/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Leaked chat logs: Lapsus$ hacked T-Mobile multiple times in March and stole some projects' source code; T-Mobile says no customer or government info was stolen

Krebs on Security Brian Krebs

Context & Ripple Effects

T-Mobile's assurance that this intrusion did not involve customer or government information narrows the immediate exposure, but it arrives days after court documents described a failed effort to halt sales of data from 30M customers. The company had also disclosed earlier breaches involving roughly 2M accounts and was investigating claims tied to more than 100M people in 2021.

The stolen project code adds a different security concern to that record: proprietary software, rather than account records, is now part of the attack surface. A later filing on data affecting about 37M customers shows that the company's security disclosures continued beyond this incident.

First-order effects

  • T-Mobile must evaluate the affected projects for code exposure and secure any systems or development processes that the stolen material could reveal.
  • Lapsus$ gains proprietary project material, while T-Mobile's stated absence of customer and government data limits the incident's immediately disclosed data scope.

Second-order effects

  • The source-code theft raises the value of T-Mobile's internal development environment as a target, alongside the customer-data repositories implicated in its earlier incidents.
  • T-Mobile's prior payment to stop a leak, which the hackers continued selling, weakens any assumption that containment through a third party ends an attacker-controlled disclosure.

Third-order effects

  • Repeated disclosures spanning account data, large claimed datasets, and project source code point to a security challenge that reaches across T-Mobile's distinct information systems rather than a single exposed database.
  • If such incidents persist, telecom security assessments will increasingly turn on protection of software-development systems as well as the handling of subscriber records.

The trend: Telecom breach risk is broadening from customer-record theft to attacks on the software and internal systems that support network services.

Discussion

  • @brettcallow Brett Callow on x
    At least one of the Lapsus$ team was worried - mostly about being found out by mum and dad. This is good stuff from @briankrebs https://krebsonsecurity.com/ ... https://twitter.com/...
  • @kimzetter Kim Zetter on x
    Really good stuff. @briankrebs got hold of private chats between teen hackers from LAPSUS$. Discuss buying access to victim networks from Russian cybercrime forums or buying/stealing/sweet-talking their way into employee accounts https://krebsonsecurity.com/ ...
  • @gibsongrantm Grant Gibson on x
    Leaked chats from #Lapsus$ outlined by @briankrebs showcase both their youth and maturity at the same time. We see how #multifactor authentication thwarted them however they abandoned @TMobile sim swapping. Priorities! https://ow.ly/...
  • @gi7w0rm @gi7w0rm on x
    So turns out #Lapsus$ had access to @TMobile for months, accessed #Globant by a 5 years old access token, doxxed each other and also lost access to one of their most important #AWS Servers with “SOOOO much illegal stuff” and advertised Supoenia Services... https://krebsonsecurity…
  • @williamturton William Turton on x
    “RIP FBI seized my server,” Amtrak wrote. “So much illegal shit. It's filled with illegal shit.” https://krebsonsecurity.com/ ...
  • @briankrebs @briankrebs on x
    1/ Exclusive: Leaked private chats from the LAPSUS$ group show they hacked T-Mobile multiple times last month, stealing large volumes of source code. T-Mobile says no customer or government data was taken. https://krebsonsecurity.com/ ...