Breach report
TelecomVerizon
Data of 14 Million Verizon Customers Exposed in Server Snafu
A Verizon call-center vendor left logs on millions of customers, including account PINs, in a publicly accessible Amazon S3 bucket, illustrating how third-party cloud mistakes can expose telecom accounts to takeover.
Reported by BleepingComputer
Records exposed
14M
Up to 14 million customer records (Verizon said about 6 million)
Scale vs. largest on file
- When
- 2017
- How they got in
- Misconfigured cloud storage at third-party vendor (Amazon S3)
- Sector
- Telecom
In July 2017, cybersecurity firm UpGuard revealed that records tied to as many as 14 million Verizon customers had been left publicly accessible on the internet. The data sat in an Amazon S3 cloud storage bucket controlled by NICE Systems, an Israel-based company that provided call center and customer service software to Verizon. Anyone who knew or guessed the bucket's web address could download the files.
UpGuard researcher Chris Vickery found the exposed repository on June 13, 2017, and notified Verizon. The bucket was secured on June 22, about nine days later. The exposure resulted from the vendor's configuration settings, which allowed public access to data that should have been restricted. There was no evidence of a targeted hack, and Verizon said it was not aware of any loss or theft of customer information beyond the researcher's discovery.
The files were logs of customers who had called Verizon's service lines over the previous six months. They contained names, addresses and phone numbers, along with account details and, critically, account PINs, the codes used to verify identity when a customer calls the carrier. Security experts warned that the PINs posed the greatest risk, since a criminal armed with a name, number and PIN could impersonate a customer, request changes to the account or port the number to a new SIM, intercepting text-message security codes in the process.
Verizon disputed the scale, saying the number of affected customers was about 6 million rather than 14 million, and stressed that the data was stored by a vendor for a customer service project. The company emphasized that no loss or theft had occurred. The same NICE bucket reportedly also held data related to French telecom operator Orange. The incident drew attention from lawmakers who were already concerned about how carriers protect customer account information.
The leak came during a wave of exposures in 2017 caused by misconfigured Amazon S3 buckets, affecting government contractors, media companies and political data firms. It highlighted that cloud storage, while secure by default, can be opened to the world by a single setting, and that companies remain accountable for data their vendors mishandle. For consumers, it reinforced advice to use unique carrier PINs and to add port-out protections to mobile accounts.