Skip to main content
  1. Home
  2. Phones
  3. Computing
  4. Mobile
  5. Web
  6. News

Bug on T-Mobile website allowed hackers to access account info

Add as a preferred source on Google

Another day, another privacy issue. Until last week, a T-Mobile website allowed hackers to gain access to personal information like email addresses, T-Mobile account numbers, and more, using only the customer’s phone number. The story was first reported by Motherboard, which said that T-Mobile fixed the issue one day after Motherboard asked the company about it.

Discovered by security researcher Karan Saini, the flaw basically allowed hackers who knew or guessed your phone number to gain valuable information that could then be used in a social engineering attack or even to gain access to other personal information elsewhere online. That put 76 million T-Mobile customers in danger of having their data compromised.

Recommended Videos

Even more concerning is the fact that, according to Saini, it would have been pretty easy for an attacker to write a script that automatically retrieved all account details through this bug. As part of the bug, hackers could also access a user’s IMSI number, which is basically a unique identifying number for customers. Using that, hackers could do things like track a user’s location, intercept texts and calls, and more. On top of that, the number could theoretically be used to conduct fraud through taking advantage of the notoriously insecure SS7 network, which is a backbone communications standard.

T-Mobile, for its part, disputes some of the claims made by Saini. Instead of affecting all 76 million customers, T-Mobile says that the bug only affects a small portion of customers. The company also said that it fixed the bug within 24 hours of it being discovered and according to Saini, the company gave him $1,000 for being a part of the T-Mobile bug bounty program, which rewards people who find and report bugs and flaws.

The report comes at a time when it’s looking more and more like Sprint and T-Mobile will announce a merger in the next few weeks. It’s unlikely this report will have an affect on talks about the merger.

There does not seem to be any evidence that any malicious hackers knew about or exploited the bug, but that doesn’t mean it didn’t happen. Either way, we reached out to T-Mobile and will update this story if we hear back.

Christian de Looper
Christian de Looper is a long-time freelance writer who has covered every facet of the consumer tech and electric vehicle…
Instagram could soon let you watch Reels while offline with automatic downloads
A new leak suggests Instagram is working on automatic downloads for Reels, which could let you continue your binge even without an internet connection.
Instagram and YouTube

Instagram could soon let users continue their Reels binge even when they're offline. A new leak suggests the app is working on automatic downloads for short-form videos, a move that would bring it closer to YouTube, which already allows offline viewing of Shorts.

What is Instagram working on?

Read more
Android 17 will let apps get the best out of your phone’s camera chops
A new vendor-defined extension system could bring advanced camera features like Super Resolution to your favorite third-party apps.
Android 17 logo.

Android 17 is shaping up to be quite an important update, especially if you care about camera quality across apps. Google is introducing a new way for phone makers to extend their custom camera features system-wide, which could finally close the gap between stock camera apps and third-party ones.

How is Android changing camera access for apps?

Read more
Google is preparing a priority charging feature for phones for rush scenarios
A hidden Android 17 feature appears built for quick top-ups, while keeping calls and texts flowing.
Electronics, Mobile Phone, Phone

Google is working on a priority charging feature designed for moments when you need power quickly. The option, uncovered in Android 17 beta code by Android Authority, focuses on boosting usable battery in a short window without shutting down core phone functions.

Instead of pushing higher charging speeds, the system shifts power toward the battery by dialing back background activity. Calls and texts still come through, but less critical processes pause so more energy goes into charging.

Read more