T-Mobile Website Glitch Gave Hackers Access To Private Data On Millions Of Customers

T Mobile One
It appears that T-Mobile has only recently squashed a rather serious bug that affected one of the company's subdomains used by staff. In this case, promotool.t-mobile.com was not password protected, allowing anyone that stumbled across it to access stored data.

According to ZDNet, which first reported on the website bug, anyone could add a T-Mobile customer’s phone number to the end or the website address after which they would gain access to a treasure trove of information. Personal customer details such as full name, address, account number, account PIN and tax identification number (in certain instances) were all made visible.

Most wireless carriers allow you set a PIN for your account as an added security measure. When you call in to customer support (i.e. to resolve an account issue), you give that PIN to the CSR so that they can pull up your full account details. If you have all of a person's identifiable account information along with their PIN, your ability to hijack their account increases dramatically.

This exploit is strikingly similar to one that we reported on last year, which also involved gaining access to a T-Mobile subdomain. That particular breach gave hackers access to email addresses, customer names, account numbers and a phone's IMSI number (a unique code which identifies a phone on a network).

hackers

Interestingly enough, the person that uncovered the newest bug received just $1,000 for their troubles as part of T-Mobile's bug bounty program. We don't know about you, but the reward for finding a bug that could affect roughly 75 million customers seems a bit stingy, but we digress.

"The bug bounty program exists so that researchers can alert us to vulnerabilities, which is what happened here, and we support this type of responsible and coordinated disclosure, said a T-Mobile representative in a statement to ZDNet. "The bug was patched as soon as possible and we have no evidence that any customer information was accessed."

T-Mobile is currently in the process of trying to seal a deal to merge with Sprint which would create a strong third-place U.S. wireless carrier to better compete with first-place Verizon Wireless and second-place AT&T.

Brandon Hill

Brandon Hill

Brandon received his first PC, an IBM Aptiva 310, in 1994 and hasn’t looked back since. He cut his teeth on computer building/repair working at a mom and pop computer shop as a plucky teen in the mid 90s and went on to join AnandTech as the Senior News Editor in 1999. Brandon would later help to form DailyTech where he served as Editor-in-Chief from 2008 until 2014. Brandon is a tech geek at heart, and family members always know where to turn when they need free tech support. When he isn’t writing about the tech hardware or studying up on the latest in mobile gadgets, you’ll find him browsing forums that cater to his long-running passion: automobiles.

Opinions and content posted by HotHardware contributors are their own.