Article Details

Original Article Text

Click to Toggle View

Verizon to pay $16 million in TracFone data breach settlement. Verizon Communications has agreed to pay a $16,000,000 settlement with the Federal Communications Commission (FCC) in the U.S. concerning three data breach incidents at its wholly-owned subsidiary, TracFone Wireless, suffered after its acquisition in 2021. TracFone is a telecommunications service provider offering services through Total by Verizon Wireless, Straight Talk, and Walmart Family Mobile, among others. Apart from the hefty civil penalty, the announced settlement agreement requires the communications firm to implement specific measures to increase the level of data security for its customers going forward. Multiple data breaches Data breaches at TracFone occurred between 2021 and 2023, involving three separate incidents. The first, referred to as the 'Cross-Brand' incident, was self-reported by TracFone on January 14, 2022. The company discovered it in December 2021, but the investigation showed that the threat actors had access to customer data since January 2021. With access to sensitive information, including personally identifiable information (PII) and customer proprietary network information (CPNI), the threat actors conducted a high number of unauthorized number porting request approvals. "In connection with this incident, threat actors exploited certain vulnerabilities related to authentication and a limited number of APIs," reads the decree. "By exploiting those vulnerabilities, threat actors were able to gain unauthorized access to certain customer information." The other two data breach incidents concern TracFone's order websites, reported on December 20, 2022, and January 13, 2023, respectively. In both cases, unauthenticated threat actors exploited a vulnerability to access order information, including certain CPNI and other customer data. "The threat actor(s) used two different methods to exploit the vulnerability (switching to a second method when TracFone successfully blocked the first)," explains the FCC's decree document. "TracFone ultimately implemented a long-term fix for the underlying vulnerability by February 2023." The number of exposed individuals and SIM-swapping incidents have been censored in the public version of the Consent Decree document. The settlement agreement mandates that TrackFone will now have to implement the following measures by February 28, 2025: BleepingComputer has contacted Verizon and TracFone to ask how many customers were impacted, but we have not received an answer.

Daily Brief Summary

DATA BREACH // Verizon Settles for $16 Million After TracFone Data Breaches

Verizon Communications agrees to a $16 million settlement with the FCC due to three data breaches at its subsidiary, TracFone Wireless, following its acquisition in 2021.

The breaches occurred over two years, with the initial incident self-reported by TracFone in January 2022, where unauthorized access had begun a year prior.

Attackers exploited authentication vulnerabilities, gaining access to sensitive customer data including personally identifiable information and customer proprietary network information.

Subsequent breaches involved TracFone's order websites, where threat actors accessed order information by exploiting a website vulnerability using two different methods.

Part of the settlement includes a mandate for TracFone to implement enhanced data security measures by February 28, 2025, to prevent future incidents.

Details on the number of affected customers and the specific nature of data accessed remain undisclosed as certain details were censored in the public consent decree.