Threat actor IntelBroker claims to have breached T-Mobile’s infrastructure this month. Image credit-Bleeping Computer
It’s possible that Common Vulnerabilities and Exposures (CVE) listing CVE-2024-1597 was exploited to obtain the data since this vulnerability affects Confluence Data Center and Server and according to Bleeping Computer, has a severity score of 9.8 out of 10. But at this point, it is not clear whether the aforementioned third-party vendor was breached using this vulnerability.
The data that IntelBroker says that he is selling includes “Source code, SQL files, Images, Terraform data, t-mobile.com certifications, Siloprograms.” A source told Bleeping Computer that the data being sold “is actually older screenshots of T-Mobile‘s infrastructure posted to a third-party vendor’s servers, where it was stolen.” This would dovetail with T-Mobile‘s statement that it is “actively investigating a claim of an issue at a third-party service provider.”