T-MOBILE USA, INC.
ent_019dd1b4312fd58bee8365efa1e2383d
Disclosures
25+
State AG · Leak Site · 12 jurisdictions
Multi-filing incidents
5
incidents joining 2+ filings here
Max affected reported
53,800,000
nationwide · State AG DE
Leak-site claims
2
unverified actor claims
Identity resolution
- Canonical name
- T-MOBILE USA, INC.
- Normalized
- t mobile usa— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300V2JRLO5DIFGE82
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- t-mobile.com
- Corporate parent
- DEUTSCHE TELEKOM AG— per GLEIF relationship records
Disclosure history (newest 25)newest first
- Maine State AGas victim2026-03-31
T-Mobile, USA reported an insider wrongdoing incident to the Maine Attorney General. An unauthorized individual accessed limited information on one Maine resident's account on January 12, 2026. The breach was discovered on March 5, 2026. Affected data included name, address, email, account number, phone numbers, PIN, driver's license, DOB, and SSN. T-Mobile reset the account PIN and offered 24 months of credit monitoring. Notification was sent on March 31, 2026.
- Massachusetts State AGas victim2023-04-28
T-Mobile USA reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-04-28. 17 Massachusetts residents were affected. The report records the breach type as electronic.
- Maine State AGas victim2023-04-28
T-Mobile, USA experienced a security breach between February 24, 2023, and March 30, 2023, which was discovered on March 27, 2023. The breach, described as an external system hack, affected 836 individuals. The compromised information included names in combination with driver's license or non-driver identification card numbers. T-Mobile notified the affected individuals on April 28, 2023, and offered 24 months of complimentary credit monitoring and identity theft protection services through Transunion.
- Indiana State AGas victim2023-04-28
T‐Mobile reported a data breach to the Indiana Attorney General. The breach occurred on 2023-02-24 and was reported on 2023-04-28. 7 Indiana residents were affected. 836 individuals affected in total.
- Washington State AGas victim2023-01-19
T-Mobile USA reported unauthorized access to customer account information in Washington. The breach, discovered on Jan 5, 2023, affected names, contact details, and DOBs. Passwords and SSNs were not compromised. 772,593 Washington residents were notified.
- GLOBALLeak Siteas victim2022-04-21
- Massachusetts State AGas victim2022-03-08
T-Mobile reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2022-03-08. 1 Massachusetts residents were affected. The report records the breach type as paper.
- New Hampshire State AGas victim2021-11-29
T-Mobile USA submitted a supplemental notice to the New Hampshire Attorney General on November 23, 2021, regarding a security event affecting New Hampshire residents. The company reported that it detected and shut down the event and sent individual notices to 116,079 residents between August 18 and October 24, 2021. The investigation was stated to be complete.
- GLOBALLeak Siteas victim2021-09-09
- South Carolina State AGas victim2021-08-31
T-Mobile USA, Inc. reported a cybersecurity incident in South Carolina affecting legacy Sprint and T-Mobile customers. Unauthorized access occurred on or before July 19, 2021, and was discovered on August 17, 2021. Personal data accessed included names, phone numbers, dates of birth, driver's license IDs, and Social Security numbers. No financial or payment card data was compromised. T-Mobile engaged forensic experts and federal law enforcement, offering two years of free identity protection.
- Oregon State AGas victim2021-08-27
T-Mobile USA reported a data breach to the Oregon Attorney General. The breach was reported on 2021-08-27. The breach was discovered on 8/17/2021. Notice was sent on 8/19/2021.
- Massachusetts State AGas victim2021-08-26
T-Mobile USA reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-08-26. 1,044,774 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2021-08-25
T-Mobile USA reported that on August 17, 2021, it learned of unauthorized access to personal data. The breach occurred on July 22, 2021. Affected data includes names, driver's licenses, government IDs, Social Security numbers, dates of birth, prepaid PINs, addresses, and phone numbers. T-Mobile states the investigation is ongoing and has reset prepaid PINs. Customers are offered free identity theft protection.
- Washington State AGas victim2021-08-24
T-Mobile USA filed a supplemental notice with the Washington Attorney General regarding a July 2021 breach affecting ~2.08M WA residents. Unauthorized access occurred on or before July 19, 2021; discovered August 17, 2021. Data included SSN, DL, DOB, names, addresses, and PINs. Notices sent Aug 18-Oct 24, 2021. Forensic experts and law enforcement engaged. Free credit monitoring offered.
- New Hampshire State AGas victim2021-08-19
T-Mobile USA notified the New Hampshire Attorney General on August 19, 2021, regarding a cybersecurity incident discovered on August 17, 2021. A bad actor illegally accessed unencrypted personal information, including names, SSNs, driver's license numbers, and account PINs. T-Mobile shut the entry point, engaged forensic experts and federal law enforcement, and provided free credit monitoring. The investigation was ongoing at the time of filing.
- Delaware State AGas victim2021-08-19
T-Mobile reported a data breach to the Delaware Attorney General. The breach occurred on 2021-08-12. It was discovered on 2021-08-17. Notice was filed on 2021-08-19. 53,800,000 individuals affected in total. Information involved: identity government.
- Massachusetts State AGas victim2021-03-31
T-Mobile reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-03-31. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- Indiana State AGas victim2021-03-31
T-Mobile reported a data breach to the Indiana Attorney General. The breach occurred on 2021-02-20 and was reported on 2021-03-31. 1 Indiana residents were affected. 65 individuals affected in total.
- New Hampshire State AGas victim2021-03-16
T-Mobile USA, Inc. notified the NH Attorney General that a T-Mobile representative accessed one New Hampshire resident's account information without authorization on February 12, 2021. The accessed data included name, address, email, account number, last 4 of SSN, DOB, and driver's license details. The representative reassigned the phone line to a different SIM card. T-Mobile terminated the access, reverted changes, disciplined the employee, and offered two years of credit monitoring.
- Indiana State AGas victim2021-02-09
T-Mobile reported a data breach to the Indiana Attorney General. The breach occurred on 2021-01-18 and was reported on 2021-02-09. 6 Indiana residents were affected. 421 individuals affected in total.
- Illinois State AGas victim2021-01-01
T-MOBILE filed a data-breach notice with the Illinois Attorney General during 2021 (case 21-339). The register records the breach as discovered on August 17, 2021. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Massachusetts State AGas victim2020-10-14
T Mobile reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2020-10-14. 3 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas victim2020-03-10
T-Mobile USA notified Montana AG of a breach affecting customer and employee email accounts via a compromised email vendor. Unauthorized access occurred Nov 26–Dec 25, 2019. Data included names, addresses, SSNs, financial account info, and government IDs. T-Mobile engaged forensic experts, notified law enforcement, and offered credit monitoring.
- Montana State AGas victim2020-03-02
T-Mobile USA notified Montana residents of a data breach involving unauthorized access to employee email accounts via a compromised email vendor. The incident occurred between November 26 and December 25, 2019, exposing names, addresses, SSNs, financial account info, and government IDs. T-Mobile engaged forensic experts, notified federal law enforcement, and offered two years of credit monitoring via TransUnion.
- New Hampshire State AGas victim2017-09-14
T-Mobile USA, Inc. reported that a former employee misused a New Hampshire resident's payment card information without authorization on or about August 24, 2017. The employee was separated. The company is providing one year of credit monitoring to the affected individual.