What we found
AT&T: FFor $300, a bounty hunter could find the real-time location of any AT&T phone in America.
In 2019, Motherboard/Vice revealed that AT&T was selling real-time customer location data through a chain of intermediaries that ended up in the hands of bounty hunters and stalkers. For as little as $300, anyone could locate any AT&T phone in America. A reporter paid a bounty hunter who found a phone's location within minutes. AT&T had promised the FCC in 2018 it would stop — then kept doing it.
Telstra: FTelstra Health managed parts of Australia's My Health Record system.
In 2022, the OAIC investigated Telstra Health (formerly Argus) after it was revealed the subsidiary had shared My Health Record data with law enforcement without proper authorisation. The OAIC found failures in data handling practices for one of Australia's most sensitive health databases.
Verizon: DVerizon bought Yahoo knowing it had been hacked — all 3 billion accounts compromised.
Verizon acquired Yahoo knowing about two massive breaches (2013-2014) affecting all 3 billion Yahoo accounts. Despite this, Verizon only negotiated a $350 million discount rather than walking away. Yahoo had also secretly built a custom email-scanning tool for US intelligence agencies to search all incoming emails in real time. Verizon inherited both the compromised user base and the surveillance infrastructure.
T-Mobile: DNine breaches.
T-Mobile has been breached at least 9 times since 2018 -- the most serially breached major company in America. August 2021: 77 million customers' data exposed, including Social Security numbers, driver's license numbers, names, addresses, and dates of birth. January 2023: 37 million customers' names, addresses, and phone numbers stolen through an exploited API for over two months before detection. Additional incidents in 2018, 2019, 2020, 2022, and 2023. The $350 million class action settlement (2022) was the direct result of the 2021 breach. T-Mobile's CEO apologised after each breach, promised to invest in security, and was breached again. Nine breaches in six years. Each time, "we take security seriously." Each time, another breach. The Un-carrier treats customer data like a revolving door.
Optus: DOptus called it a "sophisticated cyberattack." Security researchers called it an open door.
Security researchers who examined the breach quickly determined it was caused by an unsecured API endpoint that required no authentication. The API was publicly accessible on the internet -- no password, no token, no authentication of any kind. Attackers could query the API and receive customer records including passport numbers, driver's licence numbers, Medicare numbers, dates of birth, home addresses, and email addresses for 9.8 million current and former customers. The alleged attacker was reported to be a 19-year-old in Sydney. There was nothing sophisticated about the attack. Optus left a door open on the internet with no lock, and someone walked through it. Calling an unsecured API a "sophisticated cyberattack" was a public relations strategy, not a technical assessment. The Australian government was so outraged by the breach that it passed the Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022, increasing maximum penalties from $2.2 million to $50 million.
Vodafone AU: DVodafone's own 2014 transparency report admitted something extraordinary: in some countries, governments have secret direct-access wires built into Vodafone'...
In 2014, Vodafone Group published a landmark disclosure revealing that in some countries where it operates, governments have direct-access pipes into its network infrastructure — allowing authorities to listen to calls and read messages without any warrant or request process. Vodafone confirmed secret wires exist in some of its networks that bypass all normal legal processes.