:

VERIZON SENDS REFURBISHED PHONE WITH ACTIVE MDM, WIPES DATA REMOTELY

INDUSTRY DESK2 MIN READ
FRI, JUN 12, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

A Verizon customer received a refurbished device that still had Mobile Device Management (MDM) software active from its previous owner. Verizon subsequently deleted all data on the phone remotely without the new user's consent.

A Verizon customer discovered that a refurbished phone shipped to them contained active Mobile Device Management (MDM) software linked to the device's previous owner. The MDM system, typically used by enterprises to manage employee devices, remained fully operational when the customer received the phone. Without notifying the new user, Verizon remotely initiated a factory reset that deleted all data stored on the device. The action raised significant concerns about the carrier's refurbishment process and how it handles device preparation between users. MDM software allows administrators to monitor, control, and wipe devices remotely. The presence of active MDM from a previous owner on a device intended for retail sale represents a substantial security and privacy oversight. The software could have potentially granted the former owner or their organization continued access to the new user's data and device activity. The incident highlights gaps in Verizon's quality assurance procedures for refurbished devices. Proper refurbishment protocol should include complete removal of all previous ownership data, accounts, and management software before a device reaches a new customer. The carrier did not communicate the remote data deletion to the customer in advance, compounding the issue. Refurbished phones represent a significant market segment, offering cost savings to consumers while extending device lifecycles. However, the process requires meticulous attention to data security and user privacy. Carriers and retailers must ensure previous ownership artifacts—including MDM profiles, accounts, and organizational controls—are completely stripped before devices change hands. Verizon has not issued a public statement regarding the specific incident or whether this represents an isolated case or a broader systematic issue with its refurbishment procedures. The situation raises questions about industry standards for preparing used devices for new owners and whether current practices adequately protect customer data and privacy.

■ SOURCES

Ars Technica

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

A cross-site request forgery (CSRF) vulnerability in WordPress Core, dubbed 'Click2Shell,' enables attackers to execute PHP code on vulnerable servers. Technical details and working exploits are now public.

3H AGOSecurity Desk

The ShinyHunters extortion group took control of the dark web leak site belonging to the prolific Cl0p ransomware gang over the weekend. The attackers set an eight-figure extortion demand pegged at 2.333% of Cl0p's estimated net worth.

4H AGOSecurity Desk

The FBI's CJIS Security Policy v6.1 strengthens encryption requirements and vulnerability scanning mandates. Agencies must prepare for updated password, MFA, and identity verification standards ahead of compliance audits.

7H AGOSecurity Desk

New research reveals that digital watermarks intended to protect content ownership are being repurposed as surveillance mechanisms to track user behavior and identify individuals across platforms.

7H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.