Skip to main content
Breach Signal

Breach report

Telecom

T-Mobile

T-Mobile says hacker accessed personal data of 37 million customers

An attacker quietly abused a T-Mobile API for about six weeks, harvesting names, addresses, birth dates and account details on 37 million customers before the carrier noticed, marking its eighth breach in five years.

Reported by TechCrunch

Records exposed

37M

About 37 million customer accounts

Scale vs. largest on file

When
2023 (access began November 2022)
How they got in
API abuse
Sector
Telecom

On January 19, 2023, T-Mobile disclosed in a filing with the U.S. Securities and Exchange Commission that a malicious actor had obtained data on about 37 million current postpaid and prepaid customer accounts. The carrier said it detected the activity on January 5 and shut it down within a day, but its investigation found the attacker had been pulling data since around November 25, 2022.

Unlike T-Mobile's 2021 breach, this incident did not involve a direct compromise of internal servers. Instead, the attacker abused a single application programming interface, an automated gateway that lets software request information, to retrieve customer records without authorization. T-Mobile did not publicly name the API or explain exactly how it was misused, saying only that the interface was not designed to return the volume of data that was extracted.

The exposed information included names, billing addresses, email addresses, phone numbers, dates of birth, account numbers and details such as the number of lines and plan features on each account. T-Mobile said no passwords, PINs, payment card data, Social Security numbers or government ID numbers were taken. Even so, the combination of contact details and account data is well suited to targeted phishing and SIM-swap attempts.

The disclosure landed less than a year after T-Mobile agreed to pay $350 million to settle litigation over its 2021 breach, and it was widely counted as the company's eighth security incident since 2018. Critics noted that the attacker operated for roughly six weeks before being caught. In September 2024, the Federal Communications Commission announced a $31.5 million settlement with T-Mobile resolving investigations into the 2021, 2022 and 2023 incidents, split between a civil penalty and required investment in cybersecurity, including moving toward modern zero-trust architecture and broader use of phishing-resistant authentication.

The case is frequently cited as an example of API security risk, a growing concern as companies expose more back-end systems to apps and partners. Because API calls can look like normal traffic, bulk scraping may not trip traditional alarms. Security teams increasingly treat rate limiting, anomaly detection and strict limits on returned fields as basic requirements for customer-facing interfaces.

More from the wire

More in Telecom.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.