Data leak β›“ Supply Chain

Sprint Customer Data Exposure via Samsung 'Add a Line' Website Vulnerability

πŸ“… 2019-06-01 🏒 Samsung 'Add a Line' retail portal for Sprint
Primary Source β†—

Incident Details

In June/July 2019, Sprint discovered that hackers had exploited a vulnerability on Samsung’s ‘Add a Line’ promotional webpage β€” a co-branded retail portal used to add new Sprint lines to existing accounts β€” to access Sprint customer account information. Sprint reset all affected account PIN codes within three days of discovery and notified state attorneys general. Exposed data included phone numbers, device types, device IDs, customer names, billing addresses, monthly recurring charges, subscriber IDs, account numbers, account creation dates, upgrade eligibility status, and add-on services. This was Sprint’s second known customer data breach in 2019, following the March 2019 Boost Mobile credential stuffing incident. Sprint was acquired by T-Mobile in 2020 for $26 billion.

Technical Details

Initial Attack Vector
Third-party website vulnerability β€” hackers exploited a security flaw in Samsung's 'Add a Line' webpage (a retail portal used to add new Sprint lines), which allowed unauthorized access to Sprint customer account data
Vendor / Product
Samsung 'Add a Line' retail portal for Sprint
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2019-06-01 Breach occurred
  2. 2019-07-16 Publicly disclosed
  3. 2019-07-16 Customers notified