Technology

Virgin Mobile Users Vulnerable to Account Hijacking

Virgin Mobile Users Vulnerable to Account Hijacking

Six million Virgin Mobile USA subscribers were living behind a password that a laptop could guess in a day — and the man who proved it had to go public before the company would listen.

Kevin Burke, a Texas software developer (then at Twilio), disclosed this week that Virgin Mobile's online portal authenticated customers with just two things: their phone number and a 6-digit PIN. There was no meaningful lockout — Burke tried 100 bad logins in a row, then logged in fine with the right one, and found the supposed four-attempt freeze could be bypassed by clearing cookies or simply not using a mainstream browser. "It is trivial to write a program that checks all million possible password combinations, easily determining anyone's PIN inside of one day," he wrote, after brute-forcing his own account to prove it.

Once inside an account, an attacker could read call and SMS logs, change the handset linked to the number, change the email and mailing address, lock the real owner out, and spend against the credit card on file.

Burke said he had first warned the company on August 15 and exchanged calls and emails with parent company Sprint for a month. On September 14, he was told no further action was planned. So he published — and only then did Sprint respond, saying it appreciated his outreach and that accounts were monitored for illegal activity. Within days, the company added a lockout after four failed attempts and promised unusual-activity monitoring.

The episode was a small classic of security disclosure: a researcher does the company's homework, gets ignored, goes public, and only then does the fix ship. For the six million subscribers, the lesson landed anyway — the difference between a phone number and a password is that everyone already knows your phone number.

Kevin BurkeVirgin MobilesecuritySprint

Related Stories