Passwords Part of Data Breach, T-Mobile Admits: What to Do Now

UPDATED 4:00 p.m. EDT Friday with bad news that T-Mobile user passwords may indeed have been compromised. You should change your T-Mobile password as quickly as possible.

T-Mobile announced that on Thursday, it discovered and shut down a brief security breach.

Credit: Jonathan Weiss / Shutterstock.com

(Image credit: Jonathan Weiss / Shutterstock.com)

While it caught the breach quickly, T-Mobile told Motherboard that hackers were able to grab the data of almost three million people. Personal data including customers' name, billing zip code, phone number, email address, account number and account type were compromised.

Still, it could be worse: T-Mobile claims that none of your financial data, Social Security numbers, or passwords were compromised. T-Mobile is not aware of the identities of the hackers involved, and whether they are government- or criminal-affiliated. The company told Motherboard that the attackers were part of "an international group." 

"We truly regret that this incident occurred and are so sorry for any inconvenience this has caused you," the announcement reads. 

In the announcement late Thursday night, the company claimed it would "shortly" be sending texts to customers who were affected. 

This isn't the first time T-Mobile customers have had to worry about fraud. In February, the company texted warnings to its post-paid customer base about a sudden uptick in port-out frauds (a scam where a criminal impersonates you to port your number to another wireless carrier). This led to multiple customers' bank accounts being compromised and, in some cases, drained.

Anyone whose account was affected by this breach is at greater risk of becoming the victim of a port-out scam.

What to Do Now

If you're among the customers whose personal data were compromised in this breach, even though the carrier claims no passwords were impacted, it's still a good idea to change yours. Once a hacker has your account number, phone number, and email address, it's easier for them to obtain your login information.

And while it's probably not necessary since payment information and social-security numbers weren't taken here, you can also sign up for an identity-monitoring service if you're very worried.

UPDATE: Late Friday, Motherboard report Lorenzo Franceschi-Bicchierai, who broke the original story, tweeted that he had learned that encrypted passwords were indeed compromised in the T-Mobile data breach.

"We obtained a sample of one 'encrypted password' and turns out it may be a Base64 string that decodes to a MD5 hash," Franceschi-Bicchierai posted on Twitter. "In other words, it could potentially be cracked."

Base64 is an easily reversible encryption algorithm, and anyone can decipher a Base64 string using online tools. MD5 is a one-way-hash algorithm that was designed in 1992 to be irreversible, but has since been found to be severely compromised.

If your T-Mobile password was based on a dictionary word and it was part of the data breach -- and you don't know yet if it wasn't -- then you can consider it cracked.

When Franceschi-Bicchierai asked his T-Mobile contact why the company had originally said no passwords were compromised, the spokesperson replied that "they weren't ... they were encrypted."

TOPICS

Monica Chin is a writer at The Verge, covering computers. Previously, she was a staff writer for Tom's Guide, where she wrote about everything from artificial intelligence to social media and the internet of things to. She had a particular focus on smart home, reviewing multiple devices. In her downtime, you can usually find her at poetry slams, attempting to exercise, or yelling at people on Twitter.

Latest in Online Security
Graphic screen displaying malware detection warning
This dangerous new Windows malware hides from your antivirus while impersonating a popular PC brand
23andME box
23andMe has declared bankruptcy — here's how to delete your data now
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
A man filing his taxes electronically on a laptop
AI-powered tax scams are here - how to stay safe from deepfakes, phishing and more this tax season
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
Hacker using a stolen social security card
Your Social Security number is a literal gold mine for scammers and identity thieves — here’s how to keep it safe
Latest in News
Nintendo Switch 2 console, Joy-Con controllers and dock
The Switch 2's mysterious "C" button may have just been confirmed by Nintendo
Nintendo Switch virtual game card
Nintendo just announced 'Virtual Game Cards' ahead of Switch 2 launch
Gerard Butler as Detective Nick "Big Nick" O'Brien in "Den of Thieves 2: Pantera"
Netflix top 10 movies — here’s the 3 worth watching right now
Graphic screen displaying malware detection warning
This dangerous new Windows malware hides from your antivirus while impersonating a popular PC brand
Adam Scott, Zach Cherry, John Turturro and Britt Lower in Severance
Ben Stiller says 'Severance' season 3 coming 'as fast as possible'
Kevin Costner in Field of Dreams
Why I watch ‘Field of Dreams’ on baseball’s opening day every year