Los Angeles Times

Verizon customer data exposed by its vendor

- By Jill Leovy jill.leovy@latimes.com

Names and phone numbers of millions of Verizon customers were made available on a publicly accessible storage area owned by one of the company’s vendors, according an enterprise security software company that discovered the exposed data.

“Anyone entering a URL in a browser would have been able to access it,” said Dan O’Sullivan, a cyberresil­ience analyst with UpGuard, the Mountain View, Calif., company that found the data.

Exposed were text files logging calls made this year to Verizon call centers between Jan. 1 and June 22, O’Sullivan said. In most cases, the logs included the names, phone numbers and addresses of Verizon subscriber­s. In some cases, account personal identifica­tion numbers used to verify callers’ identities were also exposed, O’Sullivan said.

The storage area belonged to Nice Systems, a Verizon vendor that does business related to call-center management. UpGuard informed Verizon of its findings on June 13, O’Sullivan said. A week later, access was shut off.

After the technology news website ZD Net published a story about the episode Wednesday, Verizon issued a news release apologizin­g to its customers.

The phone giant confirmed that its customers’ informatio­n — including cellphone numbers and PINs in some cases — had been incorrectl­y placed in an insecure cloud storage area.

None of the exposed informatio­n had been lost or stolen, the company said.

Verizon spokesman David Samberg said 6 milthe lion unique customer accounts were exposed — a smaller number than the 14 million estimated by UpGuard. Verizon was still investigat­ing the problem when the story broke, he said.

Verizon said a “limited amount of personal informatio­n” had been left open to external access, as well as additional informatio­n that “had no external value.”

The episode prompted Rep. Ted Lieu (D-Torrance) to request a House Judiciary Committee hearing, said Lieu’s chief of staff, Marc Cevasco.

Lieu, a Verizon customer, is concerned about possible misuse of the data. “If anyone had that informatio­n they could go online and have access to your account, and your call log, etc.,” he said.

Also, “most people use their PIN for more than one thing,” he said, so exposed PINs might put people at risk of identity theft.

Cevasco also said Lieu was not convinced by Verizon’s assertions that no data had been lost or stolen. Samberg, the Verizon spokesman, said the assertion is based on a review of logs on storage site that yielded reports of who might have viewed the data.

“A good hacker would know how to circumvent stuff like that,” Cevasco said. Sophistica­ted state actors, looking for, say, informatio­n on government workers, were of particular concern, he added.

Lieu’s letter to Judiciary Chairman Robert W. Goodlatte (R-Va.) states that the data reportedly contained informatio­n on U.S. intelligen­ce officials. He called it “the latest in a series of disturbing data breaches.”

Nice Systems, headquarte­red in Raanana, Israel, released a statement that called the problem “human error” involving an “isolated staging area with limited informatio­n.”

O’Sullivan said the exposure underscore­s the rapidly increasing risks of data breaches. “This is a really remarkable incidence of thirdparty vendor risk,” he said. “A customer knows they are giving their informatio­n to Verizon, but they are probably not aware that informatio­n is going to be shared with third-party vendors.”

 ?? Bebeto Matthews Associated Press ?? VERIZON says data, including phone numbers and PINs, for 6 million customer accounts were exposed.
Bebeto Matthews Associated Press VERIZON says data, including phone numbers and PINs, for 6 million customer accounts were exposed.

Newspapers in English

Newspapers from United States