I'm not assuming anything, I'm pointing out a failure of self-regulation given the TTPs listed in the original article, which are distinct from fully insider-supported attacks, should not happen.
There is obvious, direct, and destructive customer impact here.
Edit: actually I know people working in security roles for T-Mobile, and I am sure they or their sister teams are trying.
There is obvious, direct, and destructive customer impact here.
Edit: actually I know people working in security roles for T-Mobile, and I am sure they or their sister teams are trying.