When a telco billing API leaks subscriber data

A telco’s billing systems hold the names, plans, balances and personal details of its subscribers. If the billing API does not check who is asking, one customer can read another customer’s records. That is a data protection incident waiting to happen, with regulatory and reputational consequences.

What we found

OSS/BSS stands for operations support systems and business support systems. Together they run a telco’s network operations, customer accounts and billing. In this operator’s billing API, changing the accountId value in a request returned another subscriber’s plan, balance and personal data. This type of flaw is called an insecure direct object reference (IDOR), and it left a large number of subscriber accounts exposed.

The operator’s web application firewall (WAF) did not catch it. WAF rules look for attack patterns such as code injection, and this request looked perfectly normal. The flaw was in the business logic.

How we tested

Our testers checked authorization by hand, looking for BOLA (broken object-level authorization), IDOR and ways to bypass permission checks. Automated scanners give limited coverage in these areas. Each finding came with a proof of concept, a mapping to the OWASP API Security Top 10 and GDPR, and a recommended fix. Here the fix was a scoped authorization check that confirms the requester actually owns the account.

Leadership received a one-page risk summary in plain language. Developers received the technical detail they needed to make the change.

The fix and what followed

The operator shipped the fix promptly, and our retest confirmed the flaw was closed. It also added new rules to its WAF and API gateway, which are now tested every sprint through FOCTOS, a Snipeyes company. The engagement gave the operator audit evidence for ISO/IEC 27001 and for its data protection obligations.

The lesson for other operators

The scanner had rated this issue as merely informational. Its seriousness only became clear when a tester showed the actual subscriber data. Whenever an API returns customer records, include manual authorization testing in scope.