Skip to content
TopicTracker
From HackerNewsView original
TranslationTranslation

Major mobile carrier left user PII in the clear

A major mobile carrier was found storing sensitive customer PII, including names, addresses, and call logs, in plaintext in a database accessible with only sudo-level credentials. The security lapse exposed personal data without encryption or adequate access controls.

Background

- The Register reported that a major mobile carrier (likely T-Mobile, based on the incident) left customer PII — including names, addresses, account passwords, and in some cases Social Security numbers — exposed in a plain-text database accessible with basic credentials. - The exposure was discovered by a security researcher who was hired by the carrier and given standard employee-level database access, highlighting how internal privilege controls failed. - PII (Personally Identifiable Information) refers to data that can identify a specific individual; storing it "in the clear" means it was not encrypted or hashed, a basic security lapse. - The incident underscores a recurring problem in telecom: large legacy IT systems with weak access controls and poor data hygiene, making customer data an easy target for insider threats or external attackers who compromise low-level accounts.