Verizon to pay $16 million in TracFone data breach settlement

Share:

Verizon Communications has agreed to pay a $16,000,000 settlement with the Federal Communications Commission (FCC) in the U.S. concerning three data breach incidents at its wholly-owned subsidiary, TracFone Wireless, suffered after its acquisition in 2021.

TracFone is a telecommunications service provider offering services through Total by Verizon Wireless, Straight Talk, and Walmart Family Mobile, among others.

Apart from the hefty civil penalty, the announced settlement agreement requires the communications firm to implement specific measures to increase the level of data security for its customers going forward.

Multiple data breaches

Data breaches at TracFone occurred between 2021 and 2023, involving three separate incidents.

The first, referred to as the ‘Cross-Brand’ incident, was self-reported by TracFone on January 14, 2022. The company discovered it in December 2021, but the investigation showed that the threat actors had access to customer data since January 2021.

With access to sensitive information, including personally identifiable information (PII) and customer proprietary network information (CPNI), the threat actors conducted a high number of unauthorized number porting request approvals.

“In connection with this incident, threat actors exploited certain vulnerabilities related to authentication and a limited number of APIs,” reads the decree.

“By exploiting those vulnerabilities, threat actors were able to gain unauthorized access to certain customer information.”

The other two data breach incidents concern TracFone’s order websites, reported on December 20, 2022, and January 13, 2023, respectively.

In both cases, unauthenticated threat actors exploited a vulnerability to access order information, including certain CPNI and other customer data.

“The threat actor(s) used two different methods to exploit the vulnerability (switching to a second method when TracFone successfully blocked the first),” explains the FCC’s decree document.

“TracFone ultimately implemented a long-term fix for the underlying vulnerability by February 2023.”

The number of exposed individuals and SIM-swapping incidents have been censored in the public version of the Consent Decree document.

The settlement agreement mandates that TrackFone will now have to implement the following measures by February 28, 2025:

  • Develop a mandated information security program to reduce API vulnerabilities by adhering to standards like NIST and OWASP, implementing secure API controls, and regularly testing and updating security measures.
  • Implement SIM change and port-out protections involving secure authentication for SIM changes and port-out requests, notifying customers of such requests, and offering number transfer PINs.
  • Perform information security annual assessments to ensure the program’s effectiveness, with independent third-party evaluations every two years to assess sufficiency and maturity.
  • Organize annual employee privacy and security awareness training to enhance their capability to safeguard customer data and comply with security protocols.

BleepingComputer has contacted Verizon and TracFone to ask how many customers were impacted, but we have not received an answer.

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
4:25 am, Jun 20, 2025
weather icon 18°C
L: 16° | H: 18°
broken clouds
Humidity: 82 %
Pressure: 1024 mb
Wind: 9 mph ENE
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 57%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:42 am
Sunset: 9:21 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
16° | 18°°C 0 mm 0% 11 mph 78 % 1024 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
18° | 32°°C 0.21 mm 21% 11 mph 62 % 1020 mb 0 mm/h
Sun Jun 22 10:00 pm
weather icon
18° | 26°°C 1 mm 100% 14 mph 82 % 1016 mb 0 mm/h
Mon Jun 23 10:00 pm
weather icon
15° | 25°°C 0.2 mm 20% 14 mph 75 % 1016 mb 0 mm/h
Tue Jun 24 10:00 pm
weather icon
14° | 25°°C 0 mm 0% 15 mph 76 % 1017 mb 0 mm/h
Today 7:00 am
weather icon
18° | 18°°C 0 mm 0% 7 mph 78 % 1024 mb 0 mm/h
Today 10:00 am
weather icon
22° | 24°°C 0 mm 0% 8 mph 57 % 1024 mb 0 mm/h
Today 1:00 pm
weather icon
26° | 26°°C 0 mm 0% 9 mph 33 % 1023 mb 0 mm/h
Today 4:00 pm
weather icon
26° | 26°°C 0 mm 0% 11 mph 34 % 1022 mb 0 mm/h
Today 7:00 pm
weather icon
24° | 24°°C 0 mm 0% 10 mph 40 % 1021 mb 0 mm/h
Today 10:00 pm
weather icon
20° | 20°°C 0 mm 0% 7 mph 56 % 1022 mb 0 mm/h
Tomorrow 1:00 am
weather icon
19° | 19°°C 0 mm 0% 5 mph 62 % 1020 mb 0 mm/h
Tomorrow 4:00 am
weather icon
18° | 18°°C 0 mm 0% 5 mph 59 % 1019 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€90,952.88
-0.28%
Ethereum(ETH)
€2,188.01
-0.12%
Tether(USDT)
€0.87
-0.01%
XRP(XRP)
€1.88
-0.11%
Solana(SOL)
€126.74
0.01%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.147500
-0.51%
Shiba Inu(SHIB)
€0.000010
-0.65%
Pepe(PEPE)
€0.000009
-1.46%
Scroll to Top