33 ms·
Claimed AT&T hack of 70M customer records including SSN, name, address
- curtis3389 5y agoIf I worked at Verizon, I'd have trouble sleeping for a while.
- rvz 5y ago> Here is the data that is available in this leak: Name Phone number Physical address Email address Social security number Date of birth Not only the phone number but the physical address? If this is true, absolutely outrageous. > The hacker has said he is willing to reach “an agreement” with AT&T to remove the data from sale. Might as well pay the hacker's ransom, AT&T to remove the data from sale otherwise if leaked; a massive fine (probably larger than the hacker's ransom) awaits you. First T-Mobile and now (if true) AT&T. Let's see who is next to unveil another hidden breach... maybe Verizon has something to hide?
- idiotsecant 5y ago>a massive fine (probably larger than the hacker's ransom) awaits you. Based on past experience, unlikely.
- ryanlol 5y agohttps://krebsonsecurity.com/2015/11/fcc-fines-cox-595k-over-lizard-squad-hack/ https://krebsonsecurity.com/2015/11/fcc-fines-cox-595k-over-... Cox had to pay up over a few social engineering calls.
- dylan604 5y ago>a massive fine (probably larger than the hacker's ransom) awaits you. ... maybe Verizon has something to hide? If we're just making stuff up, then maybe Verizon is the hacker trying to take down the competition? It's as likely as ATT being fined anything significant
- christophilus 5y ago> a massive fine (probably larger than the hacker's ransom) awaits you. If you mean, massive executive bonuses, and zero policy response by the government, then yes.
- gjsman-1000 5y agoFirst T-Mobile, then AT&T (except that AT&T is denying it, which is hopeful). All eyes on Verizon...
- swiley 5y ago>which is hopeful That’s like saying “the house is on fire but there’s little smoke which is hopeful.” Of course they’re denying it!
- chasil 5y agoThe nice thing about using an MVNO (aside from cost reduction) is that the carrier never receives any of that PII. I like the Red Pocket plans on Ebay, and they never asked for an SSN.
- travisporter 5y agoHow are MVNOs able to offer a lower price than the carriers? I was interested but didn't switch because I was worried they are selling my info or something.
- detaro 5y agoThey usually spend less on advertising/store presence/... (e.g. around here the large mobile networks have branded shops and such, the MVNOs almost never have and either sell only online or a supermarket brand and piggybacking on that store network), their plans might have restrictions the main network ones don't have, ... And in reverse, better brand recognition/(impression of) service quality allows the network operators to charge more and still get customers, the MVNOs need to be cheaper to compete with that.
- chasil 5y agoThe process of porting numbers between MVNOs is more difficult than using a main carrier with brick-and-mortar locations. I ported my landline to Page Plus in the late 2000s (which took over a week). I still have that number, and I have never spoken to a person when porting it between MVNOs (always over chat or email). My last port to Red Pocket took two days to get right. This can be a frustrating procedure, and many people prefer the major carriers for in-presence customer service for issues like this. I have repeatedly switched between Verizon and AT&T when necessary due to phone hardware or coverage, and MVNOs usually allow this to be done (a limited number of times) through automated simcard changes with no customer service interaction. The one surprising thing about my recent move to Red Pocket is the lack of voicemail in the included plan (it's available with a surcharge). I'm not certain if I miss it.
- ve55 5y agoIt would certainly be a nice time to stop using SSNs as keys, SMS as 2FA, and more importantly having next to zero consequences for this kind of stuff. At this point we just expect this to keep happening over and over again with nothing changing, it's a very strange thing to observe...
- christophilus 5y agoJust this week, I had to sign into a service for a very large transaction I'm privy to. My password? The last 4 of my social. It's unbelievable how dumb so many of our systems are.
