Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

Sprint Reveals Account Breach via Samsung Website

The last-June breach exposed data including names, phone numbers, and account numbers.

Sprint has been informing customers of a data breach discovered on June 22 that came by way of their account credentials via Samsung's "add a line" website. The number of customers impacted has not been disclosed.

Information exposed in the breach includes phone number, device type, device ID, monthly recurring charges, subscriber ID, account number, account creation date, upgrade eligibility, first and last name, billing address, and add-on services, according to Sprint's notification. The notification also stresses information that might be used in financial fraud was not affected.

"Suggesting this breach does not put users at risk of fraud or identity theft strikes me as either ignorant or disingenuous," counters Sam Bakken, senior product marketing manager at OneSpan. "Combining phone number, device type, and device ID, an attacker has the building blocks for an account-takeover scheme."

And that could have significant financial ramifications, says Tim Mackey, principal security strategist at Synopsys CyRC. "If a malicious actor has access to the appropriate provider information, they can co-opt the user's account either through the porting process or by simply obtaining a replacement SIM. These attacks are respectively known as 'port-out scams' and SIM-jacking," he explains.

Once those steps are taken, he says, many two-factor authentication schemes become weapons rather than protections. "Once ported, the replacement device will receive all cellular messages, such as SMS," Mackey says. "This can facilitate attacks where SMS is used as part of a two-factor identification strategy."

The most important information about this breach, according to Bob Maley, chief security officer at NormShield, is it's not the first Sprint has seen this year. "Earlier this year one of their subsidiaries, Boost Mobile, had a problem with a contractor," Maley says. According to the notification Sprint sent customers for that breach, which occurred March 14, "Boost.com experienced unauthorized online account activity in which an unauthorized person accessed your account through your Boost phone number and Boost.com PIN code."

"It sounds like [Sprint's] process for risk assessment for third parties might be lacking," Maley says. "As a CISO I'd want to know very early on when we engage a third party the sort of risk that engagement would bring to us. Are we sharing data with them? Will they have access to our systems or network? Is the service the third party providing critical to our operation?"  

Samsung would have said "yes" all three of those questions, Maley says, and so should fall under an enhanced schedule of monitoring and assessment for risk and security.

Many companies conduct risk assessment when a new third-party partner is onboarded but then fail to do regular reassessment of the risks, Maley says. "The 'trust but verify' model is good, but most people are just using the 'trust' part," he says.

This breach is a reminder that risks should be assessed and security practices audited on a regular basis, Maley adds. In a dynamic world, he points out, security is not a one-time affair.

Related Content:

 

Black Hat USA returns to Las Vegas with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions, and service providers in the Business Hall. Click for information on the conference and to register.

Curtis Franklin Jr. is Senior Editor at Dark Reading. In this role he focuses on product and technology coverage for the publication. In addition he works on audio and video programming for Dark Reading and contributes to activities at Interop ITX, Black Hat, INsecurity, and ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
tdsan
50%
50%
tdsan,
User Rank: Ninja
7/21/2019 | 6:35:46 PM
Continuous monitoring could help

Information exposed in the breach includes phone number, device type, device ID, monthly recurring charges, subscriber ID, account number, account creation date, upgrade eligibility, first and last name, billing address, and add-on services

This sounds like they pulled this information from a database, the "device ID or account no" sounds like the primary key. 

Schema (P = Primary, F = ForeignKey,


AcctNo (P) | FirstName | LastName | BillingAddr | PhoneNo


DeviceID (FK) | DeviceType


AddOnSvcs | UpgradeElig | CreationDate | MoRecurringChg


So they probably extracted a DB or a number of tables from different DBs, if the DB was configured with a single service account, it would have been easy to obtain this information but the question implies the B2B relationship is way more open than public exposure. The gentleman made a statement about Risk Assessment/Mgmt, there are a number of areas that could be identified to help.

  • Setup NAC (Network Access Control), only allow specific companies
  • Implement SELinux rules to allow access to certain parts of the accounting and data server
  • Implement security token that uses cryptographic keys to access certain features of the application
  • Install Attunity to replicate a stripped down DB with specific information that they need (create an external table that is considered a "Read-Only Replica" of a table or number of tables.
  • Segment the network to allow VPN access to their Zone extranet environment (IPv6 IPSec ESP/AH VPN access)

Todd
When It Comes To Security Tools, More Isn't More
Lamont Orange, Chief Information Security Officer at Netskope,  1/11/2021
US Capitol Attack a Wake-up Call for the Integration of Physical & IT Security
Seth Rosenblatt, Contributing Writer,  1/11/2021
IoT Vendor Ubiquiti Suffers Data Breach
Dark Reading Staff 1/11/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2020: The Year in Security
Download this Tech Digest for a look at the biggest security stories that - so far - have shaped a very strange and stressful year.
Flash Poll
Assessing Cybersecurity Risk in Today's Enterprises
Assessing Cybersecurity Risk in Today's Enterprises
COVID-19 has created a new IT paradigm in the enterprise -- and a new level of cybersecurity risk. This report offers a look at how enterprises are assessing and managing cyber-risk under the new normal.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-3166
PUBLISHED: 2021-01-18
An issue was discovered on ASUS DSL-N14U-B1 1.1.2.3_805 devices. An attacker can upload arbitrary file content as a firmware update when the filename Settings_DSL-N14U-B1.trx is used. Once this file is loaded, shutdown measures on a wide range of services are triggered as if it were a real update, r...
CVE-2020-29446
PUBLISHED: 2021-01-18
Affected versions of Atlassian Fisheye & Crucible allow remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulnerability in the WEB-INF directory. The affected versions are before version 4.8.5.
CVE-2020-15864
PUBLISHED: 2021-01-17
An issue was discovered in Quali CloudShell 9.3. An XSS vulnerability in the login page allows an attacker to craft a URL, with a constructor.constructor substring in the username field, that executes a payload when the user visits the /Account/Login page.
CVE-2021-3113
PUBLISHED: 2021-01-17
Netsia SEBA+ through 0.16.1 build 70-e669dcd7 allows remote attackers to discover session cookies via a direct /session/list/allActiveSession request. For example, the attacker can discover the admin's cookie if the admin account happens to be logged in when the allActiveSession request occurs, and ...
CVE-2020-25533
PUBLISHED: 2021-01-15
An issue was discovered in Malwarebytes before 4.0 on macOS. A malicious application was able to perform a privileged action within the Malwarebytes launch daemon. The privileged service improperly validated XPC connections by relying on the PID instead of the audit token. An attacker can construct ...