National Cell Phone Provider Hacked, 6 Million Users Data Leaked Online
If you are a Verizon Wireless customer be aware of this developing situation. According to the company, up to 6 million users may be in jeopardy after cybersecurity firm UpGuard confirmed the data leak. It was caused by a misconfigured security setting on a cloud server due to an apparent “human error.”
According to Fox2Now:
The error made customer phone numbers, names, and some PIN codes publicly available online. PIN codes are used to confirm the identity of people who call for customer service.
No loss or theft of customer information occurred, Verizon told CNN Tech.
UpGuard — the same company that discovered leaked voter data in June — initially said the error could impact up to 14 million accounts.
Chris Vickery, a researcher at UpGuard, discovered the Verizon data was exposed by NICE Systems, an Israel-based company Verizon was working with to facilitate customer service calls. The data was collected over the last six months.
Vickery alerted Verizon to the leak on June 13. The security hole was closed on June 22.
The incident stemmed from NICE security measures that were not set up properly. The company made a security setting public, instead of private, on an Amazon S3 storage server — a common technology used by businesses to keep data in the cloud. This means Verizon data stored in the cloud was temporarily visible to anyone who had the public link.
ZDNet first reported the breach.
The security firm analyzed a sample of the data and found some PIN codes were hidden but others were visible next to phone numbers.
UpGuard declined to disclose how the leaked data was discovered.
Dan O’Sullivan, a Cyber Resilience Analyst with UpGuard, said exposed PIN codes is a concern because it allows scammers to access someone’s phone service if they convince a customer service agent they’re the account holder.
“A scammer could receive a two-factor authentication message and potentially change it or alter [the authentication] to his liking,” O’Sullivan said. “Or they could cut off access to the real account holder.”
Verizon customers should update their PIN codes and not use the same one twice, O’Sullivan advises.
The is the latest leak to surface from a misconfigured Amazon S3 storage unit. In June, an analytics firm exposed the data of almost 200 million voters, and earlier this month, an insecure server leaked 3 million WWE fans’ data last week.
Why does this keep happening? Amazon secures these servers by default. This means the errors that occur are due to changes someone makes with a security setting — typically by accident, O’Sullivan said.
O’Sullivan says the Verizon case highlights how many third-parties have access to our personal data.
“Cyber risk is a fact of life for any digital service,” O’Sullivan said. “As data becomes more powerful and more accessible, the potential consequences for it to be misused also becomes more dangerous.”
Hopefully, no major damage comes from this situation but if you are a Verizon Wireless customer you may want to do a little more investigating to find out whether or not you are one of the unlucky ones. Technology is a double-edged sword and can benefit us but sometimes it can make things worse. Share this story around so everyone can be aware of this situation.