Technology moves fast. Context matters. Independent by design ↗

Find your next rabbit hole.

Explore the collection, or type to search.

ExplainerYahoo closes GeoCities: how the web lost millions of home pagesYahoo bought GeoCities for billions in 1999 and switched it off a decade later. The closure became a turning point for web preservation.ExplainerThe Storm worm: the botnet that started with a weather headlineIn January 2007 an email about deadly storms in Europe spread a Trojan that built one of the largest peer-to-peer botnets of its time.ExplainerGPLv3: how the free software licence was rewrittenAfter 18 months of public drafting, the Free Software Foundation published version 3 of the GNU General Public License in June 2007.ExplainerThe UK identity card scheme: from Act of Parliament to shredded registerBritain legislated for national ID cards backed by a central biometric register, then abolished the whole scheme within five years.ExplainerThe netbook era: small, cheap laptops that briefly drove PC growthThe Asus Eee PC started a boom in low-cost mini laptops that propped up PC sales, until tablets and thinner laptops took their place.

Press Esc to close

2005 · Security

The 2005 Sidekick hack: a celebrity phone breach and online account security

Last reviewed 5 October 2026

In February 2005 the address book and notes from Paris Hilton’s T-Mobile Sidekick appeared online. The breach showed how weak account recovery could expose data synced to the cloud.

What happened

The T-Mobile Sidekick, made by Danger, was one of the first popular phones to keep its contacts, notes and photos on the operator’s servers and sync them automatically. Owners could also see and edit that data through a T-Mobile website.

In February 2005 the contents of Paris Hilton’s Sidekick, including the phone numbers of other well-known people, were posted on the web. The story spread around the world within hours, and many of the people whose numbers were exposed had to change them.

How it was done

Investigators and security researchers concluded that the intruders had not broken the phone itself. The most widely reported explanation was that they got into the online account, either by abusing a weakness in T-Mobile’s website or by resetting the password through a security question whose answer could be found from public information, such as a pet’s name. Reports also described phone calls in which the attackers persuaded staff to hand over information, a technique known as social engineering.

A Massachusetts teenager was later sentenced in a juvenile court for a series of computer intrusions that included T-Mobile systems. The case came shortly after a separate, unrelated breach of T-Mobile’s systems by another hacker was revealed in 2004.

Why it mattered

The case was one of the first times the public saw that a phone’s data now lived somewhere else, and that the security of that data depended on the weakest way into the account. Security questions in particular were exposed as a poor safeguard, because the answers are often public. The same weakness was used in 2008 to break into a US politician’s webmail account.

The lessons are still taught today: use unique passwords, treat security-question answers as extra passwords rather than real facts, and turn on two-step verification. Many later celebrity account breaches followed the same pattern of guessed or reset credentials rather than technical attacks on devices.

Sources

  • Wikipedia: Danger Hiptop (T-Mobile Sidekick)
  • Brian Krebs, reporting on the Sidekick breach investigation, The Washington Post, 2005
  • US Attorney’s Office, District of Massachusetts, statement on a juvenile computer intrusion case, September 2005

More on Security