- cge 5y agoI'm in Ireland at the moment, where the health system, and vaccination process, appears to use mother's maiden name as a de facto password. There is no option to change it. It is often asked in person, and so can't be used as a placeholder. For business reasons, my mother has her parents' last name, I have hers, and this fact is easily discovered online with a few minutes research...
- specktr 5y agoOn a similar note, I setup my utility account this week. It was suggested by the representative that I use the last 4 digits of my SSN as a pin for my account. Pretty disappointing how short sighted many companies are when it comes to security practices.
- smsm42 5y agoThat's because if somebody gets in, it's not their problem for having lax authorization, it's your problem for being "victim of identity theft" and all the burden of proving it wasn't you rests on you. It costs them nothing to give out horrible advice, so they do it.
- ttGpN5Nde3pK 5y ago+1. And orgs (gov and private) will continue to just ask for completely unnecessary information because, why not? Throw it in some database with root:root as the pw and shrug when it gets breached. It really needs to stop. The only person that loses is the person that now has to potentially deal with identity theft or getting doxxed for the rest of their life...
- nathanaldensr 5y agoWhen does this end? When do our useless governments put a stop, once and for all, to these ridiculous lax security practices in corporations? I feel like I'm being forced to become a luddite--not because I don't love technology but because it's being used for such evil and potentially life-destroying purposes.
- caeril 5y agoThis situation could be greatly improved if these companies didn't have or need to have this data in the first place. Prepaid mobile plans carry a lot of stigma with them - perceived to be "low-class", or even criminal by many. But at least your SSN and address won't be in their database.
- _rs 5y agoWith AT&T at least if you want the highest priority on their towers you have to be on their Elite plan (QCI 7 I believe), which is post-paid only
- hypothesis 5y agoYikes. Is that something that AT&T openly advertising?
- trasz 5y agoWhat does the “priority on the towers” do?
- brewdad 5y agoIf you want to use your mobile data, you get sent to the back of the queue. Higher priority users might get 50mbps. You will be lucky to get 1mbps and in some cases less than that. I don't know if there is an impact on call availability as well.
- gizdan 5y agoI don't know about the US, but here in the UK prepaid mobile isn't necessarily looked down upon, but it's significantly more expensive than a contract. It's the main reason why people just go with a contract despite being locked in for 2 or more years. Even sim-only contracts are considerably cheaper.
- gigel82 5y agoInterestingly, I stopped being an AT&T customer 4 years ago but just this morning I received a phishing SMS containing my real name and a mention of AT&T overpayment or some-such. Could be a coincidence, or it could be the data is already out and being used.
- gzer0 5y agoI received the exact same thing. I was also a customer of AT&T around 4 or so years ago. The odd thing to me was the phishing text said to CALL ATT's very own number. No links or anything.
- knubie 5y agoI know this doesn’t add much to the conversation but I got the same text this morning and I am currently still with att.
- nabakin 5y agoThe seller hasn't sold the data yet. Unless it has already been available behind the scenes and changed hands, I don't think the breach is related.
- tyingq 5y agoI'm usually skeptical about denials, like AT&T is doing here. But in this case, there would be some incentive for the hackers to misrepresent the source/freshness/etc of the data. Given the recent T-Mobile hack, if they can tag the data as coming from AT&T and being fresh, it might fetch a higher price either from AT&T, or data buyers. In other words, it could be a re-label of some older exposed data.
- kingnothing 5y agoThe hackers selling the info are well known for providing fresh data, to the point that they’ve given away old data for free. I doubt they’d risk their reputation on reselling a different leak.
- tyingq 5y agoAh, thanks...not mentioned in the linked article. There's more info in the source article: https://restoreprivacy.com/att-data-breach-70-million-customers/ https://restoreprivacy.com/att-data-breach-70-million-custom... The hacker group is "ShinyHunters".
- lotsofpulp 5y agoI wonder if the price of leaked data dropped after Experian's data leak from Sep 2017 that included basically everyone in the US that uses credit. I imagine the difference in data since the Experian leak are for people that became adults since Sep 2017 or immigrants or some information about new addresses/names from moves/marriages, etc.
