Up to 14 million Verizon subscribers may have had their sensitive data exposed by Nice Systems, a partner of Verizon, reports ZDNet. Subscriber records from users who called customer service over the past six months were located on an unprotected Amazon S3 storage server controlled by Verizon partner Nice Systems.

The data, which included customer names, phone numbers, home addresses, email addresses, and account PINs, was accessible to anyone who found what ZDNet says was an easy-to-guess web address. That PINs were made available is concerning as a PIN is what's used to verify a customer's identify and make changes to an account.

verizonlogo

The customer records were contained in log files that were generated when Verizon customers in the last six months called customer service. These interactions are recorded, obtained, and analyzed by Nice, which says it can "realize intent, and extract and leverage insights to deliver impact in real time." Verizon uses that data to verify account holders and to improve customer service.

There were six folders for the months between January 2017 and June 2017, which included customer calls from several different US regions. Records included "hundreds of fields of additional data" beyond name, phone number, and PIN, like current account balance, a list of Verizon services, and more. No audio files were found, though the log files were based on calls. Some of the data was masked, but it's not clear what was hidden and what was exposed.

Verizon was informed of the leak in late June and it took more than a week for the information to be secured. Verizon told ZDNet it is investigating how information was improperly stored on the Amazon Web Services server. The company also said the "overwhelming majority" of the data has "no external value" and there's "no indication that the information has been compromised."

"Verizon provided the vendor with certain data to perform this work and authorized the vendor to set up AWS storage as part of this project," said a spokesperson. "Unfortunately, the vendor's employee incorrectly set their AWS storage to allow external access."

Verizon customers who have called in to customer support over the course of the last six months should update their PINs as a precaution.

Update: Verizon released a press statement clarifying that no one accessed the data, so there was no theft or loss of customer information. Verizon also says that only 6 million unique customers were affected and those customers were part of its residential and small business wireline.

Tag: Verizon

Top Rated Comments

keysofanxiety Avatar
88 months ago
Fake news. None of that information was ever protected in the first place. Literally almost each and every thing about all of us is known - to those who want to know it.

We have no privacy in the digital age, 'hacked' or not. It is all available.
Cool. In which case I'm sure you don't mind publically sharing your full name, phone number, email address and home address with us?

Allowing such information to become available to the public by simply following a URL which wasn't secured is far from "fake news". It's very much real news and very much an oversight that could have been easily avoided.
Score: 15 Votes (Like | Disagree)
mudflap Avatar
88 months ago
Can you hack me now?
Score: 13 Votes (Like | Disagree)
keysofanxiety Avatar
88 months ago
Coincidence that your username is keysofanxiety? I only meant to imply that any fear from this leak is the fake news. Everyone could know your address if they wanted to. Snapchat geocodes you. FB geotags you. Your phone tracks everywhere you go. Even this forum has your IP address and could make a discernible guess as to your location. Take pictures? The EXIF data extracted from those would give every location of any picture you've ever taken and posted to Instagram, etc.

And that's not even mentioning all of the rights we toss away whenever we click "I agree" to those lengthy TOS agreements that nobody ever reads. Or to say anything of the Patriot Act and the loss of those civil liberties.

People shouldn't get scared by this Verizon leak - that moment passed about 15 years ago.
All of that is true, yet it doesn't mean making such information readily available is appropriate.

There seems to be these sorts of comments every time there's any type of privacy leak and frankly I'm sick of reading it. "Who cares, if you're part of Google's ecosystem, or use Facebook, people know this stuff anyway. You think you're safe? LOL."

It's a hugely dismissive argument. Yes, people can always find stuff about you if they look hard enough or have the sufficient knowledge. There's no such thing as 'real privacy' on the Internet; nobody is denying that. But that doesn't somehow justify even more people or companies making it easier to do so.
Score: 9 Votes (Like | Disagree)
WRChris Avatar
88 months ago
Coincidence that your username is keysofanxiety? I only meant to imply that any fear from this leak is the fake news. Everyone could know your address if they wanted to. Snapchat geocodes you. FB geotags you. Your phone tracks everywhere you go. Even this forum has your IP address and could make a discernible guess as to your location. Take pictures? The EXIF data extracted from those would give every location of any picture you've ever taken and posted to Instagram, etc.

And that's not even mentioning all of the rights we toss away whenever we click "I agree" to those lengthy TOS agreements that nobody ever reads. Or to say anything of the Patriot Act and the loss of those civil liberties.

