By Matt O'Brien

The names, Social Security numbers and information from driver's licenses or other identification of just over 40 million people who applied for T-Mobile credit were exposed in a recent data breach, the company said Wednesday.

The same data for about 7.8 million current T-Mobile customers who pay monthly for phone service also appears to be compromised. No phone numbers, account numbers, PINs, passwords or financial information from the nearly 50 million records and accounts were compromised, it said.

T-Mobile has been hit before by data theft but in the most recent case, “the sheer numbers far exceed the previous breaches,” said Gartner analyst Paul Furtado.

T-Mobile, which is based in Bellevue, Washington, became one of the country’s largest cellphone service carriers, along with AT&T and Verizon, after buying rival Sprint.

“Yes, they have a big target on their back but that shouldn’t be a surprise to them,” Furtado said. “You have to start questioning the organization. How much are they actually addressing these breaches and the level of seriousness?”

T-Mobile also confirmed Wednesday that approximately 850,000 active T-Mobile prepaid customer names, phone numbers and account PINs were exposed. The company said that it proactively reset all of the PINs on those accounts. No Metro by T-Mobile, former Sprint prepaid, or Boost customers had their names or PINs exposed.

There was also some additional information from inactive prepaid accounts accessed through prepaid billing files. T-Mobile said that no customer financial information, credit card information, debit or other payment information or Social Security numbers were in the inactive file.

T-Mobile had said earlier this week that it was investigating a leak of its data after someone took to an online forum offering to sell the personal information of cellphone users.

The company said Monday that it had confirmed there was unauthorized access to “some T-Mobile data” and that it had closed the entry point used to gain access.

The company said that it will immediately offer two years of free identity protection services and is recommending that all of its postpaid customers — those who pay in monthly installments — change their PIN. Its investigation is ongoing.

T-Mobile has previously disclosed a number of data breaches over the years, most recently in January and before that in Nov. 2019 and Aug. 2018, all of which involved unauthorized access to customer information. It also disclosed a breach affecting its own employees' email accounts in 2020. And in 2015, hackers stole personal information belonging to about 15 million T-Mobile wireless customers and potential customers in the U.S., which they obtained from credit reporting agency Experian.

“It's a real indictment on T-Mobile and whether or not these customers would want to continue working with T-Mobile,” said Forrester analyst Allie Mellen. “Ultimately T-Mobile has a lot of really sensitive information on people and it's just a matter of luck that, this time, the information affected was not financial information.”

She said the hack didn't appear particularly sophisticated and involved a configuration issue on a server used for testing T-Mobile phones.

“There was a gate left wide open for the attackers and they just had to find the gate and walk through it,” Mellen said. “And T-Mobile didn't know about the attack until the attackers posted about it in an online forum. That's really troubling and does not give a good indication that T-Mobile has the appropriate security monitoring in place.”

Updated on August 18, 2021, at 1:15 p.m. ET with the latest details.

Share:
More In Business
New York Times, after Trump post, says it won’t be deterred from writing about his health
The New York Times and President Donald Trump are fighting again. The news outlet said Wednesday it won't be deterred by Trump's “false and inflammatory language” from writing about the 79-year-old president's health. The Times has done a handful of stories on that topic recently, including an opinion column that said Trump is “starting to give President Joe Biden vibes.” In a Truth Social post, Trump said it might be treasonous for outlets like the Times to do “FAKE” reports about his health and "we should do something about it.” The Republican president already has a pending lawsuit against the newspaper for its past reports on his finances.
OpenAI names Slack CEO Dresser as first chief of revenue
OpenAI has appointed Slack CEO Denise Dresser as its first chief of revenue. Dresser will oversee global revenue strategy and help businesses integrate AI into daily operations. OpenAI CEO Sam Altman recently emphasized improving ChatGPT, which now has over 800 million weekly users. Despite its success, OpenAI faces competition from companies like Google and concerns about profitability. The company earns money from premium ChatGPT subscriptions but hasn't ventured into advertising. Altman had recently announced delays in developing new products like AI agents and a personal assistant.
Trump approves sale of more advanced Nvidia computer chips used in AI to China
President Donald Trump says he will allow Nvidia to sell its H200 computer chip used in the development of artificial intelligence to “approved customers” in China. Trump said Monday on his social media site that he had informed China’s leader Xi Jinping and “President Xi responded positively!” There had been concerns about allowing advanced computer chips into China as it could help them to compete against the U.S. in building out AI capabilities. But there has also been a desire to develop the AI ecosystem with American companies such as chipmaker Nvidia.
Trump says Netflix deal to buy Warner Bros. ‘could be a problem’ because of size of market share
President Donald Trump says a deal struck by Netflix last week to buy Warner Bros. Discovery “could be a problem” because of the size of the combined market share. The Republican president says he will be involved in the decision about whether federal regulators should approve the deal. Trump commented Sunday when he was asked about the deal as he walked the red carpet at the Kennedy Center Honors. The $72 billion deal would bring together two of the biggest players in television and film and potentially reshape the entertainment industry.
What to know about changes to Disney parks’ disability policies
Disney's changes to a program for disabled visitors are facing challenges in federal court and through a shareholder proposal. The Disability Access Service program, which allows disabled visitors to skip long lines, was overhauled last year. Disney now mostly limits the program to those with developmental disabilities like autism who have difficulty waiting in lines. The changes have sparked criticism from some disability advocates. A shareholder proposal submitted by disability advocates calls for an independent review of Disney's disability policies. Disney plans to block this proposal, claiming it's misleading. It's the latest struggle by Disney to accommodate disabled visitors while stopping past abuses by some theme park guests.
Load More