Hackers used Samsung website to access Sprint’s customer data

Hackers used Samsung website to access Sprint’s customer data

Sprint Corporation, an American telecommunications company has announced that it has suffered a data breach after unknown hackers accessed customer accounts credentials using the Samsung.com “add a line” website.


Originally, the company was informed about the breach on June 22nd, 2019. The personal information which was accessed in the incident included full names, phone numbers, billing address, device ID,  device type, subscriber ID, account creation date, account number, monthly recurring charges, upgrade eligibility and add-on services.

See: Hacker extracts customer data from Canadian Telecom Firm after rebuttal


Although, it is unclear how many customers have been impacted, the breach notification notice [PDF] sent to customers stated that “Your account PIN may have been compromised, so we reset your PIN just in case in order to protect your account.”


The company further said that all targeted accounts were re-secured on June 25, 2019.


“Sprint has taken appropriate action to secure your account from unauthorized access and has not identified any fraudulent activity associated with your account at this time,” the company claimed.


Sprint has apologized for the breach and urged that customers should follow preventative measures recommended by the Federal Trade Commission (FTC).


“As a precautionary measure, we recommend that you take the preventative measures that are recommended by the Federal Trade Commission (FTC) to help protect you from fraud and identity theft. These preventative measures are included at the end of this letter. You may review this information on the FTC’s website at hackers samsung website access sprint customer