People shouldn't get scared by this Verizon leak - that moment passed about 15 years ago.
Nothing about this is fake news. Do you know what that even means?

Also your assumption that everyone who uses Verizon customer service uses those other services you talked about seems ludicrous.

Should we not know that our PINs may be in the hands of someone other than the account holder or Verizon?
Score: 5 Votes (Like | Disagree)
Vasilioskn Avatar
88 months ago
Anyone who says “fake news” is usually full of **** these days.
Score: 4 Votes (Like | Disagree)
Mick-Mac Avatar
88 months ago
"may have had their sensitive data exposed by Nice Systems"
after translating from Marketing to English becomes:
"had their sensitive data exposed by Nice Systems"
Score: 2 Votes (Like | Disagree)

Popular Stories

reset password request iphone

Warning: Apple Users Targeted in Phishing Attack Involving Rapid Password Reset Requests

Tuesday March 26, 2024 4:34 pm PDT by
Phishing attacks taking advantage of Apple's password reset feature have become increasingly common, according to a report from KrebsOnSecurity. Multiple Apple users have been targeted in an attack that bombards them with an endless stream of notifications or multi-factor authentication (MFA) messages in an attempt to cause panic so they'll respond favorably to social engineering. An...
maxresdefault

Apple to Launch New iPad Pro and iPad Air Models in May

Thursday March 28, 2024 11:07 am PDT by
Apple will introduce new iPad Pro and iPad Air models in early May, according to Bloomberg's Mark Gurman. Gurman previously suggested the new iPads would come out in March, and then April, but the timeline has been pushed back once again. Subscribe to the MacRumors YouTube channel for more videos. Apple is working on updates to both the iPad Pro and iPad Air models. The iPad Pro models will...
Generic iOS 18 Feature Purple

iOS 18: What to Expect From 'Biggest' Update in iPhone's History

Wednesday March 27, 2024 11:10 am PDT by
At least some Apple software engineers continue to believe that iOS 18 will be the "biggest" update in the iPhone's history, according to Bloomberg's Mark Gurman. Below, we recap rumored features and changes for the iPhone. "The iOS 18 update is expected to be the most ambitious overhaul of the iPhone's software in its history, according to people working on the upgrade," wrote Gurman, in a r...
maxresdefault

Apple Announces WWDC 2024 Event for June 10 to 14

Tuesday March 26, 2024 10:02 am PDT by
Apple today announced that its 35th annual Worldwide Developers Conference is set to take place from Monday, June 10 to Friday, June 14. As with WWDC events since 2020, WWDC 2024 will be an online event that is open to all developers at no cost. Subscribe to the MacRumors YouTube channel for more videos. WWDC 2024 will include online sessions and labs so that developers can learn about new...
apple maps 3d feature

Apple Maps May Gain Custom Routes With iOS 18

Tuesday March 26, 2024 3:10 pm PDT by
Apple may be planning to add support for "custom routes" in Apple Maps in iOS 18, according to code reviewed by MacRumors. Apple Maps does not currently offer a way to input self-selected routes, with Maps users limited to Apple's pre-selected options, but that may change in iOS 18. Apple has pushed an iOS 18 file to its maps backend labeled "CustomRouteCreation." While not much is revealed...
General iOS 17 Feature Orange Purple

Apple Releases Revised Versions of iOS 17.4.1 and iPadOS 17.4.1 With Updated Build Number

Wednesday March 27, 2024 5:59 am PDT by
Apple on late Tuesday released revised versions of iOS 17.4.1 and iPadOS 17.4.1 with an updated build number of 21E237, according to MacRumors contributor Aaron Perris. The updates previously had a build number of 21E236. The revised updates are available for all iPhone and iPad models that are compatible with iOS 17 and iPadOS 17, but they can only be installed via the Finder app on macOS...
applephilschiller

Apple's Phil Schiller Works 80 Hours a Week Overseeing App Store

Wednesday March 27, 2024 2:03 pm PDT by
With the App Store and app ecosystem undergoing major changes in the European Union, The Wall Street Journal today shared a profile on App Store chief Phil Schiller, who is responsible for the App Store. Though Schiller transitioned from marketing chief to "Apple Fellow" in 2020 to take a step back from Apple and spend more time on personal projects and friends, he is reportedly working...