Breach report
Credit BureauExperian (T-Mobile)
Experian reports data breach; more than 15M T-Mobile customers affected
Hackers breached an Experian server that processed credit checks for T-Mobile, exposing Social Security numbers and ID numbers of about 15 million people who had applied for T-Mobile service over two years.
Reported by CNBC
Records exposed
15M
About 15 million people
Scale vs. largest on file
- When
- 2015
- How they got in
- Intrusion into credit-check vendor server
- Sector
- Credit Bureau
On October 1, 2015, credit bureau Experian announced that an unauthorized party had accessed one of its servers holding records of consumers who applied for T-Mobile USA postpaid service or device financing. The affected data covered roughly 15 million people who had submitted applications between September 1, 2013 and September 16, 2015. Experian said it discovered the intrusion on September 15, 2015, and notified the carrier and law enforcement.
Experian ran credit checks on behalf of T-Mobile, which meant the server stored the full set of information an applicant hands over when seeking a phone contract. Experian did not publicly explain how the attacker got in, saying only that the incident was limited to a single server and did not touch its consumer credit database. The company said some sensitive fields had been encrypted, but that its investigation found the encryption may have been compromised.
The exposed records included names, addresses, Social Security numbers, dates of birth and identification numbers such as driver's license, passport or military ID numbers, along with additional information used in T-Mobile's credit assessment. Payment card and banking details were not included. Because many of the victims never became T-Mobile customers, some learned for the first time that their data had been retained at all.
Then T-Mobile chief executive John Legere issued an unusually blunt public letter saying he was angry about the breach and would review the company's relationship with Experian. Experian offered two years of free credit monitoring through its own subsidiary, a choice critics called awkward given its role in the incident. Class-action lawsuits followed, and in November 2022 Experian and T-Mobile agreed to pay a combined $16 million to a coalition of about 40 state attorneys general to resolve investigations into this breach and a separate Experian incident, while committing to strengthen data security practices.
The breach is an early, instructive example of third-party risk in consumer finance and telecom. Applicants dealt only with T-Mobile, yet their most sensitive identifiers sat on a vendor's server. It showed that outsourcing a function like credit screening does not outsource accountability, and that companies need clear contractual controls, audits and data-retention limits for partners who handle customer information.