T-Mobile Website Allowed Hackers to Access Your Account Data With Just Your Phone Number

Lorenzo Franceschi-Bicchierai reports:

Until last week, a bug on a T-Mobile website let hackers access personal data such as email address, a customer’s T-Mobile account number, and the phone’s IMSI, a standardized unique number that identifies subscribers. On Friday, a day after Motherboard asked T-Mobile about the issue, the company fixed the bug.

The flaw, which was discovered by security researcher Karan Saini, allowed malicious hackers who knew—or guessed—your phone number to obtain data that could’ve been used for social engineering attacks, or perhaps even to hijack victim’s numbers.

Read more on Motherboard.

About the author: Dissent

Comments are closed.