What happened
Syniverse routes more than 740 billion messages a year for over 300 mobile operators, including Verizon, T-Mobile and AT&T. On 5 October 2021 Ars Technica reported that a preliminary proxy statement, filed with the SEC on 27 September for its planned merger with a blank-check company, disclosed unauthorized access to its operational and IT systems.
The filing said Syniverse became aware of the access in May 2021 and that it had begun in May 2016. The intruder reached databases within its network on several occasions, and login information for its Electronic Data Transfer environment was compromised for about 235 customers. Syniverse notified law enforcement and affected customers where contractually required, reset or deactivated all EDT customer credentials, and said it saw no evidence of intent to disrupt or monetize.
Syniverse declined to say whether text messages were exposed, citing confidentiality and a pending law enforcement investigation. T-Mobile said it had no indication personal information, call records or message content were affected. Vice, citing a former employee and a carrier employee, reported that the EDT systems could hold call records and possibly message content, which Syniverse did not confirm.
Why it happened
The intruder stayed inside for roughly five years, so Syniverse's detection did not catch the 2016 intrusion until May 2021.
Credentials for the EDT environment, which carriers use to exchange billing and records data, were compromised for around 235 customers.
Syniverse is a hub for many carriers, so one breach touched numerous operators at once, as T-Mobile confirmed.
The lesson
An infrastructure vendor that hundreds of carriers depend on becomes a single point of failure. Five years of undetected access shows monitoring did not match the sensitivity of what it carried.
Aftermath
Syniverse said it implemented additional protective measures but did not describe them, and told the SEC it could not guarantee it would not uncover evidence of data exfiltration later. The disclosure came in a risk-factor section of a SPAC merger document. Ars also recalled an earlier lapse: a server failure on 14 February 2019 left more than 168,000 messages undelivered until November 2019. The article reports no fine or lawsuit.
FOLLOW THE EVIDENCE