T-Mobile will pay $350 million to settle lawsuits over massive data breach

If you were a T-Mobile customer in August 2021, you may get a few dollars from the carrier in the near future. It has agreed to settle a consolidated class action lawsuit filed against the company over a data breach that exposed the personal information of 76.6 million “current, former and prospective customers.” Back when T-Mobile’s CEO, Mike Sievert, admitted and apologized for the breach, the carrier said the individual who hacked its network used “specialized” tools and knowledge of its infrastructure in order to gain access to its testing environment. That individual then stole customer data from the network and sold them on hacker forums.

The type of information that the bad actor sold varies per person, but it could include the name, birth date and social security number for each individual. T-Mobile got in touch with people affected by the data leak shortly after it came to light and offered them two free years of access to McAfee’s ID Theft Protection Service. Now, they’re also getting monetary compensation, though it will likely be a few dollars at most. While the $350 million settlement may sound substantial, a huge chunk of that amount will go towards paying off legal fees. The rest will be divided among tens of millions of affected customers. According to the SEC filing spotted by GeekWire, the company will also spend $150 million on data security technologies throughout this year and the next.

The settlement still has to be approved by the court. But if it does, it will “resolve substantially all of the claims brought by the company’s current, former and prospective customers who were impacted by the 2021 cyberattack.” You can read the full proposed settlement here.

Former Amazon engineer convicted in 2019 Capital One data breach

A Seattle jury has found Paige Thompson, a former Amazon software engineer accused of stealing data from Capital One in 2019, guilty of wire fraud and five counts of unauthorized access to a protected computer. The Capital One hack was one of the biggest security breaches in the US and compromised the data of 100 million people in the country, along with 6 million people in Canada. Thompson was arrested in July that year after a GitHub user saw her post on the website sharing information about stealing data from servers storing Capital One information. 

According to the Department of Justice, Thompson used a tool she built herself to scan Amazon Web Services for misconfigured accounts. She then allegedly used those accounts to infiltrate Capital One’s servers and download over 100 million people’s data. The jury has decided that Thompson violated the Computer Fraud and Abuse Act by doing so, but her lawyers argued that she used the same tools and method also used by ethical hackers.

The Justice Department recently amended the Computer Fraud and Abuse Act to protect ethical or white hat hackers. As long as researchers are investigating or fixing vulnerabilities in “good faith” and aren’t using the security holes they discover for extortion or other malicious purposes, they can no longer be charged under the law.

US authorities, however, disagreed with the assertion that she was only trying to expose Capital One’s vulnerabilities. The Justice Department said she planted cryptocurrency mining software onto the bank’s servers and sent the earnings straight to her digital wallet. She also allegedly bragged about the hack on online forums. 

“Far from being an ethical hacker trying to help companies with their computer security, she exploited mistakes to steal valuable data and sought to enrich herself,” US Attorney Nick Brown said. Thompson could be sentenced with up to 20 years of prison time for wire fraud and up to five years for each charge of illegally accessing a protected computer. Her sentencing hearing is scheduled for September 15th.

Former Amazon engineer convicted in 2019 Capital One data breach

A Seattle jury has found Paige Thompson, a former Amazon software engineer accused of stealing data from Capital One in 2019, guilty of wire fraud and five counts of unauthorized access to a protected computer. The Capital One hack was one of the biggest security breaches in the US and compromised the data of 100 million people in the country, along with 6 million people in Canada. Thompson was arrested in July that year after a GitHub user saw her post on the website sharing information about stealing data from servers storing Capital One information. 

According to the Department of Justice, Thompson used a tool she built herself to scan Amazon Web Services for misconfigured accounts. She then allegedly used those accounts to infiltrate Capital One’s servers and download over 100 million people’s data. The jury has decided that Thompson violated the Computer Fraud and Abuse Act by doing so, but her lawyers argued that she used the same tools and method also used by ethical hackers.

The Justice Department recently amended the Computer Fraud and Abuse Act to protect ethical or white hat hackers. As long as researchers are investigating or fixing vulnerabilities in “good faith” and aren’t using the security holes they discover for extortion or other malicious purposes, they can no longer be charged under the law.

US authorities, however, disagreed with the assertion that she was only trying to expose Capital One’s vulnerabilities. The Justice Department said she planted cryptocurrency mining software onto the bank’s servers and sent the earnings straight to her digital wallet. She also allegedly bragged about the hack on online forums. 

“Far from being an ethical hacker trying to help companies with their computer security, she exploited mistakes to steal valuable data and sought to enrich herself,” US Attorney Nick Brown said. Thompson could be sentenced with up to 20 years of prison time for wire fraud and up to five years for each charge of illegally accessing a protected computer. Her sentencing hearing is scheduled for September 15th.

FBI warns crypto fraud on LinkedIn is a ‘significant threat’

If you have a tendency to talk to people you don’t know on LinkedIn, you may want to take extra care. According to a CNBC report, the company has acknowledged a “recent uptick of fraud on its platform,” and this time the scams involve persuading users …