Home Security Sprint security lapse gave access to customer data

Sprint security lapse gave access to customer data

2 min read

Jeenah Moon/Bloomberg via Getty Images

Add Sprint to the list of US carriers whose security shortfalls put customer data at risk. TechCrunch has confirmed that the provider was using two sets of easily-guessed logins that let a security researcher access a company portal with access to customer data, including for Boost Mobile and Virgin Mobile. There were issues within the portal, too. The researcher would only have needed an account holder’s phone number and a four-digit PIN to access their data, change plans or swap devices, and there was no limit on the number of PIN guesses.

In a statement, Sprint confirmed that the expert used “legitimate credentials” to get in. It promptly changed the passwords and vowed to “research this issue” in a bid to avoid a repeat.

This isn’t as grave as the incidents that affected AT&T and T-Mobile, since this required finding and logging into a largely unknown portal. With that said, it points to a seemingly consistent problem with security at American networks. It wouldn’t have taken much to hijack phone numbers and sign into accounts that require two-factor authentication, putting social accounts and other sensitive info within easy reach.

Let’s block ads! (Why?)

Source link

Load More By admin
Load More In Security

Leave a Reply

Your email address will not be published. Required fields are marked *

Check Also

This is the browser to use if you really care about online privacy – CNET

Do you really know who’s watching? Angela Lang/CNET You don’t want to be dripp…