in, the researcher was reportedly able to access customer account information for Sprint, Boost Mobile, and Virgin Mobile. The researcher also reported that anyone who gained access could make changes to customer accounts and that customers PINs could be brute-forced.

A Sprint spokesperson confirmed the vulnerability to TechCrunch, and noted that it didn't believe that any customers were affected by the vulnerability. The spokesperson said they were working to fix the issue.

About the Author

Sydny Shepard is the Executive Editor of Campus Security & Life Safety.

Featured

New Products

  • ADI Control4 product image

    ADI Control4® X4 & Control4® Connect

    Drive long-term system value and reduce post-installation friction with a visually redesigned control interface paired with a secure, future-ready smart service framework.

  • Schlage Sense Pro

    Schlage Sense Pro™ Smart Deadbolt

    Deliver true hands-free entry and reliable smart home integration with a premium deadbolt featuring Schlage Converge™ technology and native Matter over Thread support.

  • Theia Technologies building fisheye

    Theia Technologies Linear Optical Technology®

    Learn how ultra-wide, zero-distortion rectilinear lens design improves spatial accuracy and eliminates the need for software de-warping in real-time robotic and automation systems.