Google’s cell network provider Google Fi has confirmed a data breach, likely related to the recent security incident at T-Mobile, which allowed hackers to steal millions of customers’ information.
In an email sent to customers on Monday, obtained by TechCrunch, Google said that the primary network provider for Google Fi recently informed the company that there had been suspicious activity relating to a third-party support system containing a “limited amount” of Google Fi customer data.
The timing of the notice — and the fact that Google Fi uses a combination of T-Mobile and U.S. Cellular for network connectivity — suggests the breach is linked to the most recent T-Mobile hack. This breach, disclosed on January 19, allowed intruders access to a trove of personal data belonging to 37 million customers, including billing addresses, dates of birth and T-Mobile account details. The incident marked the eighth time T-Mobile has been hacked since 2018.
In the case of Google Fi’s breach, Google says the hackers accessed limited customer information, including phone numbers, account status, SIM card serial numbers and information related to details about customers’ mobile service plans, such as whether they have selected unlimited SMS or international roaming.
Google said that the hackers did not take customers’ personal information or payment card data, passwords, PINs or the contents of text messages or calls.
While some emails told customers that there is “no action required,” at least one Google Fi customer claimed in a Reddit post that their disclosure said that their phone number had been briefly hijacked, known as SIM swapping. Google reportedly told the customer that the intruders had transferred their number for close to two hours, during which they “could have involved the use of your phone number to send and receive phone calls and text messages.” This technique is used by hackers to gain access to a victim’s other online accounts that are protected by the same, albeit hijacked phone number.
TechCrunch asked Google whether it could confirm that the incident was linked to the recent T-Mobile breach but has yet to receive a response. It’s not immediately clear how many Google Fi subscribers have been affected by the breach. Google hasn’t made public how many cell subscribers it has in total.
In its email to customers, the company said it is working with the as-yet-unnamed network provider to “identify and implement measures to secure the data on that third-party system and notify everyone potentially impacted.” It added that there was no access to Google’s systems or any systems overseen by Google.
Updated to remove a sentence related to customer voicemails.
https://techcrunch.com/
ate on Friday, Twitter announced a new policy that will remove text message two-factor authentication (2FA) from any account that won’t pay for it. In a blog post, Twitter said that it will only allow accounts that subscribe to its premium Twitter Blue feature to use text message-based 2FA. Twitter users that don’t switch to a different […]
THE THREAT OF Facebook account takeovers always looms, whether they’re caused by attacks that steal users’ login credentials or hacks that, say, compromise users’ email accounts and exploit the access to launch rogue account recoveries. At the same time, though, Facebook users need to be able to regain access to their accounts if they forget […]
The website for ODIN Intelligence, a company that provides technology and tools for law enforcement and police departments, was defaced on Sunday. The apparent hack comes days after Wired reported that an app developed by the company, SweepWizard, which allows police to manage and coordinate multi-agency raids, had a significant security vulnerability that exposed personal information of […]
Leave a Reply