Don’t do SECURITY. Do business SECURELY.

AT&T flaw exposes email addresses of 114,000 iPad owners

A weakness in an AT&T website exposed the email addresses of around 114,000 early iPad 3G owners, including senior officials and executives.

A flaw in an AT&T web application exposed the email addresses of around 114,000 owners of Apple’s new iPad 3G. The weakness was found by a group calling itself Goatse Security, whose members harvested the addresses by sending the site SIM card identifiers.

What happened

  • The group used a script that submitted ICC-IDs (SIM identifiers) with a spoofed iPad user agent, and the site returned the matching email address.
  • Those exposed reportedly included media chief executives, technology executives, and staff at NASA, the FAA, and US military agencies.
  • AT&T said it had disabled the feature that returned the addresses and notified affected customers.
  • Two people linked to the group were later charged in the US; one conviction was overturned on appeal in 2014.

Why it mattered

The incident showed how a simple enumeration flaw in a web service could expose data about high-profile users of a flagship product, and it fuelled debate about how researchers should disclose vulnerabilities.

Lessons for organisations

Test web applications and APIs for insecure direct object references and enumeration before launch, and rate-limit lookups. A clear vulnerability disclosure policy makes it easier for researchers to report issues responsibly.

Source: Engadget

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights