Archive for T-Mobile

T-Mobile physically cuts network connection to eject Salt Typhoon hackers

Posted in Commentary with tags on August 21, 2026 by itnerd

New reporting by Bloomberg details how T-Mobile detected and removed China-backed Salt Typhoon hackers from its network during the group’s widespread 2024 campaign against telecommunications companies. T-Mobile security teams spent months searching for the attackers before identifying unusual activity reaching one of its systems through a router that was powered off but communicating with another T-Mobile machine. After locating the compromised equipment, T-Mobile cybersecurity chief Jeff Simon and three colleagues went to a data center near the company’s Bellevue, Washington headquarters and physically cut the cable connecting the system to the outside world. T-Mobile largely avoided the broader compromise experienced by other organizations targeted in the campaign, which affected hundreds of telecommunications companies, internet providers and data center operators and sought phone records and information on senior U.S. officials.
 

Larry Pesce, VP of Services, Finite State:

   “Credit first: T-Mobile’s team hunted down Salt Typhoon in days when peer carriers had them resident for months, and that’s genuinely impressive work. But this article is written for a general audience, and it shows. It reads like a movie script, complete with the team piling into the CSO’s Tesla, and for anyone who has actually run an incident it leaves a lot of important questions on the cutting room floor.

   “Start with the powered-off router in California. The likely explanation for the spoofing is mundane: the attackers were working from stale topology data and impersonated a device they didn’t know was dark. That mistake is probably what burned them. But flip it around and it’s less flattering: T-Mobile’s own telemetry was attributing live traffic to a device that its own asset inventory should have shown as powered off. The gap between what the network claimed and what the hardware was actually doing is the real story here. Accurate hardware inventory and device status is unglamorous work, and it’s exactly the kind of thing that determines how long an adversary gets to live in your network.

   “Then there’s the handling of that router. Per the article, the CSO told a staffer to “rip” a device suspected of nation-state compromise out of the rack, put it in his car, and drive it hundreds of miles to headquarters. Set aside the scissors for a moment. Where’s the chain of custody? Where’s the forensic imaging before the device gets bounced down I-5 in a trunk? For an artifact that might end up mattering to a federal investigation into Salt Typhoon, that’s a detail that made me wince.

   “As for the scissors: I’ve spent time in data centers of this caliber, and scissors are not part of the standard tech loadout. Every one of those links terminates somewhere you can unplug it, shut down at a patch panel, or kill via CLI. Simon concedes as much in the article, admitting they could have turned the device off virtually. Cutting the cable accomplished nothing that unseating a connector wouldn’t, except producing a frayed trophy now framed in the lobby. I don’t doubt the cable got cut. I just notice that the version that made a better artifact is the version that happened.

   “The substantive issue is what the fast, loud response cost them. Walk the IR lifecycle: containment, absolutely, they nailed it. But by their own account, powering the device back up in an isolated environment later yielded little. The attackers were long gone, and so was the volatile evidence. Abruptly severing the link also told the adversary, unambiguously, that they’d been made. A more patient play, instrumenting the device and the interconnect while quietly constraining what the attackers could reach, likely would have produced far more intelligence about tooling, tradecraft, and other footholds. That matters a great deal when the adversary is a state actor with confirmed presence across nine other carriers. Containment without eradication just means round two happens somewhere you aren’t watching.

   “To be clear, I’m confident T-Mobile’s IR capability is far more sophisticated than this telling suggests, and some of what looks like theater may just be what survives the corporate comms filter. But that’s exactly the problem. The sanitized, cinematic version is the one the industry got, and the useful version, the one about inventory hygiene, trusted carrier interconnects as an attack surface, evidence handling under pressure, and the real tradeoff between fast containment and thorough eradication, is the one we actually needed.”

Seemant Sehgal, Founder and CEO, BreachLock:

   “Cutting a cable makes for good storytelling, but the real headline is that a disciplined security team found an adversary that had worked hard to stay hidden. The significance of the Salt Typhoon campaign is the scale and persistence of the operation, targeting telecommunications infrastructure to gain access to highly valuable data. Based on public reporting, the attackers appear to have leveraged network infrastructure and maintained covert access paths, which highlights how difficult these intrusions can be to detect once established. Many organizations in that situation would still be writing incident reports while the attacker moved laterally. T-Mobile’s team located the threat, made a call, and physically removed it from the equation. That takes clarity of judgment under pressure, and that is genuinely rare.” 

Phil Wylie, Senior Consultant & Evangelist, Suzu Labs:

   “The dramatic part of this story is that T-Mobile physically cut a cable, but the bigger lesson is how difficult sophisticated nation-state actors can be to find and remove. Salt Typhoon demonstrates why organizations need visibility into what is actually communicating across their networks, not simply what their asset management tools say should be there. When you identify a compromised system, decisive containment matters more than elegant containment. Sometimes the right incident-response decision really is to pull the plug.”

