Could a T-Mobile data breach be traced to creaky machines?

By Angela Gunn | Published June 8, 2009, 6:28 PM

Last Saturday, a group of hackers cited by Insecure.org claimed having pilfered "everything, their databases, confidential documents, scripts and programs from their servers, financial documents up to 2009," belonging to T-Mobile. If claims of a data breach are proven true, investigators should look to some of the machines brought into the company as part of previous deals with third-party providers to modernize the network.

They should also ask what part of "upgrade" the company doesn't understand.

Analysis of the information currently available on the breach indicates that a great many of the machines claimed as breached by the people behind "pwnmobile@safe-mail.net" are behind the times -- in a few cases, seriously behind.

SunOS 5.9, for instance, is the operating system present on a slew of allegedly breached machines handling various functions including (some) security; that version was released in 2002 and superseded in 2005. HP-UX 11.1 and 11.23, which appear to be the operating environments of choice on some of the servers handling billing, were released in 2000 and 2003 respectively; HP is currently shipping 11.31, or 11i v3 in the company's alternate parlance.

Could machines so out-of-date be lacking in patching? It's possible. Moreover, notes a correspondent familiar with the situation, agreements over the years with outside service providers could have provided an environment in which a little breach could grow big. T-Mobile's aggressive US buildout in the past few years, including its serious GSM/EDGE upgrade, was made possible in part by partnerships between the telco and third-party providers, which provide many of the underpinnings that make the system go.

Our correspondent suggested that one or more of those third parties is likely to have shipped any machines it may have introduced to the network with unnecessary services switched on. If those machines were not aggressively tended once on T-Mobile's network and were not in legitimate use, they could have been sitting there for years -- a tempting attack surface for the kind of people who think they could sell evidence of a felony-level hack to T-Mobile's competitors.

In a prepared release this morning, T-Mobile stated: "The protection of our customers' information, and the safety and security of our systems, is absolutely paramount at T-Mobile.  Regarding the recent claim, we are fully investigating the matter.  As is our standard practice, if there is any evidence that customer information has been compromised, we would inform those affected as soon as possible."

10:00 am EDT June 9, 2009 • The latest recitation of T-Mobile's statement to IDG's Robert McMillan last night contained a little addition that appears to confirm that at least some of what the unidentified malicious users demonstrated is genuine customer data.

"Regarding the recent claim on a Web site," the addition reads, "we've identified the document from which information was copied, and believe possession of this alone is not enough to cause harm to our customers. We continue to investigate the matter, and have taken additional precautionary measures to further ensure our customers' information and our systems are protected."

Comments

View comments by with a score of at least

There have been many reports that including the NYTimes that as time goes on both Smartphones and Apple will be targeted more. So I would not be surprise if there was a breech and I suspect we will hear more cases coming to light as much as companies prefer to keep these things a secret.
This reminds of a recent article you wrote about the trials and tribulations of security testing companies. You had me laughing harder than I have in years and, of course, the 1st thought that came to mind was the Movie "Sneakers" which was great and the scene where Redford's company is hired to breech a bank.

Score: 0

|

No doubt at all in my mind that we're headed for a *lot* of smartphone breach attempts. Data-rich targets, to say the absolute least, and the more I read about the current state of mobile security the more I worry.

And *YES* on Sneakers. One of the all-time great geek movies.

Score: 0

|

I'm sorry, I agree with your overall point, but....

...since when has the NY Times ever predicted anything that actually came true? :-p

Score: 0

|

Microsoft's Ray Ozzie: 'Nobody's going to be 100% open'

The mobile apps ecosystems of the world may converge over time, led by apps being ported over across platforms, according to the Chief Software Architect.

Will Firefox beat IE9 to Direct2D rendering?

Just days after Microsoft executives gave conference attendees a peek at a new rendering technology, a Mozilla contributor revealed he's working on the same thing.

Where there's smoke: Apple warranty stance raises troubling questions

Carmi Levy | Wide Angle Zoom: Smoking can be dangerous not only for your lungs, it appears, but for your Apple hardware warranty.

The fallacy of Facebook privacy

Carmi Levy | Wide Angle Zoom: If an insurance company learns something interesting about its client through the Internet, is that snooping?

Microsoft 'worked with Apple' for Silverlight on iPhone, says Goldfarb

By not making such a big deal out of trying to stream video to the iPhone, Microsoft got a big deal out of it, revealed the Silverlight product manager.

Clicker.com cuts through the Web video chaos

In a world where homemade video and Hollywood movies travel the same pipeline, it's good to have a real search engine to cut through the clutter.

A case study in improving software: What Office 2010 can learn from Notion 3

A music composition product gambles with a complete overhaul, in an effort to make headway against two well-known competitors in a tough market.

Kindle 2 update adds battery life, native PDF reader

Amazon has pushed out an update to the Kindle 2 e-reader that lengthens battery life and adds a native PDF viewer.

Safari on iPhone gets competition from a $1 browser app

Apple likes to say it gives iPhone users a full browsing experience, but a new competitor tries to incorporate more desktop browser features.

Action Replay maker sues Microsoft for Xbox 360 'predatory technological barriers'

Third-party video game accessory maker Datel has filed an antitrust lawsuit against Microsoft over the Xbox 360's recent Dashboard update.