Menu
Browse

Cyber Incident Victim: United States Cellular Corporation

Date:

Dec 2021

Location:

United States of America

Summary

UScellular experienced a data breach when unauthorized actors compromised its billing system, accessing customer accounts containing personal information such as names, addresses, PIN codes, phone numbers, service plans, and billing details. The attackers exploited this access to fraudulently port customer numbers, potentially aiming to intercept two-factor authentication codes. Sensitive data like Social Security numbers and credit card information remained masked within the CRM system and were not confirmed as exposed. The incident impacted 405 individuals, with the carrier resetting employee credentials and affected customers' security questions as mitigation. This marked the company's second security event within the same year following a prior breach involving CRM software access.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

UScellular detected unauthorized access to its billing system on December 13, 2021, prompting an investigation that revealed sustained activity through December 19, 2021. Attackers compromised the carrier's customer relationship management (CRM) system, gaining visibility into wireless customer accounts containing personal information including names, addresses, PIN codes, phone numbers, service plans, usage details, and billing statements. The threat actors leveraged stolen data to fraudulently port customer phone numbers, a technique commonly used to intercept two-factor authentication codes for account takeovers. Sensitive information such as Social Security numbers and credit card data remained protected through masking protocols within the CRM platform. The company confirmed no evidence of unauthorized access to customer online user accounts despite the billing system intrusion.

Cyber Incident Image

The carrier notified 405 affected individuals via breach disclosure letters in early January 2022, marking its second security incident of the year following a January 2021 CRM access breach. Response measures included forced resets of employee login credentials and security question updates for impacted customers. Forensic analysis determined the intrusion window spanned six days, though the disclosure didn't specify whether the porting attempts succeeded or quantify potential financial losses. UScellular emphasized continuous system monitoring while acknowledging persistent risks of attackers exploiting ported numbers for secondary account compromises across other platforms. The incident exposed operational vulnerabilities in billing infrastructure without compromising masked financial identifiers or online account credentials.

Sources
Sources available to members
1 source