John Strand, Owner, Black Hills Information Security:

   “There’s only one firewall in existence that is 100% effective, and this is it. Physically cutting the line.

   “I look at stories like this and think security teams need to be empowered to make that decision. For years, the idea of actually cutting network connections during an incident, potentially impacting operations, has been fraught with second-guessing. Hindsight is always 20/20, and security teams are often criticized afterward regardless of the decision they made.

   “But this needs to be normalized. With the rate of attacks we’re seeing, especially with AI dramatically increasing the speed at which attacks can unfold, security teams need to have disconnecting network connections on the table as a legitimate course of action. Organizations should establish that authority before an incident happens, and security teams shouldn’t be punished for using it when the situation calls for it.”

Hayden Covington, Associate Director of Security Operations, Black Hills Information Security:

   “What makes groups like Salt Typhoon dangerous is that they are difficult to detect; not just because they use living-off-the-land techniques, but also because they aren’t a smash and grab operation where eventually the threat actor runs ransomware and you know they’re there. Groups like this are focused on espionage, aiming for long dwell times while they quietly collect sensitive information. Catching an attacker like that often comes down to knowledge of your environment and the ability to dig into anomalies deep enough to know that something malicious is actually happening.”

I have to admit that this is crafty and full of old school thinking. But this needs to be normalized and not the exceptional because everyone everywhere needs to hunt down threat actors and kick them off of any network ASAP.

T-Mobile Pays The Price For Their Numerous Data Breaches…. Again

Posted in Commentary with tags on October 1, 2024 by itnerd

T-Mobile has had numerous data breaches over the last few years. There’s been example, after example, after example, after example, after example, after example of T-Mobile being pwned by hackers and customer data being exposed. The FCC has stepped in and slapped T-Mobile with a file for their inability to keep customer data safe:

The Federal Communications Commission today announced a groundbreaking data protection and cybersecurity settlement with T-Mobile to resolve the Enforcement Bureau’s investigations into significant data breaches that impacted millions of U.S. consumers. To settle the investigations, T-Mobile has agreed to important forward-looking commitments to address foundational security flaws, work to improve cyber hygiene, and adopt robust modern architectures, like zero trust and phishing-resistant multi- factor authentication. The Commission believes that implementation of these commitments, backed by a $15.75 million cybersecurity investment by the company as required by the settlement, will serve as a model for the mobile telecommunications industry. As part of the settlement, the company will also pay a $15.75 million civil penalty to the U.S. Treasury.

This is on top of this fine that T-Mobile got slapped with earlier this year. At this point it’s pretty clear that T-Mobile needs to get their act together. The question is will they? Given their previous track record, that’s an open question. And one that a lot of people will be watching to see how T-Mobile answers that question.

T-Mobile Slapped With A Big Fine For Big Data Leaks

Posted in Commentary with tags on August 16, 2024 by itnerd

If you go through my blog, you’ll find example, after example, after example, after example, after example, after example of T-Mobile being pwned by hackers and customer data being exposed. And according to this Reuters story, The Committee on Foreign Investment in the United States has had enough of the pwnage and has decided to teach T-Mobile a lesson:

The Committee on Foreign Investment in the United States, or Cfius, fined T-Mobile $60 million earlier this year for failing to prevent or disclose unauthorized access to “certain sensitive data,” the panel said on its website. T-Mobile had signed a national security agreement with Cfius in 2018 as part of its merger with Sprint. 

This is the first time that the panel has disclosed the fine, and the decision to mention T-Mobile by name broke with past practice for a government body that’s known for secrecy and whose deliberations are often classified. The panel also published a list of all its penalties since 2018, though without naming the companies involved.

Cfius said the $60 million fine imposed on T-Mobile was the largest in its history. 

Now T-Mobile is a company that according to Wikipedia made about $14 billion in 2023. So a $60 million fine is likely going to be a rounding error to them. Because given how often they’ve been pwned by hackers, it’s pretty clear that they don’t take the security of their customer’s data seriously. Perhaps this fine will send a message that those in charge in the US are finally getting serious about punishing companies that screw up in this manner. Their next task in my opinion is to make the punishments hurt, and hurt so severely so it provides the proper incentive not to be T-Mobile. If I were them, I’d start with copying the EU who got this part right years ago.

T-Mobile Has Been Pwned YET AGAIN

Posted in Commentary with tags on September 22, 2023 by itnerd

Yet again, I’m writing about T-Mobile getting pwned and leaking data. Here’s the latest pwnage via vx-underground:

This is the third time this year that T-Mobile has been pwned as there was an incident in January and May of this year. This is on top of multiple incidents over the years. At this point, you have to wonder why you should do business with T-Mobile. On top of that, I have to ask when the US government will step in and punish them for clearly not having the best security to say the least. Because when you get pwned this often, there’s clearly something wrong that needs to addressed by the relevant authorities.

