Could a T-Mobile data breach be traced to creaky machines?

By Angela Gunn | Published June 8, 2009, 6:28 PM

Last Saturday, a group of hackers cited by Insecure.org claimed having pilfered "everything, their databases, confidential documents, scripts and programs from their servers, financial documents up to 2009," belonging to T-Mobile. If claims of a data breach are proven true, investigators should look to some of the machines brought into the company as part of previous deals with third-party providers to modernize the network.

They should also ask what part of "upgrade" the company doesn't understand.

Analysis of the information currently available on the breach indicates that a great many of the machines claimed as breached by the people behind "pwnmobile@safe-mail.net" are behind the times -- in a few cases, seriously behind.

SunOS 5.9, for instance, is the operating system present on a slew of allegedly breached machines handling various functions including (some) security; that version was released in 2002 and superseded in 2005. HP-UX 11.1 and 11.23, which appear to be the operating environments of choice on some of the servers handling billing, were released in 2000 and 2003 respectively; HP is currently shipping 11.31, or 11i v3 in the company's alternate parlance.

Could machines so out-of-date be lacking in patching? It's possible. Moreover, notes a correspondent familiar with the situation, agreements over the years with outside service providers could have provided an environment in which a little breach could grow big. T-Mobile's aggressive US buildout in the past few years, including its serious GSM/EDGE upgrade, was made possible in part by partnerships between the telco and third-party providers, which provide many of the underpinnings that make the system go.

Our correspondent suggested that one or more of those third parties is likely to have shipped any machines it may have introduced to the network with unnecessary services switched on. If those machines were not aggressively tended once on T-Mobile's network and were not in legitimate use, they could have been sitting there for years -- a tempting attack surface for the kind of people who think they could sell evidence of a felony-level hack to T-Mobile's competitors.

In a prepared release this morning, T-Mobile stated: "The protection of our customers' information, and the safety and security of our systems, is absolutely paramount at T-Mobile.  Regarding the recent claim, we are fully investigating the matter.  As is our standard practice, if there is any evidence that customer information has been compromised, we would inform those affected as soon as possible."

10:00 am EDT June 9, 2009 • The latest recitation of T-Mobile's statement to IDG's Robert McMillan last night contained a little addition that appears to confirm that at least some of what the unidentified malicious users demonstrated is genuine customer data.

"Regarding the recent claim on a Web site," the addition reads, "we've identified the document from which information was copied, and believe possession of this alone is not enough to cause harm to our customers. We continue to investigate the matter, and have taken additional precautionary measures to further ensure our customers' information and our systems are protected."

Comments

View comments by with a score of at least

There have been many reports that including the NYTimes that as time goes on both Smartphones and Apple will be targeted more. So I would not be surprise if there was a breech and I suspect we will hear more cases coming to light as much as companies prefer to keep these things a secret.
This reminds of a recent article you wrote about the trials and tribulations of security testing companies. You had me laughing harder than I have in years and, of course, the 1st thought that came to mind was the Movie "Sneakers" which was great and the scene where Redford's company is hired to breech a bank.

Score: 0

|

No doubt at all in my mind that we're headed for a *lot* of smartphone breach attempts. Data-rich targets, to say the absolute least, and the more I read about the current state of mobile security the more I worry.

And *YES* on Sneakers. One of the all-time great geek movies.

Score: 0

|

I'm sorry, I agree with your overall point, but....

...since when has the NY Times ever predicted anything that actually came true? :-p

Score: 0

|

A real beta process at work: Mozilla fires up Firefox 3.6 Beta 2

In the clearest sign yet that public input really does help the development process, a flurry of bug detections provoked Mozilla to release Beta 2 of the next Firefox.

Snow Leopard and Windows 7 still can't crack the netbook problem

Apple has killed Atom support in OS X 10.6.2 and Windows 7 Starter Edition is stripped of "basic" functionality.

Microsoft's Top 3 advances in Exchange Server 2010

The latest round of changes launched today will impact how admins deliver services to e-mail recipients, and how much companies will pay along the way.

Firefox turns five: Thanks for giving us a choice

Carmi Levy | Wide Angle Zoom: No longer the phoenix rising from the ashes, Mozilla has carried on more than just Netscape's legacy.

The Samsung Intrepid: A nice phone, if you can accept Windows Mobile

Samsung appears to have built solid enough hardware, but it's the software that seems uncomfortable and unintuitive.

Kindle for PC opens in beta, underwhelms

Amazon has opened the beta of Kindle for PC, a companion to the Kindle, but little else.

European ministers approve watered-down 'neutral net' language

The latest provision in the EU's telecoms regulatory framework would let businesses cancel individuals' Internet access, if they go to court first.

It's the US vs. the EU over Oracle+Sun and the meaning of 'open source'

Now that the EU is a virtual country, the US Justice Dept. is taking a stand in favor of its view -- and against the EC's -- that MySQL will survive under Oracle.

Qualcomm: $1.3 billion Samsung licensing deal unrelated to fair trade violations

Samsung has come to a 15-year licensing deal with Qualcomm over 3G and 4G wireless technology.

Nokia's 'limited number' of recalled chargers exceeds 14 million

Today, the Finnish phone maker has begun a recall of mobile phone chargers that are a shock hazard.

Ubuntu 9.10 upgraders report frustration

For those Wine aficionados out there, beware of the remote possibility that your Linux system could be infected by Windows-seeking malware.