HomeSecuritySecurity researchers uncover vulnerabilities in AT&T, T-Mobile and Sprint

Security researchers uncover vulnerabilities in AT&T, T-Mobile, and Sprint

This hasn't been a good week for telecommunications companies: security researchers uncovered security flaws at AT&T, Sprint, and T-Mobile that could have left customer data exposed.

T-Mobile

Yesterday, BuzzFeed News reported on two flaws that left customer information vulnerable at AT&T and T-Mobile. In T-Mobile’s case, a “technical error” between Apple and T-Mobile’s account validation API allowed an unlimited number of attempts on an online form, which would have allowed a hacker to use some commonly available tools to guess a PIN or the last four digits of a customer’s Social Security number.

Something similar happened with phone insurance company Asurion and AT&T customers. An online application form allowed anyone with the customer's phone number to access a form that allowed them unlimited guesses to guess a customer's password, leaving them completely vulnerable to an attack.

In any case, both companies patched the above vulnerabilities.

In another case this weekend, TechCrunch reported that security researchers gained access to an internal Sprint staff portal due to “weak and easily exploitable usernames and passwords,” with a lack of two-factor authentication. Once inside, the researcher gained access to customer account information for Sprint, Boost Mobile, and Virgin Mobile. The researcher also reported that anyone who gained access could make changes to customer accounts and that customer PINs. A Sprint spokesperson confirmed the vulnerability to TechCrunch, noting that they do not believe customers were affected by the vulnerability and that they are working to fix the issue.

It’s worth noting that vulnerabilities aren’t necessarily breaches, but rather vulnerabilities like these that allow bad actors to gain access to a system and exploit the customer data they have access to. These systems are necessarily complex: companies like AT&T, Sprint, and T-Mobile have to balance providing access for employees to do their jobs and for customers to access their information. However, given the damage a hacker can do with the vast amounts of data these companies have, it’s clear that they need to be more proactive about protecting their customers.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS