FEDERALItem 8.01 · voluntaryHackingData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICPIICriticalContained
T-MOBILE US, INC.
bd_e55b552517d3671c · schema v1 · pii pii-v1
Full breach record for T-MOBILE US, INC. →T-Mobile US disclosed a cybersecurity incident where a bad actor accessed customer data via an unauthorized API call starting around November 25, 2022. The incident was discovered on January 5, 2023. Approximately 37 million customer accounts were affected, with data including names, billing addresses, emails, phone numbers, dates of birth, and account numbers exposed. Sensitive data like SSNs and payment info was not accessed. The activity is contained, and the investigation is ongoing.
SEC clockMateriality determined Jan 19, 2023 → Filed Jan 19, 20230d ✓ SEC 4-day OK14 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed37,000,000 affectedView incident
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/1283699/000119312523010949/
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jan 19, 2023
- Raw hash
- 356bb395354fe7e2d527afaf59fd9198c88487b31c264947a586b69b325a010f
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- T-MOBILE US, INC.norm: t mobile us
- SEC CIK
- 0001283699
Victim entity
- Name
- T-MOBILE US, INC.norm: t mobile us
- SEC CIK
- 0001283699
Incident
- Discovered
- Jan 5, 2023
- Materiality determined
- Jan 19, 2023
- Notification sent
- —
- Affected individuals
- 37,000,000
- Data types
- IDENTITY_BASICPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1530 Data from Cloud Storage Object
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified certain federal agencies about the incidentWorking with law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 14 days(14 days from discovery to filing)
- Compliance flags
- SEC 4-day OK · 0d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status SEC Materiality determined: Jan 19, 2023→ Filed: Jan 19, 20230d cal. 4 business days SEC 4-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.