TechCrunch News 01月07日
Washington sues T-Mobile over 2021 data breach that spilled 79 million customer records
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

华盛顿州因T-Mobile未能保护数百万居民个人数据而提起诉讼,指控其在2021年8月数据泄露事件前未采取足够安全措施。该事件影响了全美超过7900万用户。诉讼称T-Mobile多年来已知网络安全漏洞却未有效解决,要求其赔偿损失并改进安全策略。2021年8月的黑客攻击导致客户姓名、出生日期、社保号码和驾照信息泄露,部分数据甚至在网络犯罪论坛上被公开。华盛顿州总检察长批评T-Mobile未能充分告知受影响客户,低估了事件严重性,影响了消费者评估身份盗窃风险的能力。诉讼还揭露了T-Mobile安全系统中的弱点,如使用弱密码、未限制登录尝试等。

🚨T-Mobile在2021年8月遭受数据泄露,影响全美超过7900万用户,导致客户个人信息泄露。

🔒华盛顿州总检察长指控T-Mobile多年来明知网络安全漏洞却未采取足够措施,认为此次数据泄露本可避免。

⚠️诉讼揭示T-Mobile安全系统存在重大缺陷,包括使用弱密码、未限制登录尝试,以及监控和警报配置不足,使得黑客能够轻易访问其网络。

📢T-Mobile被指控在数据泄露后未能充分告知受影响客户,低估事件严重性,影响了消费者评估风险的能力。

The U.S. state of Washington has sued T-Mobile over allegations the phone giant failed to secure the personal data of millions of state residents prior to an August 2021 data breach, which went on to affect more than 79 million customers across the United States.

In a statement announcing the lawsuit, Washington attorney general Bob Ferguson said T-Mobile “knew for years about certain cybersecurity vulnerabilities and did not do enough to address them.” Ferguson said the suit seeks financial damages under the state’s consumer protection laws and to order T-Mobile to improve its cybersecurity policies. 

The hack against T-Mobile in August 2021 was the latest in a series of data breaches at the company over recent years, with at least five security incidents dating back to 2018 by TechCrunch’s count. The breach allowed a hacker access to T-Mobile’s systems and exfiltrated customer names, dates of birth, and Social Security numbers, as well as driver’s license information. Some of the stolen T-Mobile customer data was subsequently published on a known cybercriminal forum.

Ferguson accused T-Mobile of providing inadequate notice to affected customers following the breach that “omitted critical information and downplayed the severity,” which Ferguson said affected the ability of consumers to assess their risk of identity theft or fraud.

“This significant data breach was entirely avoidable,“ Ferguson was quoted as saying in the press release. “T-Mobile had years to fix key vulnerabilities in its cybersecurity systems — and it failed.”

The lawsuit, filed in a Seattle federal court, contained significant redactions masking specific technical details of the August 2021 hack, but the complaint appears to detail alleged technical security deficiencies and internal company policies that may have made it easier for the hacker to access and download customer data from T-Mobile’s servers.

The unredacted portions note that the hacker targeting T-Mobile discovered an “easily guessable username and password”; that T-Mobile “used weak credentials” on accounts for accessing its internal systems; and that T-Mobile “allowed the connection from the threat actor’s IP address” from outside its network. The complaint also says T-Mobile did not implement rate-limiting on any login attempts, allowing the hacker to freely test as many credentials without locking the employee accounts in question.

The suit also says the company’s “inadequate monitoring and alerting configuration” made it easier for the hacker to access T-Mobile’s network without being noticed.

Ferguson’s complaint adds that T-Mobile’s public statements misrepresented the adequacy of its cybersecurity defenses and the threat to T-Mobile’s customers’ data found on the dark web, and said the company’s conduct “had the capacity to deceive a substantial number of Washington consumers.”

A spokesperson for T-Mobile, when reached Monday, did not immediately comment on the lawsuit.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

数据泄露 T-Mobile 网络安全 华盛顿州 消费者保护
相关文章