9 ms·
Google Fi seemingly affected by latest T-Mobile data breach
- modeless 4y agoA reasonable headline could state "Google Fi essentially not affected by latest T-Mobile data breach". Look at the data "breached": > limited data including when your account was activated, data about your mobile service plan, SIM card serial number, and active or inactive account status. > It does not contain your name, date of birth, email address, payment card information, social security number or tax IDs, driver’s license or other form of government ID, or financial account information, passwords or PINs that you may use for Google Fi, or the contents of any SMS messages or calls. I mean, that's almost the minimum amount of data T-Mobile has to have to provide the service to Google Fi customers, and nothing else. The actual customer data is probably stored at Google, and is perfectly safe. The chances of someone being able to use the leaked data in a nefarious way seem practically nil.
- markdown 4y ago[flagged]
- rjbwork 4y agoOof. Trying to be a grammar pedant on the internet and getting it wrong. Big L there, homes.
- Dylan16807 4y agoAre you sure that's an attempted grammar nitpick? I thought they were saying the data lost clearly is non-negligible.
- rjbwork 4y agoI suppose I'm not, but given the parent is flagged and dead, and I've got a handful of upmods...my interpretation was the same as many others. This highlights the importance of clear communication.
- Dylan16807 4y agoWell, my interpretation still doesn't make it a good comment. I'm not against it being dead, even if it was completely clear and my interpretation was the only one.
- saagarjha 4y agoI mean the fact is that Google Fi gave my information to a third party that suffered from a breach, which leaked some amount of data. I’m happy it’s not that much data, personally, but it’s still a breach. And from other comments in the thread it seems like some were affected more than that.
- wildrhythms 4y agoI don't see anywhere in the statement where Fi customer information is given to a third party. Here's what it says: >system is used for Google Fi customer support purposes and contains limited data including when your account was activated, data about your mobile service plan, SIM card serial number, and active or inactive account status. >It does not contain your name, date of birth, email address, payment card information, social security number or tax IDs, driver’s license or other form of government ID, or financial account information, passwords or PINs that you may use for Google Fi, or the contents of any SMS messages or calls.
- koheripbal 4y agoSIM swaps were reported, so this is definitely a breach that impacts Google Fi customers.
- CurrentB 4y agoThis could be a dumb question, and I assume the answer is no, but could the SIM serial data potentially be used to aid in a SIM spoof attack?
- dlgeek 4y agoOr to facilitate a SIM swap?
- deleted 4y ago[deleted]
- koheripbal 4y agoAt least 1 reported case of a Fi customer being SIM swapped because of this breach.
- GravityisaHoax 4y agoI feel like there's more to that situation, since he had multiple accounts compromised.
- arkadiyt 4y agoNot everyone got this version of the notice. Here's a reddit user who posted [1] that they were SIM swapped: > Additionally, on January 1, 2023 for about 1 hour 48 minutes, your mobile phone service was transferred from your SIM card to another SIM card. During the time of this temporary transfer, the unauthorized access could have involved the use of your phone number to send and receive phone calls and text messages. Despite the SIM transfer, your voicemail could not have been accessed. We have restored Google Fi service to your SIM card. [1]: https://old.reddit.com/r/GoogleFi/comments/10pjtie/google_fi_data_breach/j6kysv8/ https://old.reddit.com/r/GoogleFi/comments/10pjtie/google_fi...
- livueta 4y agoOof, that's not good. As a Fi user, I'm pretty angry at the moment even though I got the other version of the notice. That's because one of the main reasons I was using Fi in the first place was the perceived protection against sim swapping, via a super locked down special purpose Google account and the apparent inability of T-Mobile CSRs to access Fi customer data. The first thing I thought upon reading the notice was usefulness for sim swapping, and my heart fell upon reading your comment. Good reminder that SMS 2fa fucking sucks and so do the institutions that insist on it, especially those that offer other forms of 2fa but treat SMS as a fallback (why why why why why).
- georgyo 4y agoThe why is obvious. People will lose their 2FA. It's a fact of life. Lost keys with your yubikey. Broken phone without a backup of your totp. Etc. After that, how do you prove that someone owns their account? Send a photocopy of your passport? No way to edit a picture, right? Answer some security questions, which you certainly forgot the answer to. And people are likely using the same questions with the same answer on many sites. Tell them tough luck? The problem is there isn't a good answer for the most common failure mode. SMS 2FA isn't perfect, but it is accessible to nearly everyone and delegates ownership proof to the telephone company.
- gleenn 4y ago
- kornhole 4y agoThe same probably goes for other MVNO carriers such as Mint and Ting. The PII and billing data is with the MVNO carriers. I buy my SIM cards anonymously. I never use cellular near my house and only use it for data over a VPN. So it would not affect me if all of their data was breached.
- chairmanwow1 4y agoLol this is not the same with most people. Pretty incredible if true. Timing attacks are pretty powerful though. Only one person has likely been to all the same places at you at the same time over the past week.
- kornhole 4y agoI don't have a regular movement pattern and only activate the SIM when needed. I also rotate SIM's with my partner to confuse things more. We are part of a budding trend.
- rrdharan 4y agoIf you really want to be safe you should eat your SIM card. https://youtu.be/wxJkLKjdMcc https://youtu.be/wxJkLKjdMcc
- KennyBlanken 4y ago[flagged]
- yjftsjthsd-h 4y ago> You're paranoid-delusional, and engaging in cargo-cult spycraft where your education seems to be mostly centered around watching hollywood "lone wolf, former spy / contract killer trying to stay off the radar" type movies. > you're nowhere near as interesting or important as you seem to think you are. You actually had some decent points; are the aggressive personal attacks really necessary? Or as the site guidelines put it, > When disagreeing, please reply to the argument instead of calling names. "That is idiotic; 1 + 1 is 2, not 3" can be shortened to "1 + 1 is 2, not 3."
- lanman95 4y agoWhen will T-Mobile take accountability for their repeated data breaches and fix the systemic issues? Is there anyone in the company who cares enough to do something?
- Arnavion 4y agoThe annual T-Mobile data breach is a tradition at this point. 2022 was set to break that tradition but the breach just happened to run a few weeks late.
- wepple 4y agoThe FTC filing says they first got popped in November 2022, so it’s still an annual tradition. Also, they only report the breaches they actually know about. From my understanding of T-mobile, they probably only find a breach when someone completely stumbles into it. For every one they discover I bet there’s 10 they don’t, hah
- geocrasher 4y agoI signed up for Google Fi after the beach... But yikes.
- saagarjha 4y agoKind of upset that Google didn’t provide any details about the context of the breach itself in the email they sent me, just a vague “someone had a breach and don’t blame us”.
- StepBroBD 4y agoAfter all these years, Google Fi still has NOT add 5G support on iPhones, now another data breach, nice!
- wepple 4y agoBecause it’s buried a few links deep: T-Mobile detected the breach January 5 and shut it down “within a day” But It started approximately November 25th, so the attackers were there for at least a month and a half, pulling 37,000,000 records before anyone noticed.
- TinyRick 4y agoIf anyone is worried about a potential SIM swap attack due to this breach, you can order a new SIM card free of charge at https://fi.google.com/ordersim https://fi.google.com/ordersim