FeedExploreAsk AIAlertsSavedProfile

Categories

AICybersecurityInfrastructureDatabaseTech Updates

Tech news that matters.

FeedExploreAskAlertsSavedProfile
Back to feed
Cybersecurity·High

Verizon Sent a Phone It Could Still Control

An IT professional holds a smartphone while examining a device management interface on a laptop in an office.

TL;DR: Verizon sent a customer a refurbished phone with its Mobile Device Management (MDM) software still active. The company then used its remote access to completely wipe the customer's data, highlighting serious device management risks.

By Neeraj Dhiman·3h ago·2 min read·updated 59m ago
Source

Key facts

Category
Cybersecurity
Impact
High
Published
3h ago
Source
Ars Technica

Full summary

Verizon sent a customer a refurbished phone with its device management software still active, then used it to remotely wipe his data.

A Verizon customer received a refurbished phone that was still under the company's complete control. After reporting network issues, the customer was sent a replacement device that contained an active Mobile Device Management (MDM) profile. This software, typically used to manage corporate devices, gave Verizon the ability to remotely access and administer the phone. When the customer continued to experience problems, a support agent used this MDM access to perform a factory reset, deleting all of the user's personal data. The incident revealed a critical flaw in how the carrier prepares its refurbished devices for new users. Verizon essentially gave a customer a phone that it still treated as a corporate asset, leading to a significant privacy and data security failure.

This case is a stark warning for IT and security teams about the risks of improper device lifecycle management. When a device is decommissioned, returned, or prepared for reuse, it must be thoroughly wiped of all previous configurations, including MDM profiles. Failure to do so can leave backdoors open, allowing for unauthorized remote access and data destruction, as seen here. The incident underscores the importance of having robust, verifiable protocols for device sanitization. For any organization that manages a fleet of devices, this serves as a critical reminder to review and enforce policies for wiping and reprovisioning hardware. The fact that a major carrier like Verizon could make such a fundamental error shows that no organization is immune to these process failures.

The event also raises broader questions about consumer trust and the refurbished device market. Customers expect a refurbished product to be functionally equivalent to a new one, which includes being free from any prior ownership or administrative control. When a company retains a master key to a device sold to a customer, it fundamentally breaks that trust. This incident highlights the need for greater transparency and stricter standards in the refurbishment industry. For businesses, it reinforces the principle that device management policies are not just an internal IT concern; they have direct consequences for customer data, privacy, and brand reputation. Auditing these processes regularly is essential to prevent similar costly mistakes.

Why it matters

This incident is a critical case study for IT and security teams on the importance of robust device lifecycle management. It demonstrates how failure to properly wipe a device before reissue can lead to major data security and privacy violations, even by a major corporation.

Business impact

Improper device decommissioning protocols can lead to severe data breaches, loss of customer trust, and significant brand damage. This event highlights the financial and reputational risks of inadequate IT asset management, serving as a warning to all companies that handle corporate or refurbished devices.

Tags

#device security#verizon#data privacy#it management#mdm

Related on Notifire

  • ResearchKubernetes security
  • ResearchSupply-chain security
  • ResearchCritical CVEs of 2026
  • CompareSSO vs SCIM

✦ Notifire newsletter

Get more Cybersecurity intelligence

Join engineers getting Notifire’s verified tech briefings — short, sourced, and free. No spam, unsubscribe anytime.

The day's most important tech briefings. No spam, unsubscribe anytime.

Related stories

Primary source: Ars Technica

Tech intelligence for engineering teams

Short, verified briefings on AI, cybersecurity, infrastructure, and data — with the analysis and action steps that matter. Every briefing is sourced, fact-checked, and bylined to a named editor.

[email protected]Story tips & corrections welcomeHow we report →

The Notifire briefing

Verified tech intelligence in your inbox — AI, security, infra, and data.

The day's most important tech briefings. No spam, unsubscribe anytime.

Sections

  • AI
  • Cybersecurity
  • Infrastructure
  • Database
  • Tech Updates
  • Web3 & Chains

Newsroom

  • About Notifire
  • Editorial team
  • Editorial standards
  • Methodology
  • AI disclosure
  • Corrections

Resources

  • Explore
  • Research hubs
  • Comparisons
  • Tech glossary
  • FAQ
  • Alerts & watchlists

Follow

  • RSS feed
© 2026 NotifirePrivacyTermsCorrections
An independent, AI-assisted publication. Built at </Alpheric>
IntelligenceLive panel
Live

Top trending

Last 24h

    Popular tags

    Add to watchlist

    +OpenAI+Claude+PostgreSQL+Kubernetes+Cloudflare+AWS+CVE Critical

    Notifire score

    0–100 priority signal — combines impact, freshness, trending velocity, and source credibility.

  1. Atom feed
  2. LinkedIn
  3. X / Twitter
  4. Facebook
  5. Instagram
  6. YouTube