• Home
  • Mail
  • News
  • Finance
  • Sports
  • Entertainment
  • Search
  • Mobile
  • More
Yahoo
    • Skip to Navigation
    • Skip to Main Content
    • Skip to Related Content
    • Mail
    Entertainment Home
    Follow Us
    • The It List
    • TV
    • Movies
    • Celebrity
    • Music
    • Live Celeb Chats
    • Videos

    A Sprint contractor left thousands of US cell phone bills on the internet by mistake

    Zack Whittaker
    TechCrunchDecember 4, 2019
    Reblog
    Share
    Tweet
    Share

    A contractor working for cell giant Sprint stored on an unprotected cloud server hundreds of thousands of cell phone bills of AT&T, Verizon and T-Mobile subscribers.

    The storage bucket had more than 261,300 documents, the vast majority of which were phone bills belonging to cell subscribers dating as far back as 2015. But the bucket, hosted on Amazon Web Services (AWS), was not protected with a password, allowing anyone to access the data inside.

    It's not known how long the bucket was exposed.

    The bills — which contained names, addresses and phone numbers, and many included call histories — were collected as part of an offer to allow cell subscribers to switch to Sprint, according to Sprint-branded documents found on the server. The documents explained how the cell giant would pay for the subscriber's early termination fee to break their current cell service contract, a common sales tactic used by cell providers.

    In some cases we found other sensitive documents, such as a bank statement, and a screenshot of a web page that had subscribers' online usernames, passwords and account PINs — which in combination could allow access to a customer's account.

    U.K.-based penetration testing company Fidus Information Security found the exposed data, but it wasn't immediately clear who owned the bucket. Fidus disclosed the security lapse to Amazon, which informed the customer of the exposure — without naming them. The bucket was subsequently shut down.

    View photos

    A Verizon and AT&T phone bill from two customers. (Image: supplied)

    View photos

    A T-Mobile bill found on the exposed servers. A handful of Sprint bills were also found. (Image: supplied)

    After a brief review of the cache, we found one document that said, simply, "TEST." When we ran the file through a metadata checker, it revealed the name of the person who created the document — an account executive at Deardorff Communications, the marketing agency tasked with the Sprint promotion.

    When reached, Jeff Deardorff, president of Deardorff Communications, confirmed his company owned the bucket and that access was restricted earlier on Wednesday.

    "I have launched an internal investigation to determine the root cause of this issue, and we are also reviewing our policies and procedures to make sure something like this doesn’t happen again," he told TechCrunch in an email.

    Given the exposed information involved customers of the big four cell giants, we contacted each company. AT&T did not comment, and T-Mobile did not respond to a request for comment. Verizon spokesperson Richard Young said the company was "currently reviewing" the matter and would have details "as soon as it's available." (TechCrunch is owned by Verizon.)

    Sprint spokesperson Lisa Belot would not disclose the nature of its relationship with Deardorff but said it was "assured that the error has been corrected."

    It's not known why the data was exposed in the first place. It's not uncommon for AWS storage buckets to be misconfigured by being set to "public" and not "private."

    "The uptrend we're seeing in sensitive data being publicly accessible is concerning, despite Amazon releasing tools to help combat this," said Harriet Lester, director of research and development at Fidus. "This scenario was slightly different to usual as it was tricky to identify the owner of the bucket, but thankfully the security team at AWS were able to pass the report on to the owner within hours and public access was shut down soon after."

    We asked Deardorff if his company plans to inform those whose information was exposed by the security lapse. We did not immediately receive a response.

    Updated with Sprint comment. 

    Read more:

    • Tuft & Needle exposed thousands of customer shipping labels
    • StockX was hacked, exposing millions of customers’ data
    • DoorDash confirms data breach affected 4.9 million customers, workers and merchants
    • Equifax breach was ‘entirely preventable’ had it used basic security measures, says House report
    • Stop saying, ‘We take your privacy and security seriously’
    • Capital One breach also hit other major companies, say researchers
    • Macy’s said hackers stole customer credit cards — again
    Reblog
    Share
    Tweet
    Share

    What to Read Next

    • Chelsea Handler Mourns Death of Her TV Sidekick Chuy Bravo 

      Entertainment Tonight
    • Runner Who Slapped Reporter's Backside on Live TV Arrested for Sexual Battery

