HackingBrute ForceCustomer Data InvolvedCREDENTIALSPIIMediumContained
SPRINT CAPITAL CORPORATION
bd_ca7ba9f6530ec0a9 · schema v1 · pii pii-v1
Full breach record for SPRINT CAPITAL CORPORATION →Sprint Corporation (Boost Mobile) notified the New Hampshire Attorney General on May 9, 2019, of a security incident discovered on March 14, 2019. An unauthorized party used brute force attacks to access customer accounts on the Boost.com Guest Payment page. 25,909 customers were impacted, including 17 New Hampshire residents. Sprint blocked access, reset PINs, and implemented a permanent solution.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed25,909 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/sprint-20190513.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 13, 2019
- Raw hash
- 0a56ebb4c70258e74508bb17637c45a2933f315fcc0f5080f70c59a44ce5dd22
Reporting entity
- Name
- SPRINT CAPITAL CORPORATIONnorm: sprint capital
Victim entity
- Name
- SPRINT CAPITAL CORPORATIONnorm: sprint capital
Incident
- Discovered
- Mar 14, 2019
- Materiality determined
- —
- Notification sent
- May 9, 2019
- Affected individuals
- 25,909
- Data types
- CREDENTIALSPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1110 Brute Force
- Threat actor
- ExternalFinancial
Compliance
- Time to disclose
- 9 weeks(60 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.