/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

SEC filing: T-Mobile says a hacker stole the data of ~37M customers, including names, addresses, and phone numbers, but not passwords, SSNs, or credit cards

here's what to do if you're ever worried that your data was leaked Chris Velazco / Washington Post : Here's what to do if you think you're affected by T-Mobile's latest data breach Lorenzo Franceschi-Bicchierai / TechCrunch : T-Mobile says hacker accessed personal data of 37 million customers Jenn Gidman / Newser : Another ‘Malicious Intruder’ Strikes T-Mobile Becky Bracken / Dark Reading : T-Mobile Breached Again, This Time Exposing 37M Customers' Data Frank Bajak / Associated Press : T-Mobile says data on 37 million customers stolen Nathan Wasson / HotHardware : T-Mobile Discloses Startling Security Breach Exposing Private Data Of 37M Customers Derrek Lee / Android Central : T-Mobile suffers yet another massive data breach affecting 37 million accounts Timi Cantisano / XDA Developers : T-Mobile suffered another massive data breach that compromised 37 million accounts Devika Rao / The Week : T-Mobile data breach compromised 37 million users' information Lauren Leffer / Gizmodo : Hackers Stole Data on 37 Million T-Mobile Customers Deeba Ahmed / HackRead : T-Mobile Hacked Again: 37 Million Accounts Compromised Andrew Greene / Toilet Read : I Hacked T-Mobile  —  Yesterday I hacked T-Mobile and gained access to the personal information of 37 million customers. Tim / Droid Life : T-Mobile Announces Another Data Breach, Affects Nearly 40 Million Accounts National Cybersecurity Alliance : T-Mobile January 2023 Data Breach Announcement: What You Should Do Shawn Knight / TechSpot : Latest T-Mobile data breach impacts 37 million customers Wyatte Grantham-Philips / USA Today : In latest T-Mobile hack, 37 million customers have personal data stolen, company says Sead Fadilpašić / TechRadar : Millions of T-Mobile customers have data stolen in breach Graham Cluley : T-Mobile has been hacked... again. 37 million customers' data stolen Karandeep Singh / Android Police : T-Mobile just suffered its second massive data breach in two years Alexander Martin / The Record : T-Mobile confirms another data breach affecting 37 million customer accounts Julia Shapero / The Hill : T-Mobile says hacker stole data on 37 million customers Shraddha Goled / TechCircle : Personal data of 37 million T-Mobile customers hacked in a new cyber attack Muhammad Qasim / Appuals.com : T-Mobile Affected By a Massive Data Breach, With 37 Million Accounts Compromised Tweets: @lorenzofb : NEW: T-Mobile got hacked, again. It's the eight time since 2018. https://techcrunch.com/... https://twitter.com/... Molly Wood / @mollywood : I honestly don't understand why T-Mobile is still allowed to operate. This company gets broken into CONSTANTLY. https://www.bloomberg.com/... Molly Wood / @mollywood : *Five times in four years* as of 2021, when it lost data including SSNs on 48 million people. https://www.newsweek.com/... Marsha Collier / @marshacollier : T-Mobile Suffers ANOTHER DATA BREACH, Affecting 37 Million Accounts ☠️ The carrier says a “bad actor” has accessed data from “approximately 37 million current postpaid and prepaid customer accounts.” #cybersecurity https://www.cnet.com/... https://twitter.com/... Karl Bode / @karlbode : hey this is crazy but what if we passed privacy legislation for the internet era that meaningfully held giant corporations accountable for repeatedly over-collecting consumer data then repeatedly failing to secure it https://twitter.com/... Jacob Silverman / @silvermanjacob : “This is the eighth time T-Mobile was hacked since 2018.” https://techcrunch.com/... @cbsmiami : While no credit card or passwords were stolen, the information taken can be compiled with other stolen or publicly available information and used by scammers to steal people's identities or money. https://www.cbsnews.com/... @om : If only they had security to match when it comes to protecting customer data. Breach after breach. Terrible! Who are they going to blame now? @ftc @FCC @doj enough putting a few dollar value in fines on customer data & privacy/hell that follows! https://www.cnet.com/... https://twitter.com/... @j0hnnyxm4s : For those who are extremely bad at math, that's just around TWICE A YEAR. https://twitter.com/... @zseano : “The hackers, according to T-Mobile, didn't breach any company system but rather abused an application programming interface, or API.” bet it was a stupid IDOR like /api/customer?id=100 , change integer value and there's the info lol anyone shocked? i'm not.. https://twitter.com/... Rachel Tobac / @racheltobac : If you use T-Mobile or have friends/family with T-Mobile please remind them that this further increases their risk for SIM swapping, phishing, etc. Recommend folks w/ T-Mobile move away from SMS 2FA & toward at least app-based MFA if a match for their use case & threat model. https://twitter.com/... @bleepincomputer : The attacker started stealing data using one of T-Mobile's APIs around November 25, 2022. T-Mobile detected the malicious activity on January 5, 2023, and cut off the threat actor's access to the API one day later. @blaw : The company alerted law enforcement and has begun notifying customers whose information may have been accessed. https://blawgo.com/DNkN5eM Eli Blumenthal / @eliblumenthal : T-Mobile's had a history of data breaches. Its 2021 breach exposed the data of roughly 76.6 million people and led to a several hundred million dollar settlement. The claiming period for that breach ends next week. https://www.cnet.com/... Eli Blumenthal / @eliblumenthal : In its press release, T-Mobile is seemingly trying to downplay the exposed data by noting that “basic customer information” is “widely available in marketing databases or directories.” It also notes that no passwords or financial information were at risk from this breach. Rob Pegoraro / @robpegoraro : How many telecom-firm data breaches will it take for telecom firms to get the importance of data minimization? https://twitter.com/... Steve Kopack / @stevekopack : Since 2018, T-Mobile has reported at least 3 data breaches - one impacting 2M customers, a second impacting more than 1M, and a third impacting 50M. And today it has announced yet another breach: https://www.t-mobile.com/...

