Breach report
TelecomT-Mobile
T-Mobile says hacker accessed personal data of 37 million customers
An attacker quietly abused a T-Mobile API for about six weeks, harvesting names, addresses, birth dates and account details on 37 million customers before the carrier noticed, marking its eighth breach in five years.
Reported by TechCrunch
Records exposed
37M
About 37 million customer accounts
Scale vs. largest on file
- When
- 2023 (access began November 2022)
- How they got in
- API abuse
- Sector
- Telecom
On January 19, 2023, T-Mobile disclosed in a filing with the U.S. Securities and Exchange Commission that a malicious actor had obtained data on about 37 million current postpaid and prepaid customer accounts. The carrier said it detected the activity on January 5 and shut it down within a day, but its investigation found the attacker had been pulling data since around November 25, 2022.
Unlike T-Mobile's 2021 breach, this incident did not involve a direct compromise of internal servers. Instead, the attacker abused a single application programming interface, an automated gateway that lets software request information, to retrieve customer records without authorization. T-Mobile did not publicly name the API or explain exactly how it was misused, saying only that the interface was not designed to return the volume of data that was extracted.
The exposed information included names, billing addresses, email addresses, phone numbers, dates of birth, account numbers and details such as the number of lines and plan features on each account. T-Mobile said no passwords, PINs, payment card data, Social Security numbers or government ID numbers were taken. Even so, the combination of contact details and account data is well suited to targeted phishing and SIM-swap attempts.
The disclosure landed less than a year after T-Mobile agreed to pay $350 million to settle litigation over its 2021 breach, and it was widely counted as the company's eighth security incident since 2018. Critics noted that the attacker operated for roughly six weeks before being caught. In September 2024, the Federal Communications Commission announced a $31.5 million settlement with T-Mobile resolving investigations into the 2021, 2022 and 2023 incidents, split between a civil penalty and required investment in cybersecurity, including moving toward modern zero-trust architecture and broader use of phishing-resistant authentication.
The case is frequently cited as an example of API security risk, a growing concern as companies expose more back-end systems to apps and partners. Because API calls can look like normal traffic, bulk scraping may not trip traditional alarms. Security teams increasingly treat rate limiting, anomaly detection and strict limits on returned fields as basic requirements for customer-facing interfaces.