T-Mobile logo (image source: T-Mobile, 2020)
One-sentence summary:
T-Mobile suffered a data breach for over a month starting in November 2022, affecting over 37 million customers and potentially implicating Google Fi customers.
Who was involved?
T-Mobile, 37 million T-Mobile customers, potentially Google Fi, and a threat actor.
What was the timeline?
November 25, 2022: Threat actor starts abusing T-Mobile API
January 5, 2023: T-Mobile discovers the breach
January 6, 2023: Breach is stopped by T-Mobile after initiating an incident response
January 19, 2023: T-Mobile reports the breach in its January 2023 Form 8-K filing and makes a public notice on its website
January 30, 2023: Google Fi informs its affected customers of a breach temporally associated with T-Mobile’s breach
What occurred?
In November 2022, a threat actor obtained access to T-Mobile’s API and abused it to potentially breach the following data of over 37 million individuals: “customer account data, including name, billing address, email, phone number, date of birth, T-Mobile account number and information such as the number of lines on the account and plan features” (T-Mobile, 2023, p. 2). Google Fi later confirmed some of its customers were involved in a data breach that is temporally associated with this breach (Page, 2023).
Estimated costs:
Associated incident response costs, breach notification costs, “external cybersecurity experts”
Involved laws:
TBA or N/A (see disclaimer)
Root cause:
TBA or N/A (see disclaimer)
Lessons learned:
T-Mobile suffered a similar data breach in 2018 when it was discovered to have a publicly exposed API allowing any person to retrieve significant account information with just a phone number. Thus, it appears T-Mobile fell victim to a similar attack again where it enabled a publicly exposed API and thus was a misconfiguration. Having multiple people, such as a doer and checker, to evaluate changes in production can prove invaluable in detecting potential misconfigurations, such as a publicly exposed service or portal. Additionally, publicly-facing vulnerability assessments could also potentially discover such vulnerabilities. Finally, internal threat hunting, such as monitoring internal IIS logs to see repeated, EXTERNAL requests for that API query could have led to an earlier discovery. Public and private services should be tagged/labeled within an organization and clearly delimited for easier prevention and detection of data breaches.
Sources:
Page, C. (2023, January 31). TechCrunch is part of the Yahoo family of brands. TechCrunch. Retrieved April 23, 2023, from https://techcrunch.com/2023/01/31/google-fi-customer-data-breach/
T-Mobile. (2020, June). T-Mobile_New_Logo_Primary_RGB_M-on-W.jpg. https://www.t-mobile.com/news/_admin/uploads/2020/06/T-Mobile_New_Logo_Primary_RGB_M-on-W.jpg
T-Mobile. (2023). FORM 8-K. In SEC EDGAR (No. 1–33409). UNITED STATES SECURITIES AND EXCHANGE COMMISSION. Retrieved April 23, 2023, from https://www.sec.gov/Archives/edgar/data/1283699/000119312523010949/d641142d8k.htm
T-Mobile Newsroom. (2023). T-Mobile Informing Impacted Customers about Unauthorized Activity. T-Mobile Newsroom. https://www.t-mobile.com/news/business/customer-information