T-Mobile Has Been Pwned Again

Posted in Commentary with tags , on December 28, 2021 by itnerd

If you’re a T-Mobile customer you have to be wondering if the company can keep customer data safe. I say that because the news is out that they’ve been pwned. Again:

Affected customers fall into one of three categories. First, a customer may have only been affected by a leak of their CPNI. This information may include the billing account name, phone numbers, number of lines on the account, account numbers, and rate plan info. That’s not great, but it’s much less of an impact than the breach back in August had, which leaked customer social security numbers.

The second category an affected customer might fall into is having their SIM swapped. This is where a malicious actor will change the physical SIM card associated with a phone number in order to obtain control of said number. This can, and often does, lead to the victim’s other online accounts being accessed via two-factor authentication codes sent to their phone number. The document says that customers affected by a SIM swap have now had that action reversed.

The final category is simply both of the other two. Affected customers could have had both their private CPNI viewed as well as their SIM card swapped.

This comes after T-Mobile had a massive data breach in the summer. And keep in mind that this company has been pwned in the past too. Clearly this company does not have the best track record of protecting data. Which if you’re a T-Mobile customer, should make you reconsider if you should be dealing with them.

T-Mobile CEO “Sorry” For Massive Data Breach….. Sure….

Posted in Commentary with tags , on August 27, 2021 by itnerd

I guess the heat is getting to T-Mobile when it comes to the fact that they were either victims of massive pwnage, or just badly pwned, and it may still get worse for them. Especially since the hacker that pwned them says that their security was “awful.” I say that because the CEO of T-Mobile Mike Sievert has issued a public apology for T-Mobile’s failure to prevent the pwnage via an open letter posted to the T-Mobile website.

To say we are disappointed and frustrated that this happened is an understatement. Keeping our customers’ data safe is a responsibility we take incredibly seriously and preventing this type of event from happening has always been a top priority of ours. Unfortunately, this time we were not successful.

Attacks like this are on the rise and bad actors work day-in and day-out to find new avenues to attack our systems and exploit them. We spend lots of time and effort to try to stay a step ahead of them, but we didn’t live up to the expectations we have for ourselves to protect our customers. Knowing that we failed to prevent this exposure is one of the hardest parts of this event. On behalf of everyone at Team Magenta, I want to say we are truly sorry.

I’m sorry, but this doesn’t cut it.

If you’re the CEO of a major company with tons of customer information, and you’ve been pwned on this scale, you should be drafting a letter of resignation immediately. Doubly so given that T-Mobile has been pwned so often. Let me give you a list:

  • The theft of the details of 2 million customers in August 2018
  • A hack involving the theft of prepaid customer data in November 2019
  • The theft of employee and customer data in March 2020 
  • A “security incident” involving “malicious, unauthorized access” to some information related to T-Mobile accounts in January

There’s no excuse for any of this and he needs to walk the plank.

T-Mobile Hacker Says T-Mobile’s Security Is “Awful”

Posted in Commentary with tags , on August 27, 2021 by itnerd

It’s bad enough that T-Mobile got either massively pwned by a hacker, or just badly pwned by a hacker. Though it may still get worse. But it just got worse from the American telco. The hacker who pwned them is speaking out. His name is John Binns, a 21-year-old American who lives in Turkey, and he doesn’t have flattering things to say about the telco and their security:

In messages with the Journal, Mr. Binns said he managed to pierce T-Mobile’s defenses after discovering in July an unprotected router exposed on the internet. He said he had been scanning T-Mobile’s known internet addresses for weak spots using a simple tool available to the public.

The young hacker said he did it to gain attention. “Generating noise was one goal,” he wrote. He declined to say whether he had sold any of the stolen data or whether he was paid to breach T-Mobile.

And:

Mr. Binns said he used that entry point to hack into the cellphone carrier’s data center outside East Wenatchee, Wash., where stored credentials allowed him to access more than 100 servers.

“I was panicking because I had access to something big,” he wrote. “Their security is awful.”

He said it took about a week to burrow into the servers that contained personal data about the carrier’s tens of millions of former and current customers, adding that the hack lifted troves of data around Aug. 4.

You have to wonder how this is going over inside T-Mobile, especially since they’ve been pwned on numerous occasions. But more importantly, this is going to spark a lot of questions and inquiries from people outside T-Mobile. And I’m going to bet that T-Mobile really doesn’t want to answer any questions whatsoever. Because when you’ve been pwned as often as they have, lawmakers and others are going to make your life miserable.

