By Matt O'Brien

The names, Social Security numbers and information from driver's licenses or other identification of just over 40 million people who applied for T-Mobile credit were exposed in a recent data breach, the company said Wednesday.

The same data for about 7.8 million current T-Mobile customers who pay monthly for phone service also appears to be compromised. No phone numbers, account numbers, PINs, passwords or financial information from the nearly 50 million records and accounts were compromised, it said.

T-Mobile has been hit before by data theft but in the most recent case, “the sheer numbers far exceed the previous breaches,” said Gartner analyst Paul Furtado.

T-Mobile, which is based in Bellevue, Washington, became one of the country’s largest cellphone service carriers, along with AT&T and Verizon, after buying rival Sprint.

“Yes, they have a big target on their back but that shouldn’t be a surprise to them,” Furtado said. “You have to start questioning the organization. How much are they actually addressing these breaches and the level of seriousness?”

T-Mobile also confirmed Wednesday that approximately 850,000 active T-Mobile prepaid customer names, phone numbers and account PINs were exposed. The company said that it proactively reset all of the PINs on those accounts. No Metro by T-Mobile, former Sprint prepaid, or Boost customers had their names or PINs exposed.

There was also some additional information from inactive prepaid accounts accessed through prepaid billing files. T-Mobile said that no customer financial information, credit card information, debit or other payment information or Social Security numbers were in the inactive file.

T-Mobile had said earlier this week that it was investigating a leak of its data after someone took to an online forum offering to sell the personal information of cellphone users.

The company said Monday that it had confirmed there was unauthorized access to “some T-Mobile data” and that it had closed the entry point used to gain access.

The company said that it will immediately offer two years of free identity protection services and is recommending that all of its postpaid customers — those who pay in monthly installments — change their PIN. Its investigation is ongoing.

T-Mobile has previously disclosed a number of data breaches over the years, most recently in January and before that in Nov. 2019 and Aug. 2018, all of which involved unauthorized access to customer information. It also disclosed a breach affecting its own employees' email accounts in 2020. And in 2015, hackers stole personal information belonging to about 15 million T-Mobile wireless customers and potential customers in the U.S., which they obtained from credit reporting agency Experian.

“It's a real indictment on T-Mobile and whether or not these customers would want to continue working with T-Mobile,” said Forrester analyst Allie Mellen. “Ultimately T-Mobile has a lot of really sensitive information on people and it's just a matter of luck that, this time, the information affected was not financial information.”

She said the hack didn't appear particularly sophisticated and involved a configuration issue on a server used for testing T-Mobile phones.

“There was a gate left wide open for the attackers and they just had to find the gate and walk through it,” Mellen said. “And T-Mobile didn't know about the attack until the attackers posted about it in an online forum. That's really troubling and does not give a good indication that T-Mobile has the appropriate security monitoring in place.”

Updated on August 18, 2021, at 1:15 p.m. ET with the latest details.

Share:
More In Business
Al Sharpton to lead pro-DEI march through Wall Street
The Rev. Al Sharpton is set to lead a protest march on Wall Street to urge corporate America to resist the Trump administration’s campaign to roll back diversity, equity and inclusion initiatives. The New York civil rights leader will join clergy, labor and community leaders Thursday in a demonstration through Manhattan’s Financial District that’s timed with the anniversary of the Civil Rights-era March on Washington in 1963. Sharpton called DEI the “civil rights fight of our generation." He and other Black leaders have called for boycotting American retailers that scaled backed policies and programs aimed at bolstering diversity and reducing discrimination in their ranks.
A US tariff exemption for small orders ends Friday. It’s a big deal.
Low-value imports are losing their duty-free status in the U.S. this week as part of President Donald Trump's agenda for making the nation less dependent on foreign goods. A widely used customs exemption for international shipments worth $800 or less is set to end starting on Friday. Trump already ended the “de minimis” rule for inexpensive items sent from China and Hong Kong, but having to pay import taxes on small parcels from everywhere else likely will be a big change for some small businesses and online shoppers. Purchases that previously entered the U.S. without needing to clear customs will be subject to the origin country’s tariff rate, which can range from 10% to 50%.
Southwest Airlines’ new policy will affect plus-size travelers. Here’s how
Southwest Airlines will soon require plus-size travelers to pay for an extra seat in advance if they can't fit within the armrests of one seat. This change is part of several updates the airline is making. The new rule starts on Jan. 27, the same day Southwest begins assigning seats. Currently, plus-size passengers can pay for an extra seat in advance and later get a refund, or request a free extra seat at the airport. Under the new policy, refunds are still possible but not guaranteed. Southwest said in a statement it is updating policies to prepare for assigned seating next year.
Load More