T-MOBILE USA, INC.
ent_019dd1b4312fd58bee8365efa1e2383d
Disclosures
12
State AG · 7 jurisdictions
Incidents
2
filings grouped by incident
Max affected reported
2,079,648
as filed · State AG WA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- T-MOBILE USA, INC.
- Normalized
- t mobile usa— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300V2JRLO5DIFGE82
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- t-mobile.com
- Corporate parent
- T-MOBILE US, INC.— per GLEIF relationship records
Disclosure history (12)newest first
- 🦞Maine State AGas victim2026-03-31
T-Mobile USA insider wrongdoing: an unauthorized individual accessed one customer account on 2026-01-12; discovered 2026-03-05. Exposed data may include name, address, email, account number, phone numbers, account PIN, driver's license, date of birth, and SSN. One Maine resident affected. T-Mobile reset the PIN and offered 24 months of free credit monitoring via TransUnion myTrueIdentity.
- 🦞Maine State AGas victim2023-04-28
T-Mobile, USA experienced a security breach between February 24, 2023, and March 30, 2023, which was discovered on March 27, 2023. The breach, described as an external system hack, affected 836 individuals. The compromised information included names in combination with driver's license or non-driver identification card numbers. T-Mobile notified the affected individuals on April 28, 2023, and offered 24 months of complimentary credit monitoring and identity theft protection services through Transunion.
- 🌲Washington State AGas victim2023-01-19
T-Mobile USA, a business sector entity reported a unauthorized access incident to the Washington Attorney General. The organization became aware of the incident on 2023-01-05 and filed notice on 2023-01-19. 772,593 Washington residents were affected. 14 days elapsed between awareness and notification. 41 days to identify the breach. 0 days to contain the breach.
- 🌴South Carolina State AGas victim2021-08-31
T-Mobile notified South Carolina regulators on Oct 11, 2021, regarding a cyber incident affecting legacy Sprint and T-Mobile postpaid customers. Notifications were sent between Aug 18 and Sep 3, 2021, via SMS and email to cohorts including SSN and non-SSN data. Incident involved unauthorized access to customer records.
- 🦫Oregon State AGas victim2021-08-27
T-Mobile USA reported a data breach to the Oregon Attorney General. The breach was reported on 2021-08-27. The breach was discovered on 8/17/2021. Notice was sent on 8/19/2021.
- 🐻California State AGas victim2021-08-25
T-Mobile USA reported a cybersecurity incident on August 17, 2021, where unauthorized individuals accessed personal data. The breach affected a subset of customers, exposing names, driver's licenses, government IDs, Social Security numbers, dates of birth, addresses, and phone numbers. Prepaid PINs were reset. No financial or payment information was compromised. T-Mobile provided two years of McAfee ID Theft Protection and activated Scam Shield. The investigation was ongoing as of the August 19, 2021 notification.
- 🌲Washington State AGas victim2021-08-24
T-Mobile USA, a business sector entity reported a malware incident to the Washington Attorney General. The organization became aware of the incident on 2021-08-17 and filed notice on 2021-08-24. 2,079,648 Washington residents were affected. 7 days elapsed between awareness and notification. 26 days to identify the breach.
- 🦬Montana State AGas victim2020-03-10
T-Mobile USA reported a data breach to the Montana Attorney General. The breach was reported on 2020-03-10. The breach occurred from 11/26/2019 to 12/25/2019. 1 Montana residents were affected.
- 🐻California State AGas victim2015-10-01
T-Mobile USA, Inc. disclosed that an unauthorized party accessed Experian servers housing T-Mobile data on September 15, 2015. The breach, occurring around September 14, 2015, involved the exfiltration of personal information including names, addresses, Social Security numbers, dates of birth, and government ID numbers. No payment card or banking information was compromised. T-Mobile and Experian notified law enforcement and offered two years of credit monitoring to affected individuals.
- 🦬Montana State AGas victim2015-10-01
T-Mobile USA, Inc. reported a data breach to the Montana Attorney General. The breach was reported on 2015-10-01. The breach occurred on 9/15/2015. 1,134 Montana residents were affected.
- 🐻California State AGas victim2013-12-30
T-Mobile USA, Inc. disclosed a security incident involving unauthorized access to a file stored on a third-party supplier's server. The file contained personal information including names, addresses, Social Security numbers, and Driver's License numbers. The incident was discovered in late November 2013. T-Mobile provided one year of complimentary credit monitoring through Experian's ProtectMyID Elite service to affected individuals.
- ⛰️New Hampshire State AGas victim2009-09-03
T-Mobile USA, Inc. notified the New Hampshire Attorney General on September 3, 2009, of a security breach affecting 169 New Hampshire residents. Unauthorized individuals obtained access to customer names, addresses, and Social Security numbers through fraudulent means. The responsible individuals were arrested and prosecuted by the U.S. Department of Justice. T-Mobile corrected accounts with unauthorized charges and provided 169 affected residents with one year of complimentary credit monitoring and identity theft protection via Experian.