T-Mobile, AT&T agree to stop saying mobile voicemail is safe

By Robert McMillan, IDG News Service |  Security, AT&T, T-Mobile Add a new comment

Mobile service providers AT&T and T-Mobile have been banned from saying that their voicemail systems are safe from sabotage after agreeing to permanent injunctions filed in a Los Angeles court.

The cell-phone providers falsely advertised the security of their systems, according to the Los Angeles District Attorney's Office. During an investigation, "cell phones purchased by undercover investigators were easily hacked into, enabling the voicemail to be changed at will," the district attorney said in a statement Thursday.

"Hacking into voicemail allowed messages to be changed or erased. Important information could be removed from the voicemail and phony information could be inserted," the district attorney said. "Imagine the havoc that could result."

Investigators were able to hack into voicemail accounts using something called a SpoofCard. SpoofCard's software lets people display any number they want on caller ID and has been used to access voicemail systems that do not require passwords such as those used by Cingular (now part of AT&T) and T-Mobile.

In a statement, T-Mobile said that customers who want to add password protection to their voicemail should call voicemail, then press the star key to interrupt the greeting, and then press 5 to be prompted to change their password.

"T-Mobile cooperated with the district attorney and is pleased to have reached resolution on the issue," the company said.

Two years ago, SpoofCard suspended Paris Hilton's account after gossip sheets linked her to the voicemail hacking of her celebrity rival, Lindsay Lohan. At the time, SpoofCard said it had suspended more than 50 customers for using the service to hack into voicemail accounts.

As part of Thursday's settlement, AT&T will pay US$59,300 in penalties; T-Mobile will pay $25,000. The case was heard in the Superior Court of the State of California for the County of Los Angeles.

In a separate civil action, SpoofCard's parent company TelTech Systems has agreed not to advertise its product as "legal in 50 states." It is not legal in California and some other states, the district attorney's office said. TelTech will also pay a $33,000 fine.

AT&T and TelTech did not immediately return calls seeking comment.

ITworld LIVE

SecurityWhite Papers & Webcasts

White Paper

Extending IT Governance: From Private to Hybrid Clouds Through Consistency and Portability

IT shouldn't try to stop public clouds-not that they likely could even if they wanted to. But by working with their users, IT can make an organization's use of public and hybrid clouds a useful complement to in-house IT rather than a renegade operation that increases an organization's risks and costs.

White Paper

Secure Mobile Applications

This white paper provides a detailed description of Good Technology's Security and Architecture. It provides an overview of the changing landscape of mobile technologies within the enterprise and enumerates the key mobile device challenges faced by enterprise and government organizations.

White Paper

BYOD Policy Considerations

As companies embrace the usage of individual liable mobile devices to access corporate applications and data, Good Technology is often asked for guidance on creating individual liable usage policies. This document provides guidance on the questions to ask when establishing these policies.

Webcast On Demand

Seven Deadly Sins of Cloud Security (Video)

As cloud computing gains popularity, too few people are aware of the security threats that are emerging. In this short video, experts from HP discuss the latest cloud security threats and explain measures to help overcome them. Hear about the seven deadly sins of cloud security and learn how to avoid becoming a victim of poor security in your cloud environment.Intel and the Intel logo are trademarks of Intel Corporation in the U.S. and/or other countries.

Sponsor: HP & Intel

White Paper

Establishing a Strategy for Database Security is No Longer Optional

The options for securing increasingly valuable databases are very broad and deep, and can be confusing. This research provides an overview of three categories of controls that should be implemented to ensure that enterprise data is protected in the most efficient and effective manner.

See more White Papers | Webcasts

Ask a question

Ask a Question