HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
T-MOBILE USA, INC.
bd_19093bdb9a9ec6d4 · schema v1 · pii pii-v1
Full breach record for T-MOBILE USA, INC. →T-Mobile USA, Inc. disclosed that an unauthorized party accessed Experian servers housing T-Mobile data on September 15, 2015. The breach, occurring around September 14, 2015, involved the exfiltration of personal information including names, addresses, Social Security numbers, dates of birth, and government ID numbers. No payment card or banking information was compromised. T-Mobile and Experian notified law enforcement and offered two years of credit monitoring to affected individuals.
California clockDiscovered Sep 15, 2015 → Notified Oct 2, 201517d ✓ CA 60-day OK16 days discovery → filing
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_ba0dd1171b8616bbMontana State AGfiled 2015-10-01Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-58079
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 1, 2015
- Raw hash
- 4163053e3df6857c0c79ebdaf394ea138c197617bc0fbaf4fdee17b5ed76cfd3
Reporting entity
- Name
- EXPERIAN SERVICES CORP.norm: experian services
Victim entity
- Name
- T-MOBILE USA, INC.norm: t mobile usa
- Domain
- t-mobile.com
Incident
- Discovered
- Sep 15, 2015
- Materiality determined
- —
- Notification sent
- Oct 2, 2015
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified appropriate federal, state and international law enforcement agencies
- Third party
- via Experian
- Initial access
- supply_chain
Compliance
- Time to disclose
- 16 days(16 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 17d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Sep 15, 2015→ Notified: Oct 2, 201517d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.