T-Mobile UK Employees Sold Customers' Information
angry tapir writes "Workers at T-Mobile UK have been selling customer data to brokers who worked for the competition, according to T-Mobile and the UK's Information Commissioner's Office. Criminal charges are being prepared. 'Many thousands' of customers' account details, millions of records, were sold to several brokers for substantial amounts of money, the ICO said. In an announcement (PDF) from the ICO, the agency does not name the operator involved, but T-Mobile acknowledged that it had alerted ICO about the data breach. The BBC reports that after the other mobile operators said they were not the subject of the investigation, T-Mobile confirmed its involvement."
I'm a T-Mobile Customer. I think they did the right thing, coming forward when it was obvious they had a data breach.
I like T-Mobile, especially because they have great customer support. I have a friend who got overbilled by a lot, and decided to settle instead of going to court over it. My experience with the company though has been pretty good. I'm staying with them.
I'm an operator for T-Mobile and I'll only confirm my involvement after all the operators say they are not the subject of the investigation.
Banana who?
Knock Knock - Who is it? Banana
Banana who?
Knock Knock - Who is it? Orange
Orange who?
Exactly !!
At what point do the competitors have to take responsibility for purchasing the data? It seems that they should have known the data wasn't kosher.
The likelihood of valuable data being exploited is proportional to it's marketability. The more important the data, the more likely it will be stolen or otherwise exploited. It doesn't matter if it's a company, a utility or a government.
Oliver's law of assumed responsibility: If you're seen fixing it, you will be blamed for breaking it.
I've cancelled direct debits and my contract. Vote with my feet - if they want to be fool enough to sue me for the loss of the contract then they can expect to get countersued for the cost of credit monitoring. Until people start slapping the companies hard by refusing to do business with them this will carry on the UK data protection *laws* are good, but the *penalties* are worthless as a deterrent. It seems they siphoning off millions records. They dont leave the building scribbled down on bits of paper - there is a whole question of access here and how so many people could take this much data for long undetected.
It's fine! Almost all of the copied records belonged to customers who "don't believe in imaginary property".
This makes me wonder what an individual who would really like their info to remain private can do to keep it so.
Celebrities, politicians, all their info is potentially for sale, and all it takes is one greedy employee with some debt...
I wish this problem was exclusive to T Mobile, I really do. The sad thing is that I've been on two different networks and somehow firms seem to get hold of my mobile number and start calling me offering me an upgrade. The most accurate firm was one who had my full Orange account details, so why wouldn't you trust a firm who knows where you live? When I reported this to Orange they acted surprised but did absolutely nothing about it, probably because data is flowing far too freely around their organisation. My current provider isn't immune either, around 12 months on my previous contract with O2 I had multiple companies each trying to sell me a new contract. They claim it's just on an autodialer of numbers to call and have no personal information about me. However the fact that someone knows I'm on O2 means enough personal data is leaking.
The entire UK (Is it any different elsewhere?) Mobile Phone industry works on ethical standard that would shame organised crime, among the many abuses I've come across :
* Deceptive tariffs, resulting in unexpectedly large bills, especially the roaming data ( I used to handle the phone admin for a medium sized company, we had a user come back from overseas trips with bills up over a thousand pounds when the free roaming data the salesman told us we'd bought turned out to have a fair use limit of 10MB...)
* The reverse billing text message scam - some of the companies operating this make tens of millions, and have been fined hundreds of thousands for repeated abuses - they are still in business.
* your bank details get passed on and you are billed for insurance you never asked for
* BUYING the stolen data
Think of these guys as a bit like Chris in the Sopranos, They got impatient and wanted a piece of the action for themselves. They may get a slap on the wrist, but the business is full of worse criminals.
I was a T-Mobile customer for something like 7 years (started of as One2One customer) and that was over 5 years ago, but that doesn't stop some complete dipstick from some dipstick company calling me every year around September asking me if I would like to upgrade my T-Mobile contract!
Yeap, it's not T-Mobile calling me, but whoever it was they sold all my details to (including tarrif and expiry details) back then is STILL using/forwarding/selling it on and on! Every year the company name is different, but they always think I'm with T-Mobile, and they always hang up quickly after I've asked them for their company details so I can report them to Ofcom for breaching TPS!
I also called T-Mobile on numerous occasions complaining that they have obviously sold on my information, and of course they always deny it. F'tards.
Their ads suck, the price plans are overpriced, they are not worth being a customer of!
Clever move by T-mobile i.e. say that they are at fault before the public finds that out through the government or other sources and everyone would think they (T-mobile) didn't really meant to "lose" the data. It seems tom that it's about the right time to go on Pay as You Go! The government plans to introduce new counter measures to prevent illegal manipulation of OUR data an so should we, the general public.
Detect abuse (rising to the level of unauthorized access) of access privileges to access a handful of records? Very hard.
Detect abuse of access privileges that constitute unauthorized access to "millions of records"? Very easy. It's all about automatically flagging abnormal or unusual patterns of accesses so that they can be audited to determine if they were authorized (highly unlikely at that volume difference) or unauthorized.
But first the data/system owner has to care about unauthorized access. The DoD and other owners of classified data care. Heck, credit card companies (in the form of their fraud departments) care. Demonstrably T-Mobile UK did not care about unauthorized access.
I provide a slightly different version of my personal data each and every time I need to give them out. Thus if they are leaked/sold/whatever I know who did it, and possibly whom to blame/drop/sue. [Actually, I'm a T-Mobile customer and I haven't had problems. Then again, I don't live in the UK :) ]
"Workers at T-Mobile UK have been selling customer data to brokers who worked for the competition [...] The BBC reports that after the other mobile operators said they were not the subject of the investigation, T-Mobile confirmed its involvement."
So.. who actually bought the stolen records if T-mobile employees sold them to other operators but no other operators were involved?
Slashdot social media options: AIM, ICQ, Yahoo, Jabber and Mobile Text. Why no MySpace?
T-Mobile - "Life is for Sharing"
How is it possible for anybody to have access to all that information?
Only processes should be able to access records of people in volume, no manual query should be able to gather that information.
IANAL but write like a drunk one.
Sorry, but I fail to see why anybody should have access to a substantial amount of records at the same time.
This smacks to me as lack of security.
IANAL but write like a drunk one.
I have my 'phone with 02 and I've been getting these cold calls as well.
Bad analogies are like waxing a monkey with a rainbow.
Oh goody, my contract is up and it's another reason to want to move elsewhere.
I'm optimistic of being on a really good deal soon. With T-Mobile.
(I'm not even vaguely surprised at this kind of thing any more from any company, their being caught merely represents an opportunity for me to make use of it).
yes there are limitations, tarrifs (system access fees) and many other little details they don't explain at the outset (just like when you buy a candy bar and get hit by the 13% harmonized sales tax at the register) we canadians think we have it so good...