HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTPIIMediumActive
T-MOBILE USA, INC.
bd_b2fa46f755306925 · schema v1 · pii pii-v1
Full breach record for T-MOBILE USA, INC. →T-Mobile USA reported a cybersecurity incident on August 17, 2021, where unauthorized individuals accessed personal data. The breach affected a subset of customers, exposing names, driver's licenses, government IDs, Social Security numbers, dates of birth, addresses, and phone numbers. Prepaid PINs were reset. No financial or payment information was compromised. T-Mobile provided two years of McAfee ID Theft Protection and activated Scam Shield. The investigation was ongoing as of the August 19, 2021 notification.
California clockDiscovered Aug 17, 2021 → Notified Aug 19, 20212d ✓ CA 60-day OK8 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_6c7de9e9876d5dacWashington State AGfiled 2021-08-24(1d gap)Candidate
- bd_f59f5dad6f2da02eOregon State AGfiled 2021-08-27(2d gap)Verified
- bd_4f029ec65fed3c95South Carolina State AGfiled 2021-08-31(6d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-544287
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 25, 2021
- Raw hash
- 5bff94b80bd5c5a32b856a4b5236997c8d4af77c6a147f25b330ff1895d242a5
Reporting entity
- Name
- T-MOBILE USA, INC.norm: t mobile usa
- Domain
- t-mobile.com
- Industry
- telecom_media
Victim entity
- Name
- T-MOBILE USA, INC.norm: t mobile usa
- Domain
- t-mobile.com
- Industry
- telecom_media
Incident
- Discovered
- Aug 17, 2021
- Materiality determined
- —
- Notification sent
- Aug 19, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed breach notification with California Office of the Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 8 days(8 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 2d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Aug 17, 2021→ Notified: Aug 19, 20212d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.