Skip to main content

Bug on T-Mobile's website left customer data unprotected

posted onMay 25, 2018
by l33tdawg

For the second time this week, a company has been found to have accidentally exposed customer data to virtually anyone. Following TeenSafe's incident, it seems that it's now T-Mobile who has left information unprotected due to a bug. The flaw was discovered in April by security researcher Ryan Stevenson.

The information was exposed through a portal hosted on a T-Mobile subdomain that could be found using search engines such as Google. According to a report by ZDNet, the page is meant for use by T-Mobile employees and it contained a hidden API that allowed them to look up customer information by simply adding the customer's phone number at the end of the web address.

The problem is the site wasn't protected by a password, and anyone who stumbled upon the webpage could have obtained customer data, including their address, full name, billing account number, tax ID number, and even account PINs which are used by customers when contacting phone support.

Source

Tags

Security

You May Also Like

Recent News

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th

Friday, June 7th

Thursday, June 6th