T-MOBILE US, INC.
bd_e55b552517d3671c · schema v1 · pii pii-v1
Full breach record for T-MOBILE US, INC. →5 incidents on fileT-Mobile US, Inc. disclosed that a bad actor obtained data through an unauthorized API access starting around November 25, 2022. The company identified the activity on January 5, 2023, and contained it within a day. Approximately 37 million customer accounts were affected, exposing basic identity information such as name, address, email, phone number, and date of birth. Sensitive data like SSNs and payment card information was not accessed.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 25, 2022
Begins
Jan 5, 2023
Discovered
Jan 19, 2023
Filed
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.