HackingStolen CredentialsCustomer Data InvolvedTargetedPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
T-MOBILE USA, INC.
bd_4f029ec65fed3c95 · schema v1 · pii pii-v1
Full breach record for T-MOBILE USA, INC. →T-Mobile notified South Carolina regulators on Oct 11, 2021, regarding a cyber incident affecting legacy Sprint and T-Mobile postpaid customers. Notifications were sent between Aug 18 and Sep 3, 2021, via SMS and email to cohorts including SSN and non-SSN data. Incident involved unauthorized access to customer records.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_f59f5dad6f2da02eOregon State AGfiled 2021-08-27(4d gap)Verified
- bd_b2fa46f755306925California State AGfiled 2021-08-25(6d gap)Verified
- bd_6c7de9e9876d5dacWashington State AGfiled 2021-08-24(7d gap)Candidate
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Business%20Resources%20Laws/Related%20Laws/Breaches/2021/TMobile.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 31, 2021
- Raw hash
- 2e23d478a9b00c654373af3e3ffe3586280a3f6ab020626a7f3c2a0ede36237d
Reporting entity
- Name
- T-MOBILE USA, INC.norm: t mobile usa
- Domain
- t-mobile.com
Victim entity
- Name
- T-MOBILE USA, INC.norm: t mobile usa
- Domain
- t-mobile.com
Incident
- Discovered
- Aug 18, 2021
- Materiality determined
- Oct 11, 2021
- Notification sent
- Aug 18, 2021
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed notice with South Carolina Department of Consumer Affairs
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 13 days(13 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.