Q Link Wireless made private customer information accessible with just a phone number


A mobile carrier allowed anyone with one of its customers phone numbers to access their personal information, including name, address, phone number, and text and call history, according to a report by Ars Technica. The carrier, Q Link Wireless, claimed to have over two million customers in 2019.
Ars Technica noted a Reddit post saying that the app used by the carrier and its subsidiary Hello Mobile never asked for a password or any identifying information when the user was logging on with a phone number. Looking through the reviews, there are references to the poor security practices (to put it mildly) going back to December of 2020. While it’s unclear when the credential-less login system appeared, there is an update note from two years ago that mentions an “updated login process.”
The carrier has reportedly fixed the issue — though it seems it may have done so by just turning off logins to the app altogether. Before the change, Ars was able to see, but not change, a bevy of information from a Hello Mobile customer who volunteered their phone number, including their name, address, account number, email address, and which numbers they’d contacted or been contacted by. The last one is probably the most sensitive — while the contents of texts or phone calls weren’t shown, there’s still a lot of information that can be gleaned from knowing who you talked to and when you talked to them.
The app’s description mentions that it allows users to add more minutes or data to their plans, but it’s unclear if that required extra authentication. Regardless, there’s still a ton of information that was available to anyone able to get the phone number of one of Q Link Wireless’ customers. Reportedly, Q Link Wireless hasn’t notified its customers that their information had been accessible — which seems to be a worrying trend among companies that leak user data.
Ars found no evidence that the security vulnerability was widely exploited, but having to worry about others having access to a ton of their sensitive data isn’t something that anyone needs.
Q Link Wireless didn’t immediately reply to a request for comment.
A mobile carrier allowed anyone with one of its customers phone numbers to access their personal information, including name, address, phone number, and text and call history, according to a report by Ars Technica. The carrier, Q Link Wireless, claimed to have over two million customers in 2019. Ars Technica…
Recent Posts
- The hidden costs of data subject access requests (DSARs) on privacy
- Amazon Alexa event live – latest news and rumors ahead of devices and service announcements
- Everything new on Disney+ in March 2025: Marvel’s Daredevil: Born Again, Moana 2, Sadie Sink’s O’Dessa movie, and more
- The best Apple Watch in 2025
- Volvo ES90 will charge faster, drive farther than other Volvo EVs
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010