news.volyx.in

Hackers claim they breached T-Mobile more than 100 times in 2022 (krebsonsecurity.com)

533 points by mikece · 1280 days ago · 326 comments on HN

Article summary

Hackers claim to have breached T-Mobile's internal networks over 100 times in 2022, with the goal of phishing employees and gaining access to internal company tools. The breaches were allegedly used to offer a cybercrime service that could divert text messages and phone calls to another device. T-Mobile declined to confirm or deny the breaches, but stated that they are constantly working to fight against such activity. The company has implemented enhancements to protect against unauthorized access, including multi-factor authentication controls and threat intelligence gathering.

Main themes

  • T-Mobile breaches
  • SIM-swapping
  • telecom security
  • 2FA insecurity
  • regulation and accountability
  • security best practices

What commenters say

  • Regulation is needed to ensure companies prioritize security and protect customer data.
  • Implementing physical security keys for employee authentication could prevent breaches like these.
  • The telecom industry's history of mergers and acquisitions has led to legacy systems and security issues.
  • Using SMS for 2FA is insecure and should be replaced with more secure methods like authenticator apps or physical security keys.
  • Companies should be held accountable for neglecting basic security practices and suffering breaches as a result.
  • Mandating security best practices could lead to unintended consequences and may not be effective in preventing breaches.
  • White-hat hacking should be legally protected to encourage responsible disclosure and improve security.
  • The line between white-hat and black-hat hacking is blurry and legalizing hacking could lead to unintended consequences.