Major US Carrier Exposes Customer Credit Card Data in Cleartext

Major US Carrier Exposes Customer Credit Card Data in Cleartext

First seen 18 Jun 2026, 20:24 UTC Theregister 88% similarity 64.5

Article Content

Browse articles
ThreatCluster

A database administrator, referred to as Joker, discovered that a leading US cellular carrier stored sensitive customer information, including credit card numbers and Social Security numbers, in an unencrypted format. This incident occurred shortly after Joker was granted sudo-level access to the database on her first day of employment. The database contained a master customer table with extensive personally identifiable information (PII) without any encryption or obfuscation. After Joker reported the issue, the company deleted the exposed data and reverted to a more secure billing system. The incident highlights significant security lapses in data handling practices at the carrier, raising concerns about potential data exfiltration if access had fallen into the wrong hands. The carrier's failure to implement proper data protection measures reflects a broader issue of cybersecurity negligence in the industry.

Key Points: • Sensitive customer data, including credit card numbers, was stored unencrypted. • Access to the database was granted to new employees without proper security controls. • The incident underscores the importance of implementing zero-trust security principles.

ThreatCluster AI How this analysis works

Timeline

Date unknown
Joker hired by US carrier
Joker was hired on the spot and granted sudo access to the database within hours.
Article 1
Date unknown
Sensitive data discovered
Joker found a master customer table containing unencrypted PII, including credit card numbers.
Article 1
Date unknown
Management informed of the issue
Joker reported the security lapse to management, leading to the deletion of the exposed data.
Article 1

Community

Browse all →