{"id":51301,"date":"2014-01-06T09:59:58","date_gmt":"2014-01-06T07:59:58","guid":{"rendered":"http:\/\/businesstech.co.za\/news\/?p=51301"},"modified":"2014-01-06T10:04:07","modified_gmt":"2014-01-06T08:04:07","slug":"mobile-operators-hit-by-security-flaws","status":"publish","type":"post","link":"https:\/\/businesstech.co.za\/news\/mobile\/51301\/mobile-operators-hit-by-security-flaws\/","title":{"rendered":"Vodacom and Cell C report security flaws"},"content":{"rendered":"<p>Two of South Africa&#8217;s mobile operators, Vodacom and Cell C have reported security flaws over the past week, exposing\u00a0subscribers\u2019 personal details including account balances.<\/p>\n<p>MyBroadband alerted Cell C on 2 January 2014, to a\u00a0security flaw with it&#8217;s\u00a0online portal \u2013 aka My Cell C \u2013 which allowed anyone with an internet connection to view personal information about many of Cell C\u2019s subscribers.<\/p>\n<p>A Cell C subscriber alerted MyBroadband that the \u201cMy Cell C My Account\u201d portal provided access to personal details about many Cell C numbers by using a generic master password.<\/p>\n<p>The security flaw was tested by MyBroadband using a new Cell C SIM and existing Cell C accounts. All Cell C numbers could be accessed, except those where the user changed their online password.<\/p>\n<p>A wide range of personal information could be accessed through the portal, including account details, banking details, numbers called, PIN and PUK numbers and payment history.<\/p>\n<p>Cell C confirmed the vulnerability, adding that it had since been\u00a0resolved.<\/p>\n<p>The operator said that they suspect the flaw was the result of recent system maintenance.<\/p>\n<p>\u201cWe are pleased to confirm that by mid-afternoon today [3 January 2014], a patch was developed, tested and deployed and the issue is now fully resolved,\u201d said Cell C.<\/p>\n<p>\u201cThe security of customer information is of the utmost importance to Cell C and we will be appraising our systems accordingly.\u201d<\/p>\n<p><strong>Vodacom<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>It follows a security flaw in the \u201cMy Vodacom\u201d online portal which exposed Vodacom subscribers\u2019 personal details, including account balances, package details, service providers, average monthly spend, the phone used, PUK and PIN details.<\/p>\n<p>The flaw allowed a Vodacom subscriber who is logged into the My Vodacom online portal to enter any Vodacom number and find personal details linked to this number.<\/p>\n<p>Vodacom was alerted to the security flaw on the afternoon of the 26 December and the company launched a \u201ccomplete investigation\u201d.<\/p>\n<p>It said that the flaw was identified, and a patch was developed overnight.<\/p>\n<p>The patch was tested successfully on the morning of the 27 December and was deployed into production by midday on the same day.<\/p>\n<p>\u201cOnly high level account summary information was exposed such as the type of package and the balances. No banking information was compromised nor was it possible to transact on the affected number,\u201d said Vodacom.<\/p>\n<h3 class=\"my-4\">This article first appeared on <a title=\"http:\/\/mybroadband.co.za\/news\/\" href=\"http:\/\/mybroadband.co.za\/news\/\" target=\"_blank\"><strong>MyBroadband<\/strong><\/a><\/h3>\n<h3 class=\"my-4\">More on security flaws<\/h3>\n<p><a title=\"http:\/\/mybroadband.co.za\/news\/security\/94234-my-vodacom-security-flaw-exposes-subscriber-details.html\" href=\"http:\/\/mybroadband.co.za\/news\/security\/94234-my-vodacom-security-flaw-exposes-subscriber-details.html\" target=\"_blank\"><strong>My Vodacom security flaw exposes subscriber details<\/strong><\/a><\/p>\n<p><a title=\"http:\/\/mybroadband.co.za\/news\/security\/94332-big-cell-c-security-flaw-uncovered.html\" href=\"http:\/\/mybroadband.co.za\/news\/security\/94332-big-cell-c-security-flaw-uncovered.html\" target=\"_blank\"><strong>Big Cell C security flaw uncovered<\/strong><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Two of South Africa&#8217;s mobile operators, Vodacom and Cell C have reported security flaws over the past week, exposing subscribers\u2019 personal details, including account balances.<\/p>\n","protected":false},"author":10,"featured_media":23031,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[34],"tags":[42,26,27],"class_list":["post-51301","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-mobile","tag-cell-c","tag-headline","tag-vodacom"],"_links":{"self":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts\/51301","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/comments?post=51301"}],"version-history":[{"count":4,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts\/51301\/revisions"}],"predecessor-version":[{"id":51308,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts\/51301\/revisions\/51308"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/media\/23031"}],"wp:attachment":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/media?parent=51301"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/categories?post=51301"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/tags?post=51301"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}