Image Credits:EE

UK phone giant EE fixes bug that let customers gift data for free

EE, the largest phone network in the UK, has fixed a website bug that allowed customers to add an unlimited amount of plan data to their accounts for free.

The bug allowed any customer to modify code on the customer’s account page that allows users to “gift” data to linked accounts.

Using man-in-the-middle tools like Burp Suite, it was possible to intercept the server request and swap out the recipient’s phone number with their own. By making the phone numbers the same, the system could be tricked into duplicating the data allowance without incurring any costs.

It was also possible to gift data to other connected accounts for free.

A pseudonymous security researcher who goes by The Infosec Spider contacted TechCrunch with details of the bug, which we reported to EE.

The company said in a statement that it fixed the bug within two days, and thanked the researcher.

“Our customer data was never at risk as users could only increase the data on their own plan, or another number associated with their account, after they successfully logged into their account,” said an EE spokesperson.

Techcrunch event

Disrupt 2026: The tech ecosystem, all in one room

Your next round. Your next hire. Your next breakout opportunity. Find it at TechCrunch Disrupt 2026, where 10,000+ founders, investors, and tech leaders gather for three days of 250+ tactical sessions, powerful introductions, and market-defining innovation. Register now to save up to $400.

Save up to $300 or 30% to TechCrunch Founder Summit

1,000+ founders and investors come together at TechCrunch Founder Summit 2026 for a full day focused on growth, execution, and real-world scaling. Learn from founders and investors who have shaped the industry. Connect with peers navigating similar growth stages. Walk away with tactics you can apply immediately

Offer ends March 13.

San Francisco, CA | October 13-15, 2026

But the researcher said that the bug could have been exploited to defraud the phone giant.

It’s the second bug affecting EE the security researcher found this year. In May, the researcher found a company code repository online with a default password. In a separate security incident, EE also exposed the private keys for its Amazon Web Services instances because of a flawed deployment of its Jira bug tracking system.

Topics

, , , , ,
Loading the next article
Error loading the next article