Wednesday, August 17, 2022
London
+6...+15° C
No Result
View All Result
  • Top Stories
  • Political
  • Travel
  • Food
  • Golf
  • Showbiz & TV
  • Backchannel
  • Tennis
  • Contact us
Liverpool News 24
  • Top Stories
  • Political
  • Travel
  • Food
  • Golf
  • Showbiz & TV
  • Backchannel
  • Tennis
  • Contact us
No Result
View All Result
Liverpool News 24
No Result
View All Result
The T-Mobile Data Breach Is Much Worse Than It Had to Be

The T-Mobile Data Breach Is Much Worse Than It Had to Be

Liverpool News 24 by Liverpool News 24
August 18, 2021
in Top Stories
0

In an email overnight, T-Mobile shared details about the data breach it confirmed Monday afternoon. They’re not great. Assorted data from more than 48 million people was compromised, and while that’s less than the 100 million that the hacker had initially advertised, the vast majority of those affected turn out not to be current T-Mobile customers at all.

Instead, T-Mobile says that of the people whose data was compromised, more than 40 million are former or prospective customers who had applied for credit with the carrier. Another 7.8 million are current “postpaid” customers, which just means T-Mobile customers who get billed at the end of each month. Those roughly 48 million users had their full names, dates of birth, social security numbers, and driver’s license information stolen. An additional 850,000 prepaid customers—who fund their accounts in advance—had their names, phone numbers, and PINs exposed. The investigation is ongoing, which means that the tally may not stop there.

There’s no good news here, but the slightly less bad news is that the vast majority of customers appear not to have had their phone numbers, account numbers, PINs, passwords, or financial information taken in the breach. The bigger question, though, is whether T-Mobile really needed to hold onto such sensitive information from 40 million people with whom it doesn’t currently do businesses. Or if the company was going to stockpile that data, why it didn’t take better precautions to protect it.

“Generally speaking, it’s still the Wild West in the United States when it comes to the types of information companies can keep about us,” says Amy Keller, a partner at the law firm DiCello Levitt Gutzler who led the class action lawsuit against Equifax after the credit bureau’s 2017 breach. “I’m surprised and I’m also not surprised. I guess you could say I’m frustrated.”

Privacy advocates have long promoted the concept of data minimization, a fairly self-explanatory practice that encourages companies to hold onto as little information as necessary. Europe’s General Data Protection Regulation codifies the practice, requiring that personal data be “adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.” The US currently has no equivalent on the books. “Privacy laws in the United States that do touch upon data minimization generally don’t require it,” Keller says, “and instead recommend it as a best practice.”

Until and unless the US adopts an omnibus privacy law similar to GDPR—or state-level legislation like the California Consumer Privacy Act starts taking a harder line—data minimization will remain a foreign concept. “In general, collecting and retaining sensitive data of prospective and former customers is not an act of consumer fraud under US law, and is routine,” says David Opderbeck, codirector of Seton Hall University’s Institute of Law, Science & Technology. As inappropriate as it may seem for T-Mobile to keep detailed records on millions of people who may never have been their customers, there’s nothing stopping it from doing so, for as long as it likes.

Now those former and prospective customers, along with millions of current T-Mobile subscribers, find themselves victims of a data breach they had no control over. “The first risk is identity theft,” says John LaCour, founder and CTO of digital risk protection company PhishLabs. “The information includes names, social security numbers, driver’s license IDs: all the information that would be required to apply for credit as someone.”

“It’s still the Wild West in the United States when it comes to the types of information companies can keep about us.”

Amy Keller, Lawyer

The hack would also potentially make it easier to pull off so-called SIM swap attacks, LaCour says, particularly against the prepaid customers who had their PINs and phone numbers exposed. In a SIM swap, a hacker ports your number to their own device, typically so that they can intercept SMS-based two-factor authentication codes, making it easier to break into your online accounts. T-Mobile did not respond to an inquiry from WIRED as to whether International Mobile Equipment Identity numbers were also implicated in the breach; each mobile device has a unique IMEI that would also be of value to SIM-swappers.

