Leaked chat logs: Lapsus$ hacked T-Mobile multiple times in March and stole some projects' source code; T-Mobile says no customer or government info was stolen
Context & Ripple Effects
T-Mobile's assurance that this intrusion did not involve customer or government information narrows the immediate exposure, but it arrives days after court documents described a failed effort to halt sales of data from 30M customers. The company had also disclosed earlier breaches involving roughly 2M accounts and was investigating claims tied to more than 100M people in 2021.
The stolen project code adds a different security concern to that record: proprietary software, rather than account records, is now part of the attack surface. A later filing on data affecting about 37M customers shows that the company's security disclosures continued beyond this incident.
First-order effects
- T-Mobile must evaluate the affected projects for code exposure and secure any systems or development processes that the stolen material could reveal.
- Lapsus$ gains proprietary project material, while T-Mobile's stated absence of customer and government data limits the incident's immediately disclosed data scope.
Second-order effects
- The source-code theft raises the value of T-Mobile's internal development environment as a target, alongside the customer-data repositories implicated in its earlier incidents.
- T-Mobile's prior payment to stop a leak, which the hackers continued selling, weakens any assumption that containment through a third party ends an attacker-controlled disclosure.
Third-order effects
- Repeated disclosures spanning account data, large claimed datasets, and project source code point to a security challenge that reaches across T-Mobile's distinct information systems rather than a single exposed database.
- If such incidents persist, telecom security assessments will increasingly turn on protection of software-development systems as well as the handling of subscriber records.
The trend: Telecom breach risk is broadening from customer-record theft to attacks on the software and internal systems that support network services.