Unprotected Cloud Server Exposes Hundreds of Thousands of Cell Phone Bills

A Sprint marketing contractor leaves over 261,000 cell phone bills from AT&T, Verizon, and T-Mobile customers on an unsecured AWS server. The exposed data includes highly sensitive information like names, addresses, and even account passwords.

A marketing contractor for Sprint exposes hundreds of thousands of cell phone bills on an unprotected Amazon Web Services cloud server. The storage bucket contains over 261,300 documents dating back to 2015, and it lacks password protection, allowing anyone to access the sensitive files. Security researchers at Fidus Information Security discover the exposed data and report the lapse to Amazon.

The unsecured bills belong to subscribers of AT&T, Verizon, and T-Mobile, and include names, addresses, phone numbers, and call histories. Sprint collects these documents as part of a promotion that pays early termination fees to convince customers to switch carriers. The exposed server also holds even more sensitive items, such as bank statements and screenshots containing online usernames, passwords, and account PINs.

Metadata in a test document reveals that Deardorff Communications, the marketing agency managing the Sprint promotion, owns the exposed server. The company's president confirms the security incident and restricts access to the data, launching an internal investigation to determine the root cause. Verizon states that it is reviewing the matter, while AT&T declines to comment and T-Mobile does not respond to inquiries.

Read More at the original source →