Skip to main content

Bug on T-Mobile website allowed hackers to access account info

T-Mobile storefront with corporate signage.
Image used with permission by copyright holder
Another day, another privacy issue. Until last week, a T-Mobile website allowed hackers to gain access to personal information like email addresses, T-Mobile account numbers, and more, using only the customer’s phone number. The story was first reported by Motherboard, which said that T-Mobile fixed the issue one day after Motherboard asked the company about it.

Discovered by security researcher Karan Saini, the flaw basically allowed hackers who knew or guessed your phone number to gain valuable information that could then be used in a social engineering attack or even to gain access to other personal information elsewhere online. That put 76 million T-Mobile customers in danger of having their data compromised.

Recommended Videos

Even more concerning is the fact that, according to Saini, it would have been pretty easy for an attacker to write a script that automatically retrieved all account details through this bug. As part of the bug, hackers could also access a user’s IMSI number, which is basically a unique identifying number for customers. Using that, hackers could do things like track a user’s location, intercept texts and calls, and more. On top of that, the number could theoretically be used to conduct fraud through taking advantage of the notoriously insecure SS7 network, which is a backbone communications standard.

T-Mobile, for its part, disputes some of the claims made by Saini. Instead of affecting all 76 million customers, T-Mobile says that the bug only affects a small portion of customers. The company also said that it fixed the bug within 24 hours of it being discovered and according to Saini, the company gave him $1,000 for being a part of the T-Mobile bug bounty program, which rewards people who find and report bugs and flaws.

The report comes at a time when it’s looking more and more like Sprint and T-Mobile will announce a merger in the next few weeks. It’s unlikely this report will have an affect on talks about the merger.

There does not seem to be any evidence that any malicious hackers knew about or exploited the bug, but that doesn’t mean it didn’t happen. Either way, we reached out to T-Mobile and will update this story if we hear back.

Christian de Looper
Christian de Looper is a long-time freelance writer who has covered every facet of the consumer tech and electric vehicle…
5 carriers you should use instead of T-Mobile
The T-Mobile logo on a smartphone.

When it comes to performance, quality, and reliability, T-Mobile is undoubtedly one of the best carriers in the U.S. It offers the fastest speeds and the broadest coverage with reasonably priced plans that include quite a few perks.

However, that may still add up to more than you want to pay; top-notch performance comes with a higher price tag attached. The good news is that T-Mobile is far from the only game in town. In addition to the other two of the big three U.S. carriers -- AT&T and Verizon -- there are dozens of Mobile Virtual Network Operators (MVNOs) that piggyback on the big carrier networks with more affordable plans that offer the same coverage and great performance at a fraction of the price. You’ll get fewer perks, and customer service may not be as responsive, but those may be reasonable tradeoffs for how much you’ll save.

Read more
T-Mobile is buying one of the largest carriers in the U.S.
Cell phone tower shooting off pink beams with a 5G logo next to it.

If you were impacted by T-Mobile's latest price hike and were looking for an alternative carrier, we have some bad news — T-Mobile is buying US Cellular. For those unaware, U.S. Cellular is the fifth-largest carrier in the U.S. despite being a regional carrier based mostly in the Chicago area. Unlike mobile virtual network operators (MVNOs) like Metro by T-Mobile or Visible, which piggyback on a parent carrier’s network, US Cellular has its own towers and stores.

The deal would see T-Mobile pay $4.4 billion to take over US Cellular’s wireless customers, stores, and 30% of its spectrum assets. It includes a combination of cash and T-Mobile assuming $2 billion of U.S. Cellular’s debt. US Cellular will keep control of 4,400 of its towers and 70% of its spectrum portfolio, but T-Mobile will extend its leases for 600 US Cellular towers and sign new long-term leases on 2,015 more towers. In a conference call about the deal, T-Mobile also committed to hiring a significant number of U.S. Cellular associates.

Read more
Your next T-Mobile bill might be more expensive
The T-Mobile logo on a smartphone.

We have bad news for you if you have an older T-Mobile wireless plan. According to internal company documents obtained by The Mobile Report, rates for your plan are going up by $2 to $5 per month.

Customers with a legacy Simple Choice, ONE, or Magenta plan will likely experience price increases. The increased price applies to each line, meaning that if you have four lines, you could potentially see a monthly increase of up to $20 per lmonth. CNET also corroborated the report with its own sources.

Read more