      People
    • Hallmark Reverses Stance on LGBTQ Zola Ads Under Pressure, Looks to Reinstate Them

      The Wrap
    • Britney Spears' Fans Demand 'Gimme More' After Boyfriend Displays Insane Leg Muscles

      TheBlast
    • Trans teen Jazz Jennings rocks one-piece swimsuit for first time after gender confirmation surgery

      Yahoo Lifestyle
    • J.J. Abrams says there's one thing in The Force Awakens he wishes he'd done differently

      Entertainment Weekly
    • Tom Cruise and Val Kilmer Give a Sneak Peek at Top Gun Sequel: 'Finally Get to Share'

      People
    • Harry Styles fields questions about his sexuality in new interview

      Yahoo Celebrity
    • Mike 'The Situation' Sorrentino Claps Back at Fan Who Tells Him to 'Live Humble' Amid Sobriety

      People
    • Box Office: Clint Eastwood Suffers Worst Opening in Four Decades With ‘Richard Jewell’

      Variety
    • RHOA: Porsha Williams' Fiancé Dennis McKinley Says Her Postpartum Depression Drove Him to Cheat

      People
    • ‘American Idol’ star back in prison after drug warrant

      Yahoo Entertainment
    • Box Office: ‘Jumanji 2’ Levels Up With $60 Million Debut, ‘Richard Jewell’ Stumbles

      Variety
    • Chrissy Teigen hilariously dragged into McDonald’s CEO firing

      Yahoo Entertainment
    • ‘E.T.’ star Henry Thomas arrested for DUI

      Yahoo Entertainment
    • Future's Alleged Baby Mama Accuses Rapper Of Offering 'Hush Money' To Keep Quiet Amid Lori Harvey Romance

      TheBlast

    Dems outline potential framework for Senate impeachment trial, want Bolton, Mulvaney to testify

    LVNiteOwl: The Senate trial should adhere to the same standards of fairness as the House impeachment hearings.

    Join the Conversation
    1 / 5

    4.4k

    • 'RHOC' Alum Meghan King Edmonds Responds To Fan Claiming She's 'Too Thin' After Split With Husband

      TheBlast
    • Kylie Jenner Gets Into the Holiday Spirit with Help from 22-Month-Old Daughter Stormi

      People
    • Kelly Ripa Jokes Daughter Lola, 18, Thinks Everything Her Mom Wears Is 'Embarrassing and Awful'

      People
    • John Travolta looks back on dancing with Princess Diana

      Yahoo Entertainment
    • Runner Who Smacked TV News Reporter’s Butt Arrested, Faces Sexual Battery Charge

      Deadline
    • Gabrielle Union Wants to 'Chat' With Orlando Jones After His Alleged Firing by 'AGT' Production Company

      Entertainment Tonight
    • Daughter of rock royalty is unmasked on 'The Masked Singer'

      Yahoo Entertainment
    • Director Taika Waititi spills on upcoming 'Thor: Love and Thunder' movie

      Yahoo Entertainment
    • James Gunn responds to Martin Scorsese's comments on superhero movies not being 'cinema'

      Yahoo Entertainment
    • Ron Howard was allegedly upset over being upstaged by Henry Winkler on ‘Happy Days’

      Yahoo Entertainment
    • Watch Savannah Guthrie challenge Nikki Haley on Ukraine call assertions

      Yahoo Entertainment
    • Fuller House Star Addresses the Michelle References in Season 5

      TVLine.com
    • Sophia Hutchins Says She and Caitlyn Jenner 'Were Never Romantically Involved'

      People
    • The It List: Old Will Smith battles young Will Smith in 'Gemini Man,' 'El Camino: A Breaking Bad Movie' premieres, 'Riverdale' honors Luke Perry and the best in pop culture the week of October 7, 2019

      Yahoo Entertainment
    • 5 explosive revelations from Demi Moore’s memoir — from miscarriage with Ashton Kutcher to seizure from drug use

      Yahoo Entertainment
    • Meghan McCain praises CNN's S.E. Cupp for defending her against body-shaming troll: 'She is gorgeous, inside and out'

      Yahoo Celebrity