Data leak

BleepingComputer / Traceable / Wikipedia

πŸ“… 2022-11-25 🏒 T-Mobile US customer portal / API
Primary Source β†—

Incident Details

Attackers exploited an unprotected API endpoint starting Nov 25 2022, exfiltrating data over weeks undetected. 37 million customer records exposed including names, phone numbers, billing addresses, birthdates, email addresses, T-Mobile account numbers and plan features. Breach detected Jan 5 2023; public disclosure Jan 19 2023. T-Mobile’s 8th breach since 2018. FCC and multi-state regulators investigated. T-Mobile paid $15.75M penalty in 2024 settlement covering multiple breaches. Previous 2021 breach via SSH brute force exposed 76M records.

Technical Details

Initial Attack Vector
CWE-306: Missing Authentication for Critical Function (unauthenticated API endpoint exposing customer data)
Vendor / Product
T-Mobile US customer portal / API

Timeline

  1. 2022-11-25 Breach occurred
  2. 2023-01-19 Publicly disclosed
  3. 2023-01-19 Customers notified