T-MOBILE US, INC.
ent_019e4688de483c51ff92253a7e944671
Disclosures
4
State AG · SEC 10-K Item 1C · SEC 8-K · 3 jurisdictions
Multi-filing incidents
—
no multi-filing incident in sample
Max affected reported
37,000,000
nationwide · SEC 8-K FEDERAL
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- T-MOBILE US, INC.
- Normalized
- t mobile us— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300QHIJYOHPACPG31
- SEC EDGAR CIK
- 0001283699
- Domain
- None on record
Disclosure history (4)newest first
- 🏎️Indiana State AGas victim2025-08-29
T-Mobile reported a data breach to the Indiana Attorney General. The breach occurred on 2025-06-10 and was reported on 2025-08-29. 1 Indiana residents were affected. 2 individuals affected in total.
- FEDERALSEC 10-K Item 1Cas victim2024-02-02
T-Mobile's 10-K Item 1C cybersecurity disclosure references two previously disclosed cybersecurity incidents: an August 2021 cyberattack and a January 2023 cyberattack. Both resulted in class action lawsuits, mass arbitration claims, and (for the January 2023 incident) regulatory inquiries. The Company states it has incurred and may continue to incur significant costs that may have a material adverse effect on its business. No new incident is reported in this filing; details on attack vectors, affected counts, and data types are not provided in this Item 1C narrative.
- ⛰️New Hampshire State AGas victim2023-04-28
T-Mobile US, Inc. notified the New Hampshire Attorney General that a bad actor gained unauthorized access to limited information from a small number of T-Mobile accounts between late February and March 2023. One New Hampshire resident was affected. The compromised data included account PINs. T-Mobile reset the PINs, shut down access, and provided two years of free credit monitoring.
- FEDERALSEC 8-Kas victim2023-01-19
T-Mobile US disclosed a cybersecurity incident where a bad actor accessed customer data via an unauthorized API call starting around November 25, 2022. The incident was discovered on January 5, 2023. Approximately 37 million customer accounts were affected, with data including names, billing addresses, emails, phone numbers, dates of birth, and account numbers exposed. Sensitive data like SSNs and payment info was not accessed. The activity is contained, and the investigation is ongoing.
Subsidiary disclosures (newest 10)filed by group companies
◈ These filings were made by or about subsidiaries of T-MOBILE US, INC. — not by T-MOBILE US, INC. itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- 🦞Maine State AGvia T-MOBILE USA, INC.2026-03-31
T-Mobile USA insider wrongdoing: an unauthorized individual accessed one customer account on 2026-01-12; discovered 2026-03-05. Exposed data may include name, address, email, account number, phone numbers, account PIN, driver's license, date of birth, and SSN. One Maine resident affected. T-Mobile reset the PIN and offered 24 months of free credit monitoring via TransUnion myTrueIdentity.
- 🦞Maine State AGvia USCC Services, LLC2024-02-13
USCC Services, LLC, operating as UScellular, reported a data breach that occurred on January 28, 2024, and was discovered the following day. An external system breach (hacking) affected 100 individuals, including 8 Maine residents. The compromised information included names in combination with financial account or credit/debit card numbers and their associated security codes or PINs. Written notifications were sent to the affected individuals on February 16, 2024.
- 🦞Maine State AGvia T-MOBILE USA, INC.2023-04-28
T-Mobile, USA experienced a security breach between February 24, 2023, and March 30, 2023, which