{"id":24422,"date":"2024-05-01T02:10:08","date_gmt":"2024-05-01T10:10:08","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2024\/05\/01\/news-18152\/"},"modified":"2024-05-01T02:10:08","modified_gmt":"2024-05-01T10:10:08","slug":"news-18152","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2024\/05\/01\/news-18152\/","title":{"rendered":"Wireless carriers fined $200 million after illegally sharing customer location data"},"content":{"rendered":"\n<p>After four years of investigation, the Federal Communications Commission (FCC) has <a href=\"https:\/\/www.fcc.gov\/document\/fcc-fines-largest-wireless-carriers-sharing-location-data\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">concluded<\/a> that four of the major wireless carriers in the US violated the law in sharing access to customers\u2019 location data.<\/p>\n<p>The FCC fined AT&amp;T, Sprint, T-Mobile, and Verizon a total of almost $200 million for \u201cillegally sharing access to customers\u2019 location information without consent and without taking reasonable measures to protect that information against unauthorized disclosure.\u201d<\/p>\n<p>The fines are divided up into $12 million for Sprint, $80 million for T-Mobile (which has now merged with Sprint), more than $57 million for AT&amp;T, and an almost $47 million for Verizon.<\/p>\n<p>From the press release it becomes apparent that the FCC considers real-time location data some of the most sensitive data in a carrier&#8217;s possession. Each of the four major carriers was found to be selling its customers\u2019 location information to \u201caggregators,\u201d who then resold access to such information to third-party location-based service providers.<\/p>\n<p>The investigation by the FCC was set in motion by public reports like the ones in the <a href=\"https:\/\/www.nytimes.com\/2018\/05\/10\/technology\/cellphone-tracking-law-enforcement.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">New York Times<\/a>, <a href=\"https:\/\/www.vice.com\/en\/article\/nepxbz\/i-gave-a-bounty-hunter-300-dollars-located-phone-microbilt-zumigo-tmobile\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Vice.com<\/a>, and a letter from Sen. Ron Wyden to the FCC. All pointed out that anyone could get location information about almost any US phone if they were willing to pay an unauthorized source.<\/p>\n<p>The FCC press release specifically mentions a location-finding service operated by Securus, a provider of communications services to correctional facilities, as a source that provided the possibility to track people&#8217;s location.<\/p>\n<p>The US law, including section 222 of the <a href=\"https:\/\/transition.fcc.gov\/Reports\/1934new.pdf\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Communications Act<\/a>, requires carriers to take reasonable measures to protect certain customer information, including location information.<\/p>\n<p>The wireless carriers attempted to offload their obligation to obtain customer consent onto the downstream recipients of the location information. The end result was a failure in which no valid customer consent was obtained. And even though the carriers were aware of this, they continued to sell access to location information without taking reasonable measures to protect it from unauthorized access.<\/p>\n<p>As reported by <a href=\"https:\/\/krebsonsecurity.com\/2018\/05\/tracking-firm-locationsmart-leaked-location-data-for-customers-of-all-major-u-s-mobile-carriers-in-real-time-via-its-web-site\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Krebs on Security<\/a>, one of the data aggregation firms, LocationSmart, had a free, unsecured demo of its service online that anyone could abuse to find the near-exact location of virtually any mobile phone in North America.<\/p>\n<p>Spokespersons of Verizon and AT&amp;T both indicated to <a href=\"https:\/\/www.bleepingcomputer.com\/news\/technology\/fcc-fines-carriers-200-million-for-illegally-sharing-user-location\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">BleepingComputer<\/a> that they felt as if they were taking the blame for another company\u2019s failure to obtain consent.<\/p>\n<p>T-Mobile said in a statement to <a href=\"https:\/\/edition.cnn.com\/2024\/04\/29\/tech\/fcc-fines-att-verizon-200-million\/index.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">CNN<\/a> that it discontinued the location data-sharing program over five years ago. The company wanted to make sure first that critical services like roadside assistance, fraud protection, and emergency response would not suffer any negative consequences if it did.<\/p>\n<p>All three companies indicated they will appeal the order. We\u2019ll keep you posted on any new developments.<\/p>\n<hr class=\"wp-block-separator alignfull has-alpha-channel-opacity is-style-wide\" \/>\n<p><strong>We don\u2019t just report on phone security\u2014we provide it<\/strong><\/p>\n<p>Cybersecurity risks should never spread beyond a headline. Keep threats off your mobile devices by\u00a0<a href=\"https:\/\/www.malwarebytes.com\/ios\">downloading Malwarebytes for iOS<\/a>, and <a href=\"https:\/\/www.malwarebytes.com\/android\">Malwarebytes for Android<\/a> today.<\/p>\n<p><a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2024\/05\/wireless-carriers-fined-200-million-after-illegally-sharing-customer-location-data\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> Four major wireless carriers have been fined by the FCC for sharing access to customers\u2019 location data without consent. <\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[32,5897],"class_list":["post-24422","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-news","tag-privacy"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/24422","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=24422"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/24422\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=24422"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=24422"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=24422"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}