Data leak
β Supply Chain
Sprint Customer Data Exposure via Samsung 'Add a Line' Website Vulnerability
Primary Source βIncident Details
In June/July 2019, Sprint discovered that hackers had exploited a vulnerability on Samsung’s ‘Add a Line’ promotional webpage β a co-branded retail portal used to add new Sprint lines to existing accounts β to access Sprint customer account information. Sprint reset all affected account PIN codes within three days of discovery and notified state attorneys general. Exposed data included phone numbers, device types, device IDs, customer names, billing addresses, monthly recurring charges, subscriber IDs, account numbers, account creation dates, upgrade eligibility status, and add-on services. This was Sprint’s second known customer data breach in 2019, following the March 2019 Boost Mobile credential stuffing incident. Sprint was acquired by T-Mobile in 2020 for $26 billion.
Technical Details
- Initial Attack Vector
- Third-party website vulnerability β hackers exploited a security flaw in Samsung's 'Add a Line' webpage (a retail portal used to add new Sprint lines), which allowed unauthorized access to Sprint customer account data
- Vendor / Product
- Samsung 'Add a Line' retail portal for Sprint
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2019-06-01 Breach occurred
- 2019-07-16 Publicly disclosed
- 2019-07-16 Customers notified