{"id":1229,"date":"2024-11-08T20:27:17","date_gmt":"2024-11-09T03:27:17","guid":{"rendered":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/?p=1229"},"modified":"2024-11-08T20:27:21","modified_gmt":"2024-11-09T03:27:21","slug":"data-breach-fallout-company-faces-multi-million-dollar-fine-for-data-security-failures","status":"publish","type":"post","link":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/2024\/11\/08\/data-breach-fallout-company-faces-multi-million-dollar-fine-for-data-security-failures\/","title":{"rendered":"Data Breach Fallout: Company Faces Multi-Million Dollar Fine for Data Security Failures"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">A total $31.5 million penalty has been issued against a famous telecom brand, \u201cT-Mobile\u201d to settle an investigation by the Federal Communications Commission (FCC) for a past series of data breaches that leaked millions of personal data. This company has reached an agreement with the US Federal Communications Commission (FCC) to give $15.75 million as a penalty against a sequence of cyber security breaches from previous years, and the rest will function as collateral for their data security development. The FCC inspection finds a serious gap in the company\u2019s cyber threat protection, which led to a series of cyberattacks taken place in 2020,2021 and 2023 respectively.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What is T-Mobile and how it operates?<\/h3>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"975\" height=\"518\" data-src=\"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2024\/11\/image-16.png\" alt=\"\" class=\"wp-image-1232 lazyload\" data-srcset=\"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2024\/11\/image-16.png 975w, https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2024\/11\/image-16-300x159.png 300w, https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2024\/11\/image-16-768x408.png 768w\" data-sizes=\"(max-width: 975px) 100vw, 975px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 975px; --smush-placeholder-aspect-ratio: 975\/518;\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">T-Mobile US Inc. or \u201cT-Mobile\u201d, is a US based wireless network operator that mainly provides services like voice, text, video calling, and data communications to postpaid, prepaid, and wholesale customers under T-Mobile brands. This company also engaged in the distribution of smartphones, routers, and other mobile communication devices. T-Mobile also operates in Canada with unlimited talk, text, and setup or roaming charges exempt.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Analysis of Each Cyber Attacks<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">T-Mobile\u2019s Data Breach\u2019 2020<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">T-Mobile faced a cyberattack in 2020 where lots of personal data got stolen. Though the company denied that no customer data was leaked during the cyberattack, nevertheless, hackers from the dark web forum affirmed that, they accessed a total of 100 million customers personal information like names, phone numbers, home addresses and IMEI numbers. Additionally, they disclosed that they have reached the server through hosting phishing attacks over mail-SMS text messages, and scam calls to the end user. Hackers also used the SIM card swapping technique where bad actors can take control of the end user\u2019s phone number, which led them to effectively access\u00a0 their account and prevent the end user from entering the account.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"894\" height=\"403\" data-src=\"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2024\/11\/image-17.png\" alt=\"\" class=\"wp-image-1233 lazyload\" data-srcset=\"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2024\/11\/image-17.png 894w, https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2024\/11\/image-17-300x135.png 300w, https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2024\/11\/image-17-768x346.png 768w\" data-sizes=\"(max-width: 894px) 100vw, 894px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 894px; --smush-placeholder-aspect-ratio: 894\/403;\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Furthermore, cyber attackers exploited this process by interrupting text messages intended for authorization, which also allowed them to obtain access to other accounts linked to the individual end user\u2019s phone number.<em>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/em><\/p>\n\n\n\n<h4 class=\"wp-block-heading\">T-Mobile\u2019s Data Breach\u2019 2021<\/h4>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"881\" height=\"368\" data-src=\"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2024\/11\/image-18.png\" alt=\"\" class=\"wp-image-1234 lazyload\" data-srcset=\"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2024\/11\/image-18.png 881w, https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2024\/11\/image-18-300x125.png 300w, https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2024\/11\/image-18-768x321.png 768w\" data-sizes=\"(max-width: 881px) 100vw, 881px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 881px; --smush-placeholder-aspect-ratio: 881\/368;\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">In 2021, personal information of over 50 million customers of T-mobile, including SSN (Social Security Number) got leaked. During the data breach, previous, present, future potential customer and postpaid customers got affected. However, one good thing about this event is that bank details of each customer were safe during the hacking. The American hacker, John Brinns, who took the responsibility of this hacking, mentioned that the routers and IP addresses of T-Mobile company were very weak, which allowed him to grab data from more than 100 servers. In this type of attack, hackers observe the system\u2019s public isolated network components and try to find a weak window in the network architecture that acts as digital home addresses for other devices connected to the network. &nbsp;Binns didn\u2019t mention about any settlement with T-Mobile; nonetheless, he does mention trading the data into dark web that will be used for identity theft or future possible cyber-attacks.