T-Mobile and its subsidiary MetroPCS today disclosed a recent incident where hackers gained "unauthorized access to certain information" of its customers, which the companies have already reported to the police and shut down. The security breach occurred earlier this week on Monday, August 20, and affected two million customers (via Motherboard).

iphone x t mobile
T-Mobile promises that no financial data, credit card information, social security numbers, or passwords were compromised in the breach. However, "some of your personal information may have been exposed," the company states in the letter shared online, including one or more of the following: name, billing zip code, phone number, email address, account number, and account type (prepaid or postpaid).

A T-Mobile spokesperson says that the security breach affected "slightly less than" three percent of its 77 million customers, but did not reference a specific number. The incident reportedly happened "early in the morning" on August 20, and was perpetrated by hackers part of "an international group" that accessed T-Mobile servers through an API that "didn't contain any financial data or other very sensitive data."

The intrusion was discovered by T-Mobile's cybersecurity team the same day:

“We found it quickly and shut it down very fast,” the spokesperson said.

The spokesperson said she couldn’t give “specifics” of the attack and did not know whether the hackers were criminals or part of a government.

T-Mobile is reaching out to victims directly via text message to notify them, she said.

T-Mobile is now reaching out to notify all affected customers, and "if you don't receive a notification then that means your account was not among those impacted by this incident." The breach occurred less than a week after T-Mobile announced its new customer service initiative "Team of Experts."

Top Rated Comments

gsmornot Avatar
50 months ago
Here’s a great idea, stop centralizing databases.

Decentralize the customer information so they have direct access.

That wau when a hacker comes around, it’s not just one or two targets with MILLIONS of person info, instead they would need to target one person at a time
Not being a physical asset this would not apply. If you can see the records from a single machine it does not matter where they are stored. It would not make sense to have multiple systems for customer data, the agents alone would take a lot of time trying to find the user. So, option two is better management of access.
Score: 3 Votes (Like | Disagree)
shareef777 Avatar
50 months ago
Here’s a great idea, stop centralizing databases.

Decentralize the customer information so they have direct access.

That wau when a hacker comes around, it’s not just one or two targets with MILLIONS of person info, instead they would need to target one person at a time
There's no solution that's hacker-proof. A script can be written to pull the data of one customer and re-run a million times automatically to pull the data of all the others.
Score: 2 Votes (Like | Disagree)
Capeto Avatar
50 months ago
Yeah, I got a text message yesterday saying my info was compromised.

I hope whoever steals my identity enjoys the student loan debt!
Score: 2 Votes (Like | Disagree)
TheShadowKnows! Avatar
50 months ago
Beware that this is the perfect situation whereby you are the target of "spear phishing"

Here is how that would work:
[LIST=1]
* The news are out that T-Mobile servers have been compromised, and that a small fraction of subscribers will receive an email warning them that they may have been the target.
* You receive such email. The email appears to be authentic; but it is not and yet it appears crafted by T-Mobile Customer Service.
* It includes within the email body an embedded URL requesting you, the recipient, to click and login onto your T-Mobile account, and "change your password".
* The URL is fake, and points to hackers' backend servers.
* Unaware, you click and "login" with your login credentials.
* Presto, your credentials are now on the wild, and you have given the hackers a free pass to your T-Mobiel account, and posible financial information.

So beware.
Never click on embedded URLs within the body of emails.
Score: 1 Votes (Like | Disagree)
Amacfa Avatar
50 months ago
Here’s a great idea, stop centralizing databases.

Decentralize the customer information so they have direct access.

That wau when a hacker comes around, it’s not just one or two targets with MILLIONS of person info, instead they would need to target one person at a time
Score: 1 Votes (Like | Disagree)

Popular Stories

2022 back to school apple

Apple Launches 2022 Back to School Offer: Up to $150 Gift Card With Mac or iPad

Friday June 24, 2022 5:08 am PDT by
Apple today launched its annual "Back to School" promotion for college/university students in the United States and Canada. This year's promotion offers a free Apple gift card with the purchase of an eligible Mac or iPad, rather than free AirPods like last year. Apple is also offering students 20% off AppleCare+ plans during the promotion. Apple is offering a $150 gift card with the purchase ...
airpods pro 2 1

AirPods Pro 2 Said to Feature Upgraded H1 Chip, Find My, Heart Rate Detection, USB-C and More

Friday June 24, 2022 9:48 am PDT by
The next-generation AirPods Pro could come with a long list of new features that include heart rate detection, the ability to function as a hearing aid, and a USB-C port according to a report from 52Audio. The site claims that it has received new information on the AirPods Pro 2, and it has used that information to provide some renders on what the earbuds might look like. Design wise, there...
m1 mac mini screen

Gurman: Apple Planning M2 Pro Mac Mini, New Apple TV With A14 Chip, Revamped HomePod With S8 Chip, and More

Sunday June 26, 2022 6:31 am PDT by
In the latest edition of his Power On newsletter for Bloomberg, Mark Gurman outlined additional M2 Macs on Apple's product roadmap, including new Mac mini models with M2 and M2 Pro chips, new 14-inch and 16-inch MacBook Pro models with M2 Pro and M2 Max chips, and a new Mac Pro tower with M2 Ultra and "M2 Extreme" chips. Following the M2 series of Macs, Gurman said the first M3 series of...
apple ar headset concept 1

Apple Rumored to Announce 'Game-Changer' AR/VR Headset in January 2023

Friday June 24, 2022 2:52 am PDT by
Apple is "likely" to announce its long-rumored mixed-reality headset as soon as January 2023, Apple analyst Ming-Chi Kuo has reiterated. Concept render based on purported leaked information by Ian Zelbo In a detailed post on Medium, Kuo explained that Apple's headset will be a "game-changer" for the augmented-reality and virtual-reality market. Describing some of the headset's...
widgets ios 16 feature

Gurman: iPhone 14 Pro to Feature Always-On Display Showing iOS 16's New Lock Screen Widgets

Sunday June 26, 2022 7:36 am PDT by
iPhone 14 Pro models are widely expected to feature always-on displays that allow users to view glanceable information without having to tap to wake the screen. In the latest edition of his Power On newsletter for Bloomberg, Mark Gurman said the feature will include support for iOS 16's new Lock screen widgets for weather, fitness, and more. "Like the Apple Watch, the iPhone 14 Pro will be...