Leaked Chats Show Lapsus$ Stole T-Mobile Source Code
krebsonsecurity.com
krebsonsecurity.com
These guys have got to just be clowns, media fodder, right? State actors aren't using Discord and storing their loot on AWS.
> 29 Nov 2017
> The NSA has been hit by yet another data leak, as over 100GB of sensitive, classified data was exposed through shoddy security practises.
> The leak came from a virtual copy of a hard drive belonging to US Intelligence and Security Command (INSCOM), an intelligence organisation operating within both the US Army and the NSA.
> The virtual disk image was discovered by UpGuard cyber risk research director Chris Vickery on an unprotected public Amazon S3 server, meaning that anyone who knew the web address where the data was stored could freely access it.
https://www.itpro.com/security/30060/100gb-of-secret-nsa-dat...
https://www.datacenterdynamics.com/en/news/cia-awards-multib...
I think it's interesting that they're buying their way in. Do those accounts not sell for very much?
Also, now that I know they just buy stolen credentials, and don't even have the talent to actually hack their way into the systems, I'm underwhelmed by their achievements.
It seems to be a common sentiment on hacker news, that they're script kiddies and what they did "doesn't count" as real hacking. But doesn't that just makes things worse? It means anybody can break into anything, given basic social and computing skills. There is clearly a very big complacency problem in our industry and maybe we should do something about it.
they have collected about $14 million dollars in crypto from various cyber-crime activities and ventures
they were offering up to $20k for intel/credentials publicly on their Telegram
2020 - More than 50 million people now affected[1]
2021 - T-Mobile Hacked for 5th Time in 4 Years in Latest Breach[2]
2021 - T-Mobile suffers another, smaller data breach[3]
2022 - This story
While clearly T-Mobile does not care enough about information security to do something significant, its also pretty clear that stock market, customers and regulators also do not care about such gross negligence.
[1]https://www.cnet.com/news/privacy/t-mobile-data-breach-more-...
[2]https://www.newsweek.com/t-mobile-hacked-5th-time-4-years-la...
[3]https://www.cnet.com/tech/mobile/t-mobile-reportedly-suffers...
TMUS is not remotely special other than, it's apparently a little easier than T or VZ, but again it's not like we should consider those "safe" by any means.
> its also pretty clear that stock market, customers and regulators also do not care about such gross negligence.
Because everyone else is equally negligent. The NSA cares at least a token amount, but clearly they can't even keep their stuff safe, let alone the rest of us.
Banks are "safe" not because they have good IT security, but because they have centuries of log auditing practice and can mostly undo transactions whenever they want.
As a T-Mobile customer, this does not inspire confidence...
> Hollywood’s hacker war began on February 19, 2004 with a simple phone call. It happened at a T-Mobile store near Los Angeles. The caller told the salesperson he was from the T-Mobile headquarters in Washington. “We heard you’ve been having problems with your customer account tools?” The caller said. “No, we haven’t had any problems really,” the clerk replied, “just a couple slowdowns. That’s about it.”
> “Yes, that’s what is described here in the report,” the caller replied. “We’re going to have to look into this for a quick second.”
> “All right, what do you need?” Then he dutifully gave the caller the company’s internal web site for managing customer accounts —
Still works there in the same capacity: https://www.mesaonline.org/conferences/with-leadership-award...
is twilio viable for personal cell use?
So no, it's not viable at all.
Webmail providers don't even have service, which can be a curse as much as it is a blessing
Anyone can commit megafraud against you by filing a USPS change of address form on your behalf to intercept all your paper correspondence, not to mention the rampant straight up package theft the past few years.
We need a more comprehensive plan than just 'dont use phones'. As long as correspondence has value, someone is going to try and steal it.
[0]: I am assuming that each VPN has a unique identifier.
And if a nurse, doctor or similar access a journal they most likely have no reason to, it can get flagged for investigation.
Also it’s always amusing to hear about hackers who partake in the incident response meetings for their own hacks. Not the first time I’ve read that.
Krebs makes a very good point in the last paragraph. Way way way cheaper than paying ransoms.
The problem is not only with the fact that secrets need to be rotated, but the operational impact it can cause if not rotated in all places. Add the time aspect to it and you have a goodie bag.
I did some things when I was their age that would get me time breaking rocks today. It seems like nothing in the hacking culture has changed. The only different things are that we were moving in slow motion because of the speed of our connections.
We even used to store our loot in "the cloud," too. Usually the mainframe accounts of college philosophy and literature professors who never logged in and so never used their disk quotas.
luckily, you can just skip the part and buy VPN credentials and session cookies on the dark markets
it's so easy, it's almost cheating
ABAC + Zero Trust.