Attacks/Breaches
11/17/2009
06:04 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%
Repost This

T-Mobile Says Employees Sold Customer Data

A report issued by the U.K. Information Commission's Office calls for action against the unlawful sale of personal data.

T-Mobile employees are alleged to have stolen the personal information of thousands of customers and to have sold the data to rivals.

The Information Commissioner's Office (ICO) in the U.K. on Tuesday said that it had been approached by an unnamed mobile telephone service provider with information about employees believed to be selling customer data.

The data included mobile phone contract information and expiration dates.

In a statement on its Web site, T-Mobile said that it alerted the ICO when it learned that contract renewal information was being passed to third parties without its knowledge.

The mobile provider told the ICO that the information was being sold to competing service providers for lead generation: Competitors allegedly used the information to solicit T-Mobile customers whose contracts were about to expire.

"The customer information that was compromised contained no personal financial or security-related information whatsoever," the company said.

The ICO said that "substantial amounts of money have changed hands" and that a prosecution case is being prepared.

T-Mobile said it was "surprised" that its name had been publicly reported because it had been previously asked to keep all information about the incident confidential to avoid hindering the investigation and judicial proceedings.

"Whilst it is deeply regrettable that customer information has been misapproriated in this way, we have proactively supported the ICO to help stamp out what is a problem for the whole industry," said T-Mobile in its statement.

Information Commissioner Christopher Graham said that as more and more data is collected and as data collection systems become increasingly intertwined, the risk that such data may be abused will only increase.

"Many people will have wondered why and how they are being contacted by someone they do not know just before their existing phone contract is about to expire," said Graham in a statement. "We are considering the evidence with a view to prosecuting those responsible and I am keen to go much further and close down the entire unlawful industry in personal data."

InformationWeek has published an in-depth report on smartphone security. Download the report here (registration required).

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-3946
Published: 2014-04-24
Cisco IOS before 15.3(2)S allows remote attackers to bypass interface ACL restrictions in opportunistic circumstances by sending IPv6 packets in an unspecified scenario in which expected packet drops do not occur for "a small percentage" of the packets, aka Bug ID CSCty73682.

CVE-2012-5723
Published: 2014-04-24
Cisco ASR 1000 devices with software before 3.8S, when BDI routing is enabled, allow remote attackers to cause a denial of service (device reload) via crafted (1) broadcast or (2) multicast ICMP packets with fragmentation, aka Bug ID CSCub55948.

CVE-2013-6738
Published: 2014-04-24
Cross-site scripting (XSS) vulnerability in IBM SmartCloud Analytics Log Analysis 1.1 and 1.2 before 1.2.0.0-CSI-SCALA-IF0003 allows remote attackers to inject arbitrary web script or HTML via an invalid query parameter in a response from an OAuth authorization endpoint.

CVE-2014-0188
Published: 2014-04-24
The openshift-origin-broker in Red Hat OpenShift Enterprise 2.0.5, 1.2.7, and earlier does not properly handle authentication requests from the remote-user auth plugin, which allows remote attackers to bypass authentication and impersonate arbitrary users via the X-Remote-User header in a request to...

CVE-2014-2391
Published: 2014-04-24
The password recovery service in Open-Xchange AppSuite before 7.2.2-rev20, 7.4.1 before 7.4.1-rev11, and 7.4.2 before 7.4.2-rev13 makes an improper decision about the sensitivity of a string representing a previously used but currently invalid password, which allows remote attackers to obtain potent...

Best of the Web