T-Mobile US let hackers nick my phone number, drain my crypto-wallets, cries man who lost $20k

PIN 'ignored' – no wonder T-Mob has put out an alert

By Shaun Nichols in San Francisco


A bloke from Washington is suing T-Mobile USA after miscreants were able to steal his phone number and take all his crypto-coins.

Carlos Tapang this week told the US state's western district court that the telco broke America's Federal Communications Act when, in November of last year, it allowed strangers to get control of Tapang's phone number and use it to take over his cryptocurrency wallets and drain thousands of dollars in digital money.

According to Tapang's complaint [PDF], the raid occurred on November 7 last year when someone contacted T-Mob and asked the carrier to transfer his number to a device on AT&T's network.

Rather than ask for a PIN to authorize the transfer, which Tapang claims he asked the telco to require as a safety precaution, T-Mobile staff simply signed ported the number as requested, letting AT&T assign the cell number to a device controlled by the criminals, it is alleged. From there, the thieves used the cell number to reset the password on Tapang's online cryptocurrency account – which was linked to that number – and then take over its wallets and drain his funds.

In total, Tapang's suit claims the pilfered currency amounted to 2.875 Bitcoins, worth approximately $20,350 at the time. The wallets held 1,000 OmiseGo (OMG) tokens, and 19.6 BitConnect coins, which were converted into BTC by the crooks, it is claimed.

Someone checked and, yup, you can still hijack Gmail, Bitcoin wallets etc via dirty SS7 tricks


Tapang does not appear to be the only person to have allegedly had a phone number stolen via a fraudulent port-out request. Enough victims have reported account thefts that T-Mob has set up a website to deal with the issue. Punters are told to set up a PIN to protect their numbers, but according to Tapang that safeguard is useless.

Because the biz failed to require the PIN and allowed the number to be transferred without any authentication, Tapang has accused the cell network of negligence, and therefore responsible for the hack.

"T-Mobile has failed to establish or implement reasonable policies, procedures, or regulations governing the creation and authentication of user credentials for authorized customers accessing T-Mobile accounts, creating unreasonable risk of unauthorized access," the suit read.

"As such, at all times material hereto, T-Mobile has failed to ensure that only authorized persons have such access and that customer accounts are secure."

Now, Tapang is seeking a jury trial to determine damages for allegedly violating the Federal Communications Act, breach of contract, negligence, and breaking Washington's consumer protection act.

T-Mobile USA did not respond to a request for comment on the lawsuit. ®

Sign up to our NewsletterGet IT in your inbox daily


More from The Register

FBI fingers North Korea for two malware strains

'Joanap' and 'Brambul' harvest info about your systems and send it home

Ignore that FBI. We're the real FBI, says the FBI that's totally the FBI

Don't open that malware mail from the Feds that's not from the Feds, Feds warn

Israel cyberczar drops hints about country's new security initiative

Israel Cyber Week PM pops in to brag about industry wins

FBI to World+Dog: Please, try turning it off and turning it back on

Feds trying to catalogue VPNFilter infections

FBI agents take aim at VPNFilter botnet, point finger at Russia, yell 'national security threat'

Feds warn admins malware is rather tough to destroy

You want how much?! Israel opts not to renew its Office 365 vows

Government to cut Microsoft off at the end of 2018

Israel cyber chief's 'pants' analogy for password security deemed, well, 'pants'

Changed often, never shared? Prevailing wisdom suggests otherwise

NSO Group bloke charged with $50m theft of government malware

Alleged unethical behavior from a grey hat? Who'd a thunk it?

FBI's flawed phone tally blamed on programming error. 7,800 unbreakable mobes? Er, um...

We meant 1,000. Maybe 2,000

Schadenfreude for UK mobile networks over the tumult at Carphone

Analysis That's what you get for selling unlocked phones