Breach report
TelecomT-Mobile
T-Mobile says at least 47M current and former customers affected by hack
A hacker broke into T-Mobile's network through an exposed router and stole Social Security numbers and driver's license data on tens of millions of current, former and prospective customers, leading to a $350 million settlement.
Reported by TechCrunch
Records exposed
76.6M
About 76.6 million people
Scale vs. largest on file
- When
- 2021
- How they got in
- Network intrusion via exposed router and brute-force access to internal servers
- Sector
- Telecom
In mid-August 2021, a seller on a criminal forum advertised a trove of personal data allegedly taken from T-Mobile's servers. The U.S. carrier confirmed days later that its systems had been breached and that at least 47 million people were affected, including about 7.8 million current postpaid customers and roughly 40 million former or prospective customers who had applied for credit. Subsequent updates and the eventual class-action settlement put the total at around 76.6 million people in the United States.
The individual who claimed responsibility, a U.S.-born hacker living in Turkey, told reporters he had found an unprotected router exposed to the internet, used it to reach a testing environment, and then worked his way into servers holding customer records. T-Mobile did not publish a detailed technical account, but acknowledged that the attacker had used brute-force techniques to gain access. The company said it had closed the access point once it confirmed the intrusion, and it brought in outside cybersecurity experts to investigate.
The stolen data included names, birth dates, Social Security numbers and driver's license or ID information for many victims. About 850,000 prepaid customers also had names, phone numbers and account PINs exposed, and T-Mobile reset those PINs while urging all postpaid customers to change theirs. Device identifiers such as IMEI and IMSI numbers were also taken, which heightened concern about SIM-swapping fraud, in which criminals hijack a phone number to intercept security codes.
The incident was one of several T-Mobile breaches in a few years, and it prompted sharp criticism from lawmakers. Chief executive Mike Sievert publicly apologized and said the company had hired outside security firms. In July 2022, T-Mobile agreed to pay $350 million to settle consolidated class-action claims and committed to spending an additional $150 million on data security through 2023. The Federal Communications Commission later reached a separate settlement with the carrier covering this and subsequent breaches.
The breach underscored a recurring problem in telecom: carriers hold rich identity data on people who merely applied for service, sometimes for years after the relationship ends. For consumers, it reinforced the value of credit freezes and carrier account PINs, and for companies it highlighted the risk of internet-facing test systems that sit outside normal security controls.