4 ms·
>The company said it identified malicious activity on Jan. 5 and contained it within a day, adding that no sensitive data such as financial information was comp
by Entinel 4y ago
>The company said it identified malicious activity on Jan. 5 and contained it within a day, adding that no sensitive data such as financial information was compromised.
> However, some basic customer information was obtained, such as name, billing address, email and phone number, T-Mobile said.
Is this not sensitive information? That all qualifies as PII.
- hunter2_ 4y agoPlus, another article [0] goes on to add "dates of birth, T-Mobile account numbers and information describing the kind of service they have" which gets me wondering about social engineering against CSRs, leading to a wave of SIM hijacking and the like. [0] https://www.cnn.com/2023/01/19/tech/tmobile-hack/index.html https://www.cnn.com/2023/01/19/tech/tmobile-hack/index.html
- alexriddle 4y agoIn the UK (arising from GDPR so I would assume EU as well), sensitive personal data is an enhanced category of PII which requires more considered handling. This would include things like race, health conditions, disabilities, sexual orientation, political views - basically things that you wouldn't expect T-Mobile to be storing.
- orhmeh09 4y agoIt is all PII. At the same time, all of this is often readily available for free from local government websites — this data and more are present for anyone who registers to vote in Seattle (maybe King County?), in a downloadable spreadsheet. I hate that this information is out there. For most of us it’s one in a series of unwanted disclosures. I care and disapprove on principle but I don’t think I’m compromised any more than I already am.
- sedatk 4y ago> Is this not sensitive information? Not after T-Mobile breach.
- jackcosgrove 4y agoIn these breaches there always seem to be two tiers of data, sensitive data that remains secure and less sensitive data that is leaked. This shows to me that companies are capable of securing sensitive data in most cases, and don't care as much about less sensitive data (even if it is PII). Maybe all data should be encrypted at rest, in transit, etc. and not just passwords, socials, and credit card numbers.
- baxtr 4y agoRemember phone books? Also, this type of PII got leaked very often by now.
- deleted 4y ago[deleted]