Cyber Incident Victim: United States Cellular Corporation
Date:
Dec 2021
Location:
United States of America
Summary
UScellular experienced a data breach when unauthorized actors compromised its billing system, accessing customer accounts containing personal information such as names, addresses, PIN codes, phone numbers, service plans, and billing details. The attackers exploited this access to fraudulently port customer numbers, potentially aiming to intercept two-factor authentication codes. Sensitive data like Social Security numbers and credit card information remained masked within the CRM system and were not confirmed as exposed. The incident impacted 405 individuals, with the carrier resetting employee credentials and affected customers' security questions as mitigation. This marked the company's second security event within the same year following a prior breach involving CRM software access.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
UScellular detected unauthorized access to its billing system on December 13, 2021, prompting an investigation that revealed sustained activity through December 19, 2021. Attackers compromised the carrier's customer relationship management (CRM) system, gaining visibility into wireless customer accounts containing personal information including names, addresses, PIN codes, phone numbers, service plans, usage details, and billing statements. The threat actors leveraged stolen data to fraudulently port customer phone numbers, a technique commonly used to intercept two-factor authentication codes for account takeovers. Sensitive information such as Social Security numbers and credit card data remained protected through masking protocols within the CRM platform. The company confirmed no evidence of unauthorized access to customer online user accounts despite the billing system intrusion.

The carrier notified 405 affected individuals via breach disclosure letters in early January 2022, marking its second security incident of the year following a January 2021 CRM access breach. Response measures included forced resets of employee login credentials and security question updates for impacted customers. Forensic analysis determined the intrusion window spanned six days, though the disclosure didn't specify whether the porting attempts succeeded or quantify potential financial losses. UScellular emphasized continuous system monitoring while acknowledging persistent risks of attackers exploiting ported numbers for secondary account compromises across other platforms. The incident exposed operational vulnerabilities in billing infrastructure without compromising masked financial identifiers or online account credentials.