- metaphor 5y agoWhat AT&T service compels consumer SSN disclosure to begin with?
- oenetan 5y agoIf you take out credit, or don't want to pay security deposit, they ask for it
- metaphor 5y agoThanks for the clarification.
- mancerayder 5y agoI think it's any contract with a carrier. They want the ability to go after you and hurt your credit if you refuse to pay, is my guess. It's disgusting.
- lotsofpulp 5y agoHow is it disgusting for a lender to be able to look up someone's credit history and determine if they are an appropriate credit risk for them? The alternative is everyone gets (or does not get at all) credit on the same terms without regards to personal behavior or risk profiles, which is a valid option, but I would still think "disgusting" is a strong word to describe the prior scenario.
- mancerayder 5y agoYou're asking this question in the following context: getting a cell mobile provider contract requires a social security number. Social security number is used to pin a score on someone's credit worthiness. Mobile provider gets hacked, exposing clients to bad actors using social security number and associated data to open credit lines fraudulently and hurting users' credit worthiness scores. The disgusting part is the whole reason the providers demanded SS # is to defend their own interests to threaten clients with collection agencies and credit score dips. The neglect of these same now cause clients to risk getting credit score dips through no fault of their own. Which part of this sits well with you?
- EvanAnderson 5y agoAs I've said before, it's time to wipe the slate on SSN's. They are de facto public anyway. A date should be announced when the entire database will be published. After that date all liability for fraud perpetrated using an SSN as a shared "secret" will be assigned to the party who accepted the SSN as "authentication". That would solve the problem. As an aside: When it comes to an authentication source to take the place of silly shared public "secrets" I think it would be great if the United States Postal Service "pivoted" into issuing digital certificates to individuals. They already have infrastructure and procedures in place for identity verification and physical delivery. I suppose that's too much like a federally-issued ID to ever fly, though our "REAL ID" drivers licenses are, in effect, a federal ID anyway. I'd rather have a digital certificate out of the deal too.
- rafale 5y agoWhat are we gonna use instead? Hardware keys, like Ledger but for ID?
- gruez 5y agoThat's basically what some countries have: IDs with a smartcard built in which functions like a HSM
- dredmorbius 5y agoI'm strongly partial to a wearable token. The NFC Ring is one highly attractive option. - It's inobtrusive enough to wear all, or very nearly all of the time. Contrast cards or similar carried-but-not-worn tokens. - It can be readily use to tap a sensor for identification purposes. Contrast cards or similar tokens (e.g., USB keys), which are far less immediate. - It is replaceable. That is, if it's compromised, stolen, or lost, it can be replaced. If it becomes unadvisable to possess, it's readily discarded and reasonably easily destroyed. This contrasts with biometrics or permanently embedded sensors. - Its absence is reasonably immediately determinable. Again, contrast carried-but-not-worn tokens. - The existing prevalence of ring-wearing makes use of an NFC ring less obvious or evident (mostly a concern in early-adoption periods), or the opting-out of wearing one (which ring is the NFC ring?), without directly querying each individual, which ... might not work regardless (depending on implementations). - There are relatively few people who would be entirely unable to use such a device. Ready alternatives for most such cases exist: wrist bands - Unintentional validation (e.g., surveillance) is relatively easily avoided, if devices require immediate contact with a sensor/receiver. That is, a surveillance entity couldn't mass scan a crowd or region quickly, but would have to individually query rings in close proximity. (This might be achieved through high-volume transit points already, but this already raises the ante.) - It's possible with a query/response system that multiple identities with the same root, but not immediately correlated, could be supported. (Deanonymisation or identity linking remains a significant problem, however.) Ideally, such a system could be limited to only satisfying minimum qualifying criteria (e.g., "I've paid a fare for this trip"), rather than transmitting either a full personal dossier or an absolute identity. Key (so to speak) challenges are in agreeing on a single standard, ensuring crytpgraphic robustness, and protecting privacy, surveillance, and other concerns, as well as distributing the detector infrastructure for desired uses.
