By J. Mesa
A cyberattack can seem distant until you get the call that says your systems were breached. Many organizations don’t list a security breach among their top five operational risks. Following real incidents helps put that risk in view, because every industry depends on technology.
The T-Mobile breach of January 2023 is a useful case. It shows how one overlooked connection exposed millions of customers.
What happened in the T-Mobile breach?
In January 2023, T-Mobile announced that an attacker had obtained data on about 37 million customer accounts. The attacker pulled the data through an application programming interface, or API.
According to the company’s disclosure, the activity began in late November 2022. T-Mobile detected it in early January 2023 and shut it down within a day. The attacker had access for more than a month.
What data was exposed?
T-Mobile said the attacker obtained:
- Names
- Billing addresses
- Email addresses
- Phone numbers
- Dates of birth
- Account numbers and plan details
The company said passwords, payment card details, and Social Security numbers were not exposed.
That sounds mild. It isn’t. A name, phone number, birth date, and account number are what a criminal needs to pose as you to a phone carrier, or to write a phishing message that looks real.
What is an API, and how do attackers abuse one?
An API is a connection that lets one piece of software request data from another. When an app shows your account balance, it asks an API for it.
APIs cause breaches when they hand over more than they should. Common weaknesses include:
- No check that the requester is allowed to see the data
- No limit on how many records one requester can pull
- Old or forgotten APIs that nobody monitors
In this case the attacker used an API to collect customer records at scale, without breaking into the core network.
Why does this keep happening to T-Mobile?
The 2023 breach followed several earlier ones. A breach in 2021 exposed data on tens of millions of people and led to a $350 million settlement. The company was in the middle of a large security overhaul when the API incident happened.
It is encouraging that the company invested in security. The repeat incident shows that a large budget does not remove risk. A large company has thousands of systems, and an attacker needs one weak point.
What should I do if my data was exposed?
- Set an account PIN or passcode with your carrier, and change it if you already had one.
- Turn on SIM protection. Carriers offer a setting that blocks someone from moving your number to a new SIM without extra verification.
- Move away from text-message codes for your most important accounts. Use an authenticator app or a security key where you can.
- Freeze your credit with Equifax, Experian, and TransUnion. It is free.
- Watch for phishing. Expect calls, texts, and emails that mention your carrier and your real account details.
- Check your accounts for charges or changes you did not make.
What is SIM swapping?
SIM swapping is a fraud where a criminal convinces your carrier to move your phone number to a SIM card they control. They then receive your calls and texts, including login codes from your bank and email.
Leaked carrier data makes the con easier, because the criminal can answer the carrier’s verification questions. An account PIN and SIM protection are your defense.
How do I spot a phishing message after a breach?
- It mentions the breach and asks you to “verify” your account
- It includes real details, such as your name and plan
- It links to a login page
- It pushes you to act within hours
Your carrier will not ask for your password or PIN by text or email. Go to the company’s app or website yourself. Don’t use the link.
What should businesses learn from this breach?
- Know your APIs. Keep an inventory of every API you expose, including old versions.
- Require authentication and authorization on every request. Confirm who is asking and what they are allowed to see.
- Limit the rate of requests, so one account can’t pull millions of records.
- Monitor for unusual volume. A month of bulk requests should trigger an alert on day one.
- Encrypt sensitive data and use multi-factor authentication for staff.
- Audit on a schedule. Regular security assessments find the forgotten connection before an attacker does.
Does this apply to a small business?
Yes. You may not build APIs, and you use them. Your website, your booking tool, your payment processor, and your accounting software all connect through them.
- Ask your vendors how they secure customer data.
- Remove integrations and plugins you no longer use.
- Give each connected app the least access it needs.
- Rotate API keys when staff or vendors change.
Why does employee training matter?
Technical controls are one half of the defense. Staff need to know the risks and how to respond. Training should cover:
- How to identify and report suspicious emails
- Why strong passwords and multi-factor authentication matter
- What to do in the first minutes of a suspected breach
What is the customer’s role?
Customers protect their own information too. Use strong, unique passwords, check your accounts for unfamiliar activity, and report anything unusual to your provider right away.
Should I switch carriers after a breach?
A breach alone does not tell you which carrier is safest. Every major carrier has disclosed incidents. Judge a provider by how it responds: how fast it tells customers, what protections it offers, and whether it fixes the cause. Whichever carrier you use, set a PIN and turn on SIM protection.
How do I know if I was part of the breach?
T-Mobile notified affected customers directly. If you were a customer in late 2022, check your account messages and mail from that period. You can also search your email address at haveibeenpwned.com.
Your next step
Set a PIN on your mobile account today. It takes five minutes. If your business handles customer data, find out how your systems and vendors would hold up under the same attack. Cerberus Cybersecurity can show you with a risk and compliance assessment. Contact us to schedule one.
Leave a Reply