Credential theft
T-Mobile 2019 Prepaid Customer Breach (1.26M Accounts)
Primary Source βIncident Details
In November 2019, T-Mobile’s cybersecurity team identified and shut down unauthorized access to systems containing prepaid customer account information. Approximately 1.26 million prepaid customers were affected β less than 1.5% of T-Mobile’s total customer base at the time. Exposed data included names, billing addresses, phone numbers, account numbers, rate plans, and features. No Social Security numbers, passwords, or financial information were confirmed exposed. T-Mobile notified affected customers and reset PINs. This breach is distinct from the far larger August 2021 breach attributed to John Binns affecting 54 million records, and the 2023 API breach affecting 37 million accounts. T-Mobile has experienced multiple separate breach incidents across 2019, 2020, 2021, 2022, and 2023.
Technical Details
- Initial Attack Vector
- Unauthorized access to T-Mobile systems containing prepaid customer data; specific access vector not disclosed publicly; distinct from the 2021 John Binns breach affecting 54M records
Timeline
- 2019-11-01 Breach occurred
- 2019-11-22 Publicly disclosed
- 2019-11-22 Customers notified