- deleted 5y ago[deleted]
- integrale 5y agoGiven that legislation will realistically never keep pace with technology, would it be crazy to implement whitelist data collection law, i.e., no data can be collected unless explicitly allowed? Hypothetically, of course — congress actually putting something like this into law is a different story.
- rsync 5y agoI bought a new iPhone with cash, signed up for a Verizon MVNO using an assumed name and used an impersonal email address (and assumed name) for my Apple ID (which I seldom use). Nobody in this chain has my real name or any significant PII. I don't care if any of them get "hacked". Further, if my phone is lost I just recreate the chain and point my (twilio) number to the new SIM card. I can temporarily forward SMS to email for a day or three. Yes, of course twilio has an assumed name. None of this was difficult nor illegal nor expensive. The enabling factor is that Visa/MC do not actually verify cardholder name (even though everyone thinks they do). So my bank sort of knows who all the providers are, but they'd need to collude with (MVNO or twilio or Apple) to have any real PII which could then be stolen ... My threat model is PII theft via hacks (like this one) and wayward employees at each provider. My threat model is not state actors or LEAs.
- deleted 5y ago[deleted]
- EvanAnderson 5y agoCan you elaborate on "The enabling factor is that Visa/MC do not actually verify cardholder name"? Are you saying that you've got a credit card under an assumed name?
- rsync 5y agoNo, of course not. I am saying that merchants do not have the ability to verify card holder name. Your transaction will process properly with Mickey mouse as first last. Only amex verifies cardholder name. EDIT: relevant stackexchange is here: https://security.stackexchange.com/questions/220724/i-can-pay-by-my-credit-card-under-fake-name-whos-responsible-to-check https://security.stackexchange.com/questions/220724/i-can-pa...
- BeefySwain 5y ago> None of this was difficult nor illegal nor expensive. Is giving a false name to the CC companies not illegal in some way? At the very least I'm certain it is a breach of contract.
- Jaepa 5y agoInterestingly it looks like T-Mobile US also had a very similar data breach a couple days ago. > We have determined that the types of impacted information include: names, drivers’ licenses, government identification numbers, Social Security numbers, dates of birth, T-Mobile prepaid PINs (which have already been reset to protect you), addresses and phone number(s). https://www.t-mobile.com/brand/data-breach-2021 https://www.t-mobile.com/brand/data-breach-2021
- afrcnc 5y agoSomeone posts eight SSNs on a hacking forum and some wild claims, and reporters run it as a legitimate 70 million hack. And people wonder why the term fake news exists.
- codegeek 5y agoKnowing what we know about these companies and their security practices, I would give benefit of doubt to this "someone" who posted on a hacking forum.
- slownews45 5y agoexcept these companies are crap at security and the folks posting have a relatively good reputation? That said - yeah, maybe post 500? This could just be trash as you say.
- tsjq 5y agoTMobile: 100M ATT : 70M suffice to say nearly all adults of USA. I am surprised how come not a single high profile person faces ID Theft and related troubles from these many data leaks !
- lotsofpulp 5y agoTmobile was 40M. It is all small pickles anyway compared to Sep 2017's Experian leak of 147M people's records: https://www.consumer.ftc.gov/blog/2019/07/equifax-data-breach-pick-free-credit-monitoring https://www.consumer.ftc.gov/blog/2019/07/equifax-data-breac... A credit reporting agency's information is all the important information you would need about someone to do something fraudulent with their identity.
