DisclosureLens
FEDERALItem 8.01 · voluntaryHackingTelecom & MediaInformationAbuse Of FunctionalityData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIdentity (basic)CriticalContained

T-MOBILE US, INC.

bd_e55b552517d3671c · schema v1 · pii pii-v1

Severity

Critical

Discovered

Jan 5, 2023

Filed

Jan 19, 2023

To disclose

14 days

Affected

37,000,000

Confidence

65%
Full breach record for T-MOBILE US, INC.5 incidents on file

T-Mobile US, Inc. disclosed that a bad actor obtained data through an unauthorized API access starting around November 25, 2022. The company identified the activity on January 5, 2023, and contained it within a day. Approximately 37 million customer accounts were affected, exposing basic identity information such as name, address, email, phone number, and date of birth. Sensitive data like SSNs and payment card information was not accessed.

Incident timeline

undetected · 41 days
discovery → filing · 14 days

Nov 25, 2022

Begins

Jan 5, 2023

Discovered

Jan 19, 2023

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed37,000,000 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filing

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statementThis record

Unlocks: materiality, stated response, full audit trail. Ceiling removed.