Data Breaches

T-Mobile confirms Lapsus$ hackers had accessed its systems

0

The acknowledgment came after popular investigator and journalist Brian Krebs shared internal chats belonging to the core members of the group indicating that LAPSUS$ breached the company numerous times in March prior to the arrest of its seven members.

T-Mobile stated that the incident occurred “several weeks ago, with the “bad actor” using stolen credentials to access internal systems. They added that the systems accessed contained no customer or government information or other similarly sensitive information, and that they have no evidence that the intruder was able to obtain anything of value.

The VPN credentials used for initial access are believed to have been obtained from illicit websites like Russian Market with the aim of gaining control of T-Mobile employee accounts, ultimately allowing the threat actor to perform SIM ping attacks at will.

Besides gaining access to an internal customer account management tool called Atlas, the chats show that LAPSUS$ had breached T-Mobile’s Slack and Bitbucket accounts, using the latter to download over 30,000 source code repositories.

Over the last months, the Lapsus$ gang compromised many prominent companies such as NVIDIA, Samsung, Ubisoft, Mercado Libre, Vodafone, Microsoft, Okta, and Globant.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Docker servers targeted in ongoing cryptomining malware campaign

Previous article

Elon Musk to acquire Twitter for $44 billion

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *