T-Mobile Got Hacked Again and I Finally Changed My PIN

T-Mobile Got Hacked Again and I Finally Changed My PIN

Tech News data breach privacy security t-mobile

So T-Mobile got hacked. Again. I say "again" because at this point it's basically a T-Mobile tradition, like a company picnic except instead of hot dogs they hand out your social security number.

Here's what I actually know, pieced together from what T-Mobile itself has admitted over the last week or so. Someone got into their systems and pulled data on a genuinely staggering number of people, T-Mobile's own updated count as of a few days ago is over 47 million, and that includes current postpaid customers, former customers, and even people who never signed up but applied for credit with them at some point. Names, dates of birth, social security numbers, driver's license info. For some of the older or prospective-customer records it's less sensitive, but for a chunk of current customers it's the full nightmare bundle. Whoever had the data was reportedly asking six bitcoin for a slice of it on a hacking forum, which at the moment is somewhere around a quarter million dollars, which tells you something about how much this stuff is worth to the wrong people.

What got me was the interview Motherboard ran with the guy who claims to have done it. He described T-Mobile's security as "awful," said he found an exposed router that let him into their internal network, and just kind of wandered around from there. I dont know how much of that to take at face value, hackers exaggerate, journalists get played sometimes too, but "awful" tracks with my general experience of T-Mobile's app, which regularly forgets my password for no reason and once logged me out mid-payment in a way that felt personal.

I've been a T-Mobile customer for about four years now (switched from Verizon when they still had that unlimited plan that actually meant unlimited), so this week involved the fun ritual of logging in, changing my account PIN, and sitting with that specific low-grade dread of "well, my SSN is probably out there now, forever, cool cool cool." T-Mobile's offering two years of free identity protection through McAfee, which is nice I guess, in the same way a bandaid is nice for a wound that needed stitches. Two years. My social security number does not expire in two years. It does not expire ever. That's kind of the whole problem with using a number issued at birth as a permanent security credential, something I've been annoyed about since long before this particular breach, and will probably still be annoyed about the next time this happens to some other company, because it will happen again.

CEO Mike Sievert put out one of those statements that hits every beat of the genre, "deeply sorry," "unacceptable," "we take security seriously", and look, I believe he's sorry. I just dont think being sorry after the fact is a security strategy. If the guy on the forum is telling the truth about how he got in, this wasnt some nation-state zero-day, it was an exposed router. That's not a sophisticated attack, that's a door left open.

Anyway. If you're on T-Mobile, go change your PIN, it takes about ninety seconds in the app or you can dial 611 and talk to an actual human who has clearly answered this exact question forty times today already. Bless whoever's working phone support this week.

Small unrelated thing I'm keeping an eye on: Google's Pixel 5a is supposed to land later this week, US and Japan only, which is a weirdly narrow rollout for a phone that's otherwise a pretty solid budget option on paper. I've had decent luck with Pixels as daily drivers in the past (the 3a was underrated, fight me), so I'm curious whether the 5a ends up being one of those phones nobody talks about in September and everybody recommends by December. We'll see.

Going to go double check that I actually changed that PIN and didnt just think about changing it, which is a thing I do more often than I'd like to admit.