Major mobile carrier left user PII in the clear
A major mobile carrier was found storing sensitive customer PII, including names, addresses, and call logs, in plaintext in a database accessible with only sudo-level credentials. The security lapse exposed personal data without encryption or adequate access controls.
Background
- The Register reported that a major mobile carrier (likely T-Mobile, based on the incident) left customer PII — including names, addresses, account passwords, and in some cases Social Security numbers — exposed in a plain-text database accessible with basic credentials.
- The exposure was discovered by a security researcher who was hired by the carrier and given standard employee-level database access, highlighting how internal privilege controls failed.
- PII (Personally Identifiable Information) refers to data that can identify a specific individual; storing it "in the clear" means it was not encrypted or hashed, a basic security lapse.
- The incident underscores a recurring problem in telecom: large legacy IT systems with weak access controls and poor data hygiene, making customer data an easy target for insider threats or external attackers who compromise low-level accounts.