T-Mobile US let hackers nick my phone number, drain my crypto-wallets, cries man who lost $20k

PIN 'ignored' – no wonder T-Mob has put out an alert

By Shaun Nichols in San Francisco

Posted in Security, 6th February 2018 00:43 GMT

A bloke from Washington is suing T-Mobile USA after miscreants were able to steal his phone number and take all his crypto-coins.

Carlos Tapang this week told the US state's western district court that the telco broke America's Federal Communications Act when, in November of last year, it allowed strangers to get control of Tapang's phone number and use it to take over his cryptocurrency wallets and drain thousands of dollars in digital money.

According to Tapang's complaint [PDF], the raid occurred on November 7 last year when someone contacted T-Mob and asked the carrier to transfer his number to a device on AT&T's network.

Rather than ask for a PIN to authorize the transfer, which Tapang claims he asked the telco to require as a safety precaution, T-Mobile staff simply signed ported the number as requested, letting AT&T assign the cell number to a device controlled by the criminals, it is alleged. From there, the thieves used the cell number to reset the password on Tapang's online cryptocurrency account – which was linked to that number – and then take over its wallets and drain his funds.

In total, Tapang's suit claims the pilfered currency amounted to 2.875 Bitcoins, worth approximately $20,350 at the time. The wallets held 1,000 OmiseGo (OMG) tokens, and 19.6 BitConnect coins, which were converted into BTC by the crooks, it is claimed.

Someone checked and, yup, you can still hijack Gmail, Bitcoin wallets etc via dirty SS7 tricks


Tapang does not appear to be the only person to have allegedly had a phone number stolen via a fraudulent port-out request. Enough victims have reported account thefts that T-Mob has set up a website to deal with the issue. Punters are told to set up a PIN to protect their numbers, but according to Tapang that safeguard is useless.

Because the biz failed to require the PIN and allowed the number to be transferred without any authentication, Tapang has accused the cell network of negligence, and therefore responsible for the hack.

"T-Mobile has failed to establish or implement reasonable policies, procedures, or regulations governing the creation and authentication of user credentials for authorized customers accessing T-Mobile accounts, creating unreasonable risk of unauthorized access," the suit read.

"As such, at all times material hereto, T-Mobile has failed to ensure that only authorized persons have such access and that customer accounts are secure."

Now, Tapang is seeking a jury trial to determine damages for allegedly violating the Federal Communications Act, breach of contract, negligence, and breaking Washington's consumer protection act.

T-Mobile USA did not respond to a request for comment on the lawsuit. ®

Sign up to our NewsletterGet IT in your inbox daily


More from The Register

2017: The FBI alerts parents to dangers of Internet of Sh*t toys

Families urged to brush up on opsec, check for privacy leaks, patch security flaws, if possible

Phone crypto shut FBI out of 7,000 devices, complains chief g-man

But he gets it, there's a balance to be struck, yada yada

Fake mobile base stations spreading malware in China

'Swearing Trojan' pushes phishing texts around carriers' controls

Brit teen accused of running malware factory and helpdesk for crims

Lad cuffed after worldwide manhunt leads cops to parents' home in Stockport, UK

Did the FBI engineer its iPhone encryption court showdown with Apple to force a precedent? Yes and no, say DoJ auditors

Analysis Official report blows lid on behind-the-scenes

'DNC hackers' used mobile malware to track Ukrainian artillery – researchers

Frontline battlefield operatives are Fandoids?

Say hello to Dvmap: The first Android malware with code injection

Trojan deletes root access to dodge detection

Imagine you're having a CT scan and malware alters the radiation levels – it's doable

WannaCry was a wake-up call for healthcare, but the sector is still terribly vulnerable to attack

'Uncarrier' T-Mobile US to un-carry $40m for bumpkin blower bunkum

FCC levies fine equivalent to 32 hours of quarterly profit

Google Play Protect is 'dead last' at fingering malware on Android

Don't expect ads giant to stop all software nasties for you – it certainly can't