SEC filing: T-Mobile says a hacker stole the data of ~37M customers, including names, addresses, and phone numbers, but not passwords, SSNs, or credit cards
T-Mobile US Inc. said a hacker obtained data for 37 million customer accounts, though it didn't include payment card information or personal identifying numbers.
BloombergCatherine Larkin
Context & Ripple Effects
T-Mobile's latest disclosure follows a sequence of customer-data incidents: a 2019 breach affecting more than a million customers and the 2021 intrusion in which the company confirmed access to systems holding far more sensitive identity data. The current incident again centers on customer contact information, though the filing says passwords, Social Security numbers, and card data were not accessed.
The recurrence matters because it keeps T-Mobile's handling of subscriber data under scrutiny even as the sensitivity and scale of the disclosed records have varied across incidents.
First-order effects
The roughly 37 million affected T-Mobile accounts face exposure of names, addresses, and phone numbers, data that can be used to make unsolicited or impersonating communications more credible.
T-Mobile must again manage customer notification and the operational fallout of a breach disclosure, while emphasizing that passwords, Social Security numbers, and payment cards were not included.
Second-order effects
Repeated disclosures make prior T-Mobile customers harder to reassure: the 2021 breach involved reported access to phone numbers and identity records, increasing the importance of clear account-security communications around the new incident.
Wireless rivals can use reliability and trust in customer-data protection as a competitive contrast when T-Mobile's breach history becomes part of switching decisions.
Third-order effects
If recurring carrier breaches continue, protection of subscriber identity data becomes a durable competitive and operating requirement for wireless providers, rather than a one-time incident-response issue.
The pattern points toward customer contact data being treated as consequential breach material even when the affected records exclude credentials and financial identifiers.
The trend: Wireless carriers are facing a recurring trust challenge as breaches expose subscriber identity and contact data across multiple incidents.
New by @lorenzofb: T-Mobile says a hacker accessed the personal information of 37 million customers. — By our count, this is the eighth breach at T-Mobile since 2018. — More: https://techcrunch.com/...
While no credit card or passwords were stolen, the information taken can be compiled with other stolen or publicly available information and used by scammers to steal people's identities or money. https://www.cbsnews.com/...
If only they had security to match when it comes to protecting customer data. Breach after breach. Terrible! Who are they going to blame now? @ftc @FCC @doj enough putting a few dollar value in fines on customer data & privacy/hell that follows! https://www.cnet.com/... https://t…
Since 2018, T-Mobile has reported at least 3 data breaches - one impacting 2M customers, a second impacting more than 1M, and a third impacting 50M. And today it has announced yet another breach: https://www.t-mobile.com/...
In its press release, T-Mobile is seemingly trying to downplay the exposed data by noting that “basic customer information” is “widely available in marketing databases or directories.” It also notes that no passwords or financial information were at risk from this breach.
The attacker started stealing data using one of T-Mobile's APIs around November 25, 2022. T-Mobile detected the malicious activity on January 5, 2023, and cut off the threat actor's access to the API one day later.
“The hackers, according to T-Mobile, didn't breach any company system but rather abused an application programming interface, or API.” bet it was a stupid IDOR like /api/customer?id=100 , change integer value and there's the info lol anyone shocked? i'm not.. https://twitter.com/…
If you use T-Mobile or have friends/family with T-Mobile please remind them that this further increases their risk for SIM swapping, phishing, etc. Recommend folks w/ T-Mobile move away from SMS 2FA & toward at least app-based MFA if a match for their use case & threat model. htt…
T-Mobile's had a history of data breaches. Its 2021 breach exposed the data of roughly 76.6 million people and led to a several hundred million dollar settlement. The claiming period for that breach ends next week. https://www.cnet.com/...