Theregister
Major US Carrier Exposes Customer Credit Card Data in Cleartext
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A database administrator, referred to as Joker, discovered that a leading US cellular carrier stored sensitive customer information, including credit card numbers and Social Security numbers, in an unencrypted format. This incident occurred shortly after Joker was granted sudo-level access to the database on her first day of employment. The database contained a master customer table with extensive personally identifiable information (PII) without any encryption or obfuscation. After Joker reported the issue, the company deleted the exposed data and reverted to a more secure billing system. The incident highlights significant security lapses in data handling practices at the carrier, raising concerns about potential data exfiltration if access had fallen into the wrong hands. The carrier's failure to implement proper data protection measures reflects a broader issue of cybersecurity negligence in the industry.
Key Points: • Sensitive customer data, including credit card numbers, was stored unencrypted. • Access to the database was granted to new employees without proper security controls. • The incident underscores the importance of implementing zero-trust security principles.