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">T-Mobile\u2019s Data Breach\u2019 2023<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">After facing several data breaches, yet flaws remain in T-Mobile\u2019s servers, and they faced another huge cyberattack in 2023. In this recent attack, over 37 million customer\u2019s data, like birthday and contact information got leaked. The company ensured that, no sensitive information like bank details or Social Security Number was stolen during the cyberattacks. The data breach actually happened on November 25<sup>th<\/sup>, 2022, and the company declared the news after 8 weeks, on January 19<sup>th<\/sup>, 2023. In this cyberattack, hackers used APIs to enter the system.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"975\" height=\"416\" data-src=\"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2024\/11\/image-19.png\" alt=\"\" class=\"wp-image-1235 lazyload\" data-srcset=\"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2024\/11\/image-19.png 975w, https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2024\/11\/image-19-300x128.png 300w, https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-content\/uploads\/sites\/119\/2024\/11\/image-19-768x328.png 768w\" data-sizes=\"(max-width: 975px) 100vw, 975px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 975px; --smush-placeholder-aspect-ratio: 975\/416;\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">API, or Application Programming Interface is a type of software interface that works as a connection channel between computers or their programs. In this type of attack, hackers attempt to manipulate APIs by locating the system, security details like how the API is constructed and applied. After that, hackers try to find the weaknesses of the system like insufficient encryption and poor authentication which led them into cyber-attacks like DDOS (Distributed Denial of Service), MITM (Man-In-The-middle), API injection attack.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">After facing many frequent cyberattacks, it is obvious that there was insufficiency in the company\u2019s data security protection. Telecom companies should take proper security measurements against cyber attacks as they engage with consumers sensitive data. Hackers are more advanced these days, and they look for every tiny loophole in the system. As a consequence, every company that is occupied with people\u2019s sensitive data should increase their data privacy threshold up to the mark. &nbsp;At the end, penalty cannot retrieve the stolen data.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Reference:<\/strong><\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Coker, J. (2024, October 1). <em>T-Mobile to pay $15.75m penalty for multiple data breaches<\/em>. Infosecurity Magazine. https:\/\/www.infosecurity-magazine.com\/news\/t-mobile-penalty-data-breaches\/<\/li>\n\n\n\n<li>Plc, G. (n.d.). <em>Tmobileus Inc company Profile &#8211; Tmobileus Inc Overview<\/em>. https:\/\/www.globaldata.com\/company-profile\/tmobileus-inc\/#:~:text=T%2DMobile%20US%20Inc%20(T,%2C%20prepaid%2C%20and%20wholesale%20customers.<\/li>\n\n\n\n<li>Lukic David Luki\u0107 is an information privacy, D. (2020, August 17). <em>T-Mobile Data Breach: The infamous cyber attack<\/em>. IDStrong. https:\/\/www.idstrong.com\/sentinel\/the-saga-of-t-mobile-data-breach\/<\/li>\n\n\n\n<li><em>IP address hacking: Risks and tips for Secure Networks<\/em>. Trend Micro Help Center. (2024, October 31). <a href=\"https:\/\/helpcenter.trendmicro.com\/en-us\/article\/tmka-12368#iphack\">https:\/\/helpcenter.trendmicro.com\/en-us\/article\/tmka-12368#iphack<\/a><\/li>\n\n\n\n<li><em>Routing attack meaning<\/em>. Ledger. (2024, March 13). https:\/\/www.ledger.com\/academy\/glossary\/routing-attack#:~:text=A%20routing%20attack%20is%20a,it%20into%20multiple%20isolated%20components.<\/li>\n<\/ol>\n","protected":false},"excerpt":{"rendered":"<p>A total $31.5 million penalty has been issued against a famous telecom brand, \u201cT-Mobile\u201d to settle an investigation by the Federal Communications Commission (FCC) for a past series of data breaches that leaked millions of personal data. This company has reached an agreement with the US Federal Communications Commission (FCC) to give $15.75 million as &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/2024\/11\/08\/data-breach-fallout-company-faces-multi-million-dollar-fine-for-data-security-failures\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Data Breach Fallout: Company Faces Multi-Million Dollar Fine for Data Security Failures&#8221;<\/span><\/a><\/p>\n","protected":false},"author":675,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"ngg_post_thumbnail":0,"footnotes":""},"categories":[1],"tags":[6],"class_list":["post-1229","post","type-post","status-publish","format-standard","hentry","category-uncategorized","tag-data-breach","entry"],"featured_image_src":null,"featured_image_src_square":null,"author_info":{"display_name":"Md. Saidul Arifin Shuvo","author_link":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/author\/md-saidul-arifin-shuvo\/"},"_links":{"self":[{"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/posts\/1229","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/users\/675"}],"replies":[{"embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/comments?post=1229"}],"version-history":[{"count":1,"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/posts\/1229\/revisions"}],"predecessor-version":[{"id":1239,"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/posts\/1229\/revisions\/1239"}],"wp:attachment":[{"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/media?parent=1229"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/categories?post=1229"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/jacobson-cpsc\/wp-json\/wp\/v2\/tags?post=1229"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}