T-Mobile Discovers That Their Pwnage Issues Are Worse Than They Thought

Posted in Commentary with tags , on August 20, 2021 by itnerd

This morning, T-Mobile has shared its latest discoveries as it continues its investigation into the hack that resulted in information on almost 50 million people has been leaked. The new information indicates that 5.3 million more current postpaid customer accounts that were compromised:

We previously reported information from approximately 7.8 million current T-Mobile postpaid customer accounts that included first and last names, date of birth, SSN, and driver’s license/ID information was compromised. We have now also determined that phone numbers, as well as IMEI and IMSI information, the typical identifier numbers associated with a mobile phone, were also compromised. Additionally, we have since identified another 5.3 million current postpaid customer accounts that had one or more associated customer names, addresses, date of births, phone numbers, IMEIs and IMSIs illegally accessed. These additional accounts did not have any SSNs or driver’s license/ID information compromised.

And that’s not all:

We also previously reported that data files with information from about 40 million former or prospective T-Mobile customers, including first and last names, date of birth, SSN, and driver’s license/ID information, were compromised. We have since identified an additional 667,000 accounts of former T- Mobile customers that were accessed with customer names, phone numbers, addresses and dates of birth compromised. These additional accounts did not have any SSNs or driver’s license/ID information compromised.

I have the sneaking suspicion that more details are going to leak out that will bring this number to the 100 million that was previously reported. And that won’t be a good look for T-Mobile.

T-Mobile Got Pwned…. Again….. And They Are Sure Acting Like They Don’t Want Their Customers To Know About It

Posted in Commentary with tags , on August 17, 2021 by itnerd

T-Mobile recently disclosed that they will investigate the theft of over 100 million of their users’ personal identifiable information being sold on the web. How many customers does T-Mobile have? About 100 million. So basically, every T-Mobile customer has been affected by this. And this is not the first time that T-Mobile has been pwned. More on that shortly.

All together now: Whiskey Tango Foxtrot?

“We have determined that unauthorized access to some T-Mobile data occurred,” a spokesperson said in a statement. But “we are confident that the entry point used to gain access has been closed.”

The company added that they are addressing the matter with the “highest degree of urgency” but admitted it will “take some time.”

The company on August 15 said it is looking into an alleged massive data breach compromising over 100 million users based on a claim made in an underground forum post, according to Vice’s Motherboard.

T-mobile said it cannot confirm further details until it has completed its assessment but ensured customers it has enlisted the help of digital forensic experts and law enforcement.

The seller, according to the post, is asking for bitcoin in exchange.

Here’s where things get sketchy. T-Mobile posted a notification on the Twitter account of their CEO Mike Sievert. Not their main Twitter account. Not their customer assistance account. The CEO’s Twitter account.

This account is the least likely to be seen by T-Mobile customers. The responsible thing for T-Mobile to do would have been publicize this far and wide. But that’s what’s happening here. And what’s worse is that Sievert, or someone who controls his Twitter account is handing over these sorts of responses over and over again:

Here’s another example:

Let’s cut to the chase:

  • T-Mobile got pwned. Again as this is not the first time that they have been pwned. Let me list all the previous hacks:
    • The theft of the details of 2 million customers in August 2018
    • A hack involving the theft of prepaid customer data in November 2019
    • The theft of employee and customer data in March 2020 
    • A “security incident” involving “malicious, unauthorized access” to some information related to T-Mobile accounts in January
  • Every customer has been affected. Every. Single. Customer.
  • T-Mobile isn’t exactly going out of their way to inform their customers about this. Nor does it seem that they have a plan to protect their customers.
  • What communication they are doing is a PR disaster.

T-Mobile at this point deserves to not only lose every customer that they have, but this merits them being hauled in front of congress, investigated, and punished in the most severe way possible. Because T-Mobile has simply failed it’s customers in the worst way possible.

Sprint & T-Mobile USA Announce Merger Agreement

Posted in Commentary with tags , on April 30, 2018 by itnerd

The big news coming out of the US telco space over the weekend is a merger agreement between US telcos Sprint and T-Mobile. The new combined company will be named T-Mobile and current T-Mobile CEO John Legere will serve as the Chief Executive Officer. The new company promises that it will be “force for positive change” . What sort of change? Here’s the video:

Along with the faster rollout of 5G technology, Sprint and T-Mobile say the merger will lead to job creation, lower prices for consumers, improved coverage, and “unprecedented network capacity.” We’ll see if all that comes true. Assuming that this deal gets approved of course. That’s a bit of an open question seeing as there’s currently a battle in the courts with the AT&T / Time Warner merger. So we’ll have to wait and see on that front.

Hopefully, this new company decides to come to Canada as we could use some of that “force for positive change” around here.