T-Mobile Confirms Data Breach, Unclear If Personal Customer Data Was Accessed

T-Mobile today confirmed that some of its data had been accessed without authorization in a breach that may impact more than 100 million of its users.

tmobilelogo
Over the weekend, T-Mobile began investigating a forum post that offered data from more than 100 million people. T-Mobile was not mentioned in that post, but the person selling the data told Motherboard that it had come from T-Mobile's servers, thus leading T-Mobile to look into it. The hacker who spoke to Motherboard claimed that several T-Mobile servers had been breached.

T-Mobile has now confirmed that there was indeed unauthorized access to some customer data, but T-Mobile in a statement says it does not yet know if personal customer data has been accessed.

We have been working around the clock to investigate claims being made that T-Mobile data may have been illegally accessed. We take the protection of our customers very seriously and we are conducting an extensive analysis alongside digital forensic experts to understand the validity of these claims, and we are coordinating with law enforcement.

We have determined that unauthorized access to some T-Mobile data occurred, however we have not yet determined that there is any personal customer data involved. We are confident that the entry point used to gain access has been closed, and we are continuing our deep technical review of the situation across our systems to identify the nature of any data that was illegally accessed. This investigation will take some time but we are working with the highest degree of urgency. Until we have completed this assessment we cannot confirm the reported number of records affected or the validity of statements made by others.

We understand that customers will have questions and concerns, and resolving those is critically important to us. Once we have a more complete and verified understanding of what occurred, we will proactively communicate with our customers and other stakeholders.

According to the original forum post, the data for sale includes social security numbers, phone numbers, names, physical addresses, IMEI numbers, and driver licenses information. Motherboard said that it was provided with some samples of data and was able to confirm that they contained accurate information on T-Mobile customers.

T-Mobile says that the entry point used to gain access to the data has been closed, and it is now conducting a "deep technical review" of the situation to determine the nature of the data that was obtained. The company will not be able to confirm the reported number of records affected until the internal investigation is complete, and it plans to proactively communicate with customers when the information is available.

Popular Stories

sonny iphone 16 pro colors

All Four iPhone 16 Pro Colors Revealed in New Image

Friday August 16, 2024 4:14 am PDT by
Leaker Sonny Dickson is back today with a new dummy unit image showing all four iPhone 16 Pro color variants, including the rose gold or "bronze" unit that replaces Blue Titanium in the existing iPhone 15 Pro models. The iPhone 16 Pro models are expected to come in black, white or silver, gray or "Natural Titanium," and a rose or rose gold color replacing Blue Titanium, according to Apple...
iPhone 16 Pro Right Side Feature

The iPhone 16 is Getting a New Button: Here's What It Can Do

Tuesday August 13, 2024 4:01 pm PDT by
Multiple rumors have suggested that the iPhone 16 models are going to have an all-new button that's designed to make it easier to capture photos when the devices are held in landscape mode. Apple calls the button the Capture Button internally, and it is going to be one of the most advanced buttons that's been introduced to date with support for multiple gestures and the ability to respond to ...
iPhone 16 Pro Sizes Feature

iPhone 16 Launch Is Just One Month Out – Here's Everything We Know

Saturday August 10, 2024 5:00 am PDT by
Apple typically releases its new iPhone series in the fall, and a possible September 10 announcement date has been floated this year, which means we are just one month away from the launch of the iPhone 16. Like the iPhone 15 series, this year's lineup is expected to stick with four models – iPhone 16, iPhone 16 Plus, iPhone 16 Pro, and iPhone 16 Pro Max – although there are plenty of design...
iPhone 16 Pro Sizes Feature

When Is the iPhone 16 Coming Out?

Wednesday August 14, 2024 6:20 am PDT by
Apple's iPhone 16 series is expected to debut in September 2024. This release follows Apple's trend of introducing new iPhone models annually in the fall. While the exact date has yet to be officially confirmed, the day of Tuesday, September 10 has been rumored as a possible announcement date, and September has traditionally been the month when Apple unveils its latest smartphone innovations. ...
maxresdefault

Apple Aiming to Launch Tabletop Robotic Home Device as Soon as 2026 With Pricing Around $1,000

Wednesday August 14, 2024 11:30 am PDT by
Apple is moving forward with its project to develop a tabletop robotic device, according to Bloomberg's Mark Gurman. Subscribe to the MacRumors YouTube channel for more videos. The device would feature a large iPad-like display mounted on a "thin robotic arm" that would allow the display to tilt and up and down and rotate a full 360º, and it would serve as a "smart home command center," a...
M4 Mac mini Silver Ortho Cooler

These New Macs Are Coming in 2024

Thursday August 15, 2024 4:34 pm PDT by
It's almost September, but Apple still has multiple new product launches planned for 2024. New iPhone 16 models and Apple Watches are coming in September, and we're also going to get at least three Mac updates with M4 chips this year, according to rumors. Here's what's on the horizon. MacBook Pro Apple plans to refresh both the 14-inch and 16-inch MacBook Pro models, adding M4 chips. The ...
T Mobile Generic Feature Pink 1

United States Fines T-Mobile $60 Million for Failing to Prevent Unauthorized Access to Sensitive Customer Data

Thursday August 15, 2024 1:32 pm PDT by
T-Mobile was fined $60 million by the Committee on Foreign Investment in the US (CFIUS) for negligence surrounding data breaches, reports Reuters. CFIUS penalized T-Mobile for failing to prevent or disclose unauthorized access to sensitive customer data. When T-Mobile merged with Sprint, it signed a national security agreement with CFIUS, which is what led to the fine earlier this year....

Top Rated Comments

LawJolla Avatar
39 months ago
I own a small car dealership and I encrypt all of my customer's data at rest. I could hand my database to a hacker with next to nothing compromised. You'd need to dump my database and steal the secret in memory key.

In 2021 these billion dollar companies need to be held accountable. Unacceptable.
Score: 65 Votes (Like | Disagree)
lip008 Avatar
39 months ago
Anytime I've had to go into Sprint or T-Mobile they required a scan of my driver's license. It's been a pita to access the account or go into the store for a while now all in the name of security! Guess that was all for nothing! Status quo....we'll get 18 months of credit monitoring and $8 from the lawsuit outcome in 2025...
Score: 23 Votes (Like | Disagree)
Wags Avatar
39 months ago
Companies should be fined heavily for stuff like this. Many don’t invest enough resources to be responsible but not enough public outrage. Will be no news by tomorrow.
Score: 20 Votes (Like | Disagree)
Graphikos Avatar
39 months ago

I own a small car dealership and I encrypt all of my customer's data at rest. I could hand my database to a hacker with next to nothing compromised. You'd need to dump my database and steal the secret in memory key.

In 2021 these companies need to be held accountable. Unacceptable.
That all sounds nice in theory but as we know nothing is ever 100% secure. For a small business, you can more easily lock things down and restrict access. When you talk about large corporations with so many different facets and functions it becomes much harder to grant access to those who need it, trust everyone that is involved, and keep hardware and software secure. There are just so many more variables that you really can't compare.
Score: 17 Votes (Like | Disagree)
SFjohn Avatar
39 months ago
That’s totally unacceptable in this day and age. As a T-mobile customer for years now, this is really bad. Social Security numbers, phone numbers, names, physical addresses, IMEI numbers, and driver licenses information! What else? Mother’s Maiden Name? T-Mobile needs to pay for a lifetime of fraud monitoring on every account stolen!
Score: 14 Votes (Like | Disagree)
ouimetnick Avatar
39 months ago
? I switched from AT&T to T-Mobile this past May…. ??
Score: 12 Votes (Like | Disagree)