Feeds

T-Mobile coughs to data theft

But can't understand all the fuss

Website security in corporate America

T-Mobile has admitted it was the operator whose staff sold customer data to competitors, but can't understand why the Information Commissioner decided to share the information.

Staff at the network operator had developed a sideline selling customer records to brokers who then called up the customers to offer alternative contracts.

T-Mobile had been told not to mention the case to anyone as there were prosecutions pending, so the operator was pretty surprised when the Information Commissioner decided to spill the beans yesterday to help his political case for harsher sentences for data breaches.

The Information Commissioner's Office (ICO) is trying to whip up support for custodial sentences for those convicted of stealing data, but public sympathy for celebrities who had their phone records stolen is minimal. The T-Mobile case, on the other hand, demonstrates why normal people should care too, which is why the details came out in the Commissioner's response to the Government consultation about the introduction of prison sentences.

T-Mobile seemingly couldn't have handled the case better. The operator received complaints that customers were getting curiously well-informed cold calls, so T-Mobile investigated - as operators are surprisingly willing to do. It took its evidence to the ICO, who investigated further and told the operator to say nothing to anybody until the case was complete.

But that restriction didn't apply to the ICO, who published the details to support its argument. The ICO didn't name the operator, but it didn't take long to get denials out of all the other operators, forcing T-Mobile to admit it was them, despite promising the ICO they wouldn't say anything.

As for the data stolen, it mainly consisted of customer details and contract end dates - annoying to have public but not exactly state secrets. Customer details are in the phone book, and most people will tell you their contract renewal date if you call them up and ask (as cold callers are wont to do).

Whether one approves of custodial sentences for nicking data, or not, it's clear that the ICO has manipulated this case into a cause celebre with impact far beyond its real importance. ®

Internet Security Threat Report 2014

More from The Register

next story
Brit telcos warn Scots that voting Yes could lead to HEFTY bills
BT and Co: Independence vote likely to mean 'increased costs'
Phones 4u slips into administration after EE cuts ties with Brit mobe retailer
More than 5,500 jobs could be axed if rescue mission fails
ISPs' post-net-neutrality world is built on 'bribes' says Tim Berners-Lee
Father of the worldwide web is extremely peeved over pay-per-packet-type plans
New 'Cosmos' browser surfs the net by TXT alone
No data plan? No WiFi? No worries ... except sluggish download speed
Radio hams can encrypt, in emergencies, says Ofcom
Consultation promises new spectrum and hints at relaxed licence conditions
Google+ GOING, GOING ... ? Newbie Gmailers no longer forced into mandatory ID slurp
Mountain View distances itself from lame 'network thingy'
Blockbuster book lays out the first 20 years of the Smartphone Wars
Symbian's David Wood bares all. Not for the faint hearted
Bonking with Apple has POUNDED mobe operators' wallets
... into submission. Weve squeals, ditches payment plans
Vodafone to buy 140 Phones 4u stores from stricken retailer
887 jobs 'preserved' in the process, says administrator PwC
prev story

Whitepapers

Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
The next step in data security
With recent increased privacy concerns and computers becoming more powerful, the chance of hackers being able to crack smaller-sized RSA keys increases.