0% found this document useful (0 votes)
43 views6 pages

Case Study Data Breach T-Mobile

A cyberattack on T-Mobile exposed the personal information of over 40 million people. The stolen data included names, dates of birth, social security numbers, driver's licenses and other information for 7.8 million current and former customers. Additionally, names, phone numbers and account PINs were exposed for 850,000 active prepaid customers. T-Mobile is offering identity protection services and additional security measures to help protect impacted customers.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
43 views6 pages

Case Study Data Breach T-Mobile

A cyberattack on T-Mobile exposed the personal information of over 40 million people. The stolen data included names, dates of birth, social security numbers, driver's licenses and other information for 7.8 million current and former customers. Additionally, names, phone numbers and account PINs were exposed for 850,000 active prepaid customers. T-Mobile is offering identity protection services and additional security measures to help protect impacted customers.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Case Study

Data Breach

T-Mobile

© Copyright IBM Corp. 2023


On August 17, 2023, T-Mobile learned that a bad actor
personal data accessed and/or acquired illegally. He The
villainous actor first gained access to T-Mobile's systems in
or before July 19, 2023.

Our investigation is ongoing, but we verified that a subset of


Attack Category: T-Mobile data have been accessed and/or acquired by
Security Data unauthorized persons individuals and data stolen from our
systems are not include certain personal information.
Breach
Sources:
[Link]
against-tmobile-and-our-customers
The mobile service provider said in a statement that it had
been investigating the data breach since last week, when it
was “informed of claims made in an online forum that a bad
actor had compromised T-Mobile systems.” The company
said the stolen files included information from
approximately 7.8 million current T-Mobile accounts, as
Company well as records of more than 40 million former or
Description and prospective customers who had applied for credit with the
company. Some of the exposed data included customers’
Breach Summary first and last names, social security numbers, driver’s
license and other information, T-Mobile said. It also
included the PINs of about 850,000 active prepaid
customers.
A cyberattack on T-Mobile exposed the information of more than 40
1 million people.

Then located and immediately closed the access point that we


2 believe was used to illegally gain entry to our servers

Offering two years of free identity protection services with McAfee’s


3 ID. Theft Protection Service to any person who believes they may
be affected
Timeline
Recommending that all eligible T-Mobile customers sign up for free
4 scam blocking protection through Scam Shield

Offering an extra step to protect your mobile account with our


5 Account Takeover Protection capabilities for postpaid customers,
which makes it harder for customer to be stolen.

Approximately 850,000 active T-Mobile prepaid customer names,


6 phone numbers and account PINs were exposed
Vulnerabilities
The mobile operator revealed that the compromised data included full names, dates of birth, SSNs and driver’s license/ID information for 7.8 million
current T-Mobile postpaid customers as well as over 40 million former or prospective customers who had applied for credit with T-Mobile. No phone
numbers, account numbers, PINs, passwords, or financial information were exposed for these users. However, names, phone numbers, and account PINs
were exposed for 850,000 active T-Mobile prepaid customers.

Vulnerability 1 Vulnerability 2 Vulnerability 3 Vulnerability 4


SMS phishing SIM swapping Victim profiles Social Engineering
Phishing attacks could be Another type of attack The more breaches In this type of attack, the
launched over SMS that is specific to phone occur, the easier it is for attacker manipulates the
messages, impersonating users is SIM swapping. attackers to build victim into giving up
the mobile operator. At This is when an attacker complete victim profiles personal information,
first glance, in the case of manages to convince a and launch attacks that clicking malicious links,
the 48 million current, mobile operator to are increasingly hard to or downloading malware.
former, and prospective associate a victim's detect by both This can be done through
T-Mobile customers phone number with a SIM companies and users. SMS phishing, phone
whose personal details card under their control calls, emails, or even in
were exposed to receive all their phone person.
calls and text messages
Costs Prevention

The data breach could turn out to T-Mobile is offering all impacted
be a costly one for the mobile customers a free two-year
operator, as new research shows subscription for McAfee's ID Theft
the average cost of a data breach Protection Service, which includes
has risen to more than $4.7m. credit monitoring, full-service
Costs and T-Mobile US said 7.8 million
identity restoration, identity
insurance, dark web monitoring,
Prevention postpaid service customer records
and more
were lifted by hackers. The data of
about 850,000 prepaid customers Business and postpaid customers
was also hacked, as well as more can also enable T Mobile's Account
than 40 million records of former Takeover Protection service for
or prospective customers. free and all T-Mobile users can use
the company's Scam Shield app
that enables caller ID and
automatically blocks calls flagged
as scams

You might also like