Millions of T-Mobile customers have data stolen in breach


T-Mobile has warned millions of its customers that a threat actor used an Application Programming Interface (API) to gain access to some of their sensitive data.
In a warning published on the company’s website, T-Mobile tried to play down the importance of the incident, saying some “basic customer information (nearly all of which is the type widely available in marketing databases or directories)” was obtained.
The data, however, includes people’s names, billing addresses, email addresses, phone numbers, dates of birth, and account numbers, all valuable information for identity theft (opens in new tab) attacks, phishing, and similar social engineering attacks.
Millions of victims
Passwords, payment card information, Social Security numbers, government ID numbers, as well as financial account information, remained safe, the company confirmed. It also said its investigation concluded that there was no evidence of a breach in its networks or systems.
While the warning does not say how many people were affected by the breach, and which account types were compromised, a total of 37 million customers had their data accessed, including both prepaid and postpaid customers.
The attack was taking place between November 25, 2022, and January 5, 2023. It was on January 6 that T-Mobile finally cut the threat actors’ access.
The company reported the attack to both law enforcement and federal agencies in the United States, whose investigation is now ongoing, it was said. T-Mobile also added that it started notifying customers who might have had their data compromised.
The German telecommunications giant’s track record for data breaches is far from ideal. The company’s had multiple incidents over the years, including one in 2018, one in 2019, and at least three in 2020. In 2021, it was found that the company paid hundreds of thousands of dollars to not have its sensitive data leaked to the web, which happened anyway, and a year later, in 2022, confirmed being targeted by the Lapsus$ extortion gang.
Via: BleepingComputer (opens in new tab)
Audio player loading… T-Mobile has warned millions of its customers that a threat actor used an Application Programming Interface (API) to gain access to some of their sensitive data. In a warning published on the company’s website, T-Mobile tried to play down the importance of the incident, saying some “basic…
Recent Posts
- Amazon CEO says ‘beautiful’ new Alexa hardware is coming this fall
- Apple will let parents share their kids’ ages to limit app access
- Perplexity’s voice mode gets a futuristic makeover on your iPhone
- Apple just expanded its child safety features with age ratings that could lessen the chance of an inappropriate download
- OpenAI announces GPT-4.5, warns it’s not a frontier AI model
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010