- cowturds 5y agoIf only we could <i>change</i> our SSN just like we can name, address, and bank accounts
- figassis 5y agoWhy is it so much harder and costlier for companies to be able to store credit card numbers, but not SSNs? I mean there is a whole certification process that costs hundreds of thousands of dollars to get pci certified, but you could say an SSN has the same of not larger risk profile. You can cancel credit cards, can’t get a new SSN. What is stopping government from implementing the same requirements? No one asks for your card number that is not certified, and certainly you would not give it if asked, even if they said it’s mandatory. So why the SSN leniency?
- x0x0 5y agoA globally unique id is incredibly useful to many businesses, particularly since half of America changes their names. Often repeatedly. So there will be incredible back pressure at implementing this.
- figassis 5y agoThen make it both unique and worthless. Every other country has national ids, and you gain nothing by stealing it, you actually present it almost everywhere, same value as a driver's license. In fact, when pulled over, you are asked for the license and the card, to make sure the license is really yours. What you cannot definitely do is transact with only your nacional id, that's silly. Its identification, not authentication. Your pins, passwords, signatures, presence are required in addition to your ID number to do anything. While in the US, I always thought it was weird the importance that such a document was given, to the point that even laminating it is taboo, complete with a notice written on it. They tell you to not walk around with it. Never understood how it got to this point.
- 41209 5y agoEveryone should put a lock on their credit. Also since it takes a few days to remove the lock, you can't impulse buy a car ( or another big ticket item). At this point the only thing I'll ever need to do a credit check for is a new apartment.
- jmount 5y agoIn the US many companies publicly share their EIN (the equivalent of SSN for companies), and somehow the laws are set up that this isn't a source of identity theft.
- lotsofpulp 5y agoYou cannot get a loan with a company's EIN, nor can you (easily?) get money from the government by filing tax returns with a company's EIN. Therefore there is not much value in fraudulent use of EINs.
- vlovich123 5y agoI’ve been wanting the government to roll out a zero proof ID mechanism so that businesses don’t need any info. Just have a unique ID that’s a representation of that one unique representation. Visit a new Dr’s office? Instead of an SSN generate a new ID they can use to contact you with the government as the intermediary. The business never gets your PII and the government already has your PII and needs to keep it secure (and is politically culpable to breaches). Some care needs to be taken to ensure that the government is actually blinded to the identity of the entity you connect with so that they can’t connect the dots about activity, but I think this is tractable. Same thing with medical records. The current design is abhorrent. Every medical provider has an independent copy of your records. You should be the only one with a copy (or with a storage provider you designate) with strict timely access controls (eg doctor gets the records for 30 days for review or something). That I have to fill out a form to get my own medical records is retarded. This stuff isn’t hard, but it’s hard to make money on so there’s perverse incentives to keep the status quo.
- mrtweetyhack 5y agowhy does ATT have your SSN? Sounds like a lawsuit to me :)
- ourmandave 5y agoI wonder what the settlement for my data be stolen will be? 1. $10 off a new AT&T phone. When you sign a 5 year contract. Excludes all other offers. 2. A free month of AT&T limited service. When you sign a 5 year contract. Excludes all other offers. 3. Or absolutely nothing, like the last bazillion times. The suspense is killing me. I hope it lasts.
- atok1 5y agoAt this point, I'm leaning to believe it's willful on the company side. This is nuts.
- cc101 5y agoMy ATT pin may have been changed without my knowledge. I tried to pay for my pre-pay wifi today and was told I gave the wrong pin. I'm worried, but there doesn't seem to be anything to do about it now.
- BobJS 5y agoAnybody who has ever worked in finance or any number of Finance adjacent industries realizes how easily accessible social Security numbers actually are. Anyone can sign up for a skip tracing service or an identity validation service and reverse search a name and City to find your social security number if they want to. It's probably time to replace the old social security number system.
- Threeve303 5y agoThe only difference between what the cell carriers consider business as usual and a “hack” is getting paid for your data. EDIT: And who knows, maybe after insurance payouts and tax write offs and the usual corporate B.S., it’s still as profitable if they just sold it directly