Bloomberg Catherine Larkin

Context & Ripple Effects

T-Mobile had already disclosed a 2019 customer-data breach affecting more than one million people and a 2021 attack involving current, former, and prospective customers. The newly reported incident adds another large exposure of subscriber identity and contact data, even though T-Mobile says passwords, Social Security numbers, and payment-card data were not taken.

The related coverage also records AT&T notifying consumers after phone records for nearly all of its cellular and landline customers were stolen, placing T-Mobile’s disclosure within a broader run of major carrier data-security incidents.

First-order effects

  • About 37 million T-Mobile customers have names, addresses, and phone numbers exposed, while T-Mobile says password, Social Security number, and credit-card data were not included.
  • T-Mobile’s latest filing renews the company’s immediate security and customer-communication burden after its earlier disclosed breaches.

Second-order effects

  • Recurring disclosures at T-Mobile make subscriber-data protection a more visible point of comparison for competing carriers, particularly as AT&T separately handles its own large-scale breach notification.
  • The exposure of contact details gives customers a reason to treat communications associated with their carrier accounts more cautiously, even absent stolen passwords or payment data.

Third-order effects

  • If repeated carrier breaches continue, telecom providers will be judged less on whether an individual incident includes financial credentials and more on their ability to safeguard the basic identity and contact data held at national scale.
  • The paired T-Mobile and AT&T disclosures point toward data-security resilience becoming a persistent competitive and accountability issue for consumer telecom operators.

The trend: Major telecom breaches are making protection of subscriber identity, contact, and communications data a recurring industry accountability test.

Discussion

  • @lorenzofb @lorenzofb on x
    NEW: T-Mobile got hacked, again. It's the eight time since 2018. https://techcrunch.com/... https://twitter.com/...
  • @mollywood Molly Wood on x
    I honestly don't understand why T-Mobile is still allowed to operate. This company gets broken into CONSTANTLY. https://www.bloomberg.com/...
  • @mollywood Molly Wood on x
    *Five times in four years* as of 2021, when it lost data including SSNs on 48 million people. https://www.newsweek.com/...
  • @marshacollier Marsha Collier on x
    T-Mobile Suffers ANOTHER DATA BREACH, Affecting 37 Million Accounts ☠️ The carrier says a “bad actor” has accessed data from “approximately 37 million current postpaid and prepaid customer accounts.” #cybersecurity https://www.cnet.com/... https://twitter.com/...
  • @karlbode Karl Bode on x
    hey this is crazy but what if we passed privacy legislation for the internet era that meaningfully held giant corporations accountable for repeatedly over-collecting consumer data then repeatedly failing to secure it https://twitter.com/...
  • @silvermanjacob Jacob Silverman on x
    “This is the eighth time T-Mobile was hacked since 2018.” https://techcrunch.com/...
  • @cbsmiami @cbsmiami on x
    While no credit card or passwords were stolen, the information taken can be compiled with other stolen or publicly available information and used by scammers to steal people's identities or money. https://www.cbsnews.com/...
  • @om @om on x
    If only they had security to match when it comes to protecting customer data. Breach after breach. Terrible! Who are they going to blame now? @ftc @FCC @doj enough putting a few dollar value in fines on customer data & privacy/hell that follows! https://www.cnet.com/... https://t…
  • @j0hnnyxm4s @j0hnnyxm4s on x
    For those who are extremely bad at math, that's just around TWICE A YEAR. https://twitter.com/...
  • @zseano @zseano on x
    “The hackers, according to T-Mobile, didn't breach any company system but rather abused an application programming interface, or API.” bet it was a stupid IDOR like /api/customer?id=100 , change integer value and there's the info lol anyone shocked? i'm not.. https://twitter.com/…
  • @racheltobac Rachel Tobac on x
    If you use T-Mobile or have friends/family with T-Mobile please remind them that this further increases their risk for SIM swapping, phishing, etc. Recommend folks w/ T-Mobile move away from SMS 2FA & toward at least app-based MFA if a match for their use case & threat model. htt…
  • @bleepincomputer @bleepincomputer on x
    The attacker started stealing data using one of T-Mobile's APIs around November 25, 2022. T-Mobile detected the malicious activity on January 5, 2023, and cut off the threat actor's access to the API one day later.
  • @blaw @blaw on x
    The company alerted law enforcement and has begun notifying customers whose information may have been accessed. https://blawgo.com/DNkN5eM
  • @eliblumenthal Eli Blumenthal on x
    T-Mobile's had a history of data breaches. Its 2021 breach exposed the data of roughly 76.6 million people and led to a several hundred million dollar settlement. The claiming period for that breach ends next week. https://www.cnet.com/...
  • @eliblumenthal Eli Blumenthal on x
    In its press release, T-Mobile is seemingly trying to downplay the exposed data by noting that “basic customer information” is “widely available in marketing databases or directories.” It also notes that no passwords or financial information were at risk from this breach.
  • @robpegoraro Rob Pegoraro on x
    How many telecom-firm data breaches will it take for telecom firms to get the importance of data minimization? https://twitter.com/...