T-Mobile has implemented a few precautions on behalf of victims; it’s offering two years of identity protection services from McAfee’s ID Theft Protection Service, and has already reset the PINs of the 850,000 prepaid customers who had theirs exposed. It’s recommending but not mandating that all current postpaid customers change their PINs as well, and offering a service called Account Takeover Protection to help stymie SIM-swap attacks. It also plans to publish a site for “one stop information” Wednesday, although the company didn’t say if it would offer any kind of lookup to see if you’re affected by the breach.

Tags: cybersecuritydata breacheshackst-mobile

Related Posts

Uniper Reports Huge Loss as Russia Cuts Gas Flows
Top Stories

Uniper Reports Huge Loss as Russia Cuts Gas Flows

August 17, 2022
Suspect in Rushdie Attack Loses His Mother’s Support
Top Stories

Suspect in Rushdie Attack Loses His Mother’s Support

August 17, 2022
Behind Enemy Lines, Ukrainians Tell Russians ‘You Are Never Safe’
Top Stories

Behind Enemy Lines, Ukrainians Tell Russians ‘You Are Never Safe’

August 17, 2022
What Liz Cheney’s Lopsided Loss Says About the State of the G.O.P.
Top Stories

What Liz Cheney’s Lopsided Loss Says About the State of the G.O.P.

August 17, 2022
Life in a Ukrainian Unit: Diving for Cover, Waiting for Western Weapons
Top Stories

Life in a Ukrainian Unit: Diving for Cover, Waiting for Western Weapons

August 17, 2022
Turkey’s president signals his disapproval of Finland and Sweden joining NATO.
Top Stories

Turkey’s president signals his disapproval of Finland and Sweden joining NATO.

August 17, 2022

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Julia Fox And Kanye West Confirm Romance With Steamy Photos Just Days After Meeting

Julia Fox And Kanye West Confirm Romance With Steamy Photos Just Days After Meeting

by Liverpool News 24
January 9, 2022
0

Uncut Gems actor Julia Fox has gone public about her relationship with Kanye West days after paparazzi spotted the pair...

Emma Raducanu set to become the 'biggest name in tennis' after US Open victory | Tennis | Sport

Emma Raducanu set to become the ‘biggest name in tennis’ after US Open victory | Tennis | Sport

by Liverpool News 24
September 12, 2021
0

The Australian legend said Raducanu, 18, and her Canadian opponent Leylah Fernandez, 19, are set to fill the void when...

Investigation Demanded Over Tory MP Geoffrey Cox 'Working Second Job From Parliament'

Investigation Demanded Over Tory MP Geoffrey Cox ‘Working Second Job From Parliament’

by Liverpool News 24
November 10, 2021
0

Parliament’s standards watchdog has been urged to investigate a former Cabinet minister over claims he “broke the rules” by using...

Sunny-Day Flooding Is About to Become More Than a Nuisance

Sunny-Day Flooding Is About to Become More Than a Nuisance

by Liverpool News 24
August 2, 2021
0

During the summer of 2017, the tide rose to historic heights again and again in Honolulu, higher than at any...

Rebel Wilson Speaks Out After Australian Paper Admits It Asked Her To Comment On New Relationship Before She’d Come Out

Rebel Wilson Speaks Out After Australian Paper Admits It Asked Her To Comment On New Relationship Before She’d Come Out

by Liverpool News 24
June 12, 2022
0

Rebel WilsonRebel Wilson has spoken out after an Australian newspaper admitted it tried to get her to comment on her...

Legal info

  • Privacy Policy
  • Copyright
  • Contact us

Suspect in Rushdie Attack Loses His Mother’s Support

Uniper Reports Huge Loss as Russia Cuts Gas Flows

Behind Enemy Lines, Ukrainians Tell Russians ‘You Are Never Safe’

Contact us

If you have a question, please feel free to contact us by using a contact form

Liverpool News 24

All rights reserved © 2022

No Result
View All Result
  • Top Stories
  • Political
  • Travel
  • Food
  • Golf
  • Showbiz & TV
  • Backchannel
  • Tennis
  • Contact us

All rights reserved © 2022

We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept”, you consent to the use of ALL the cookies.
Do not sell my personal information.
Cookie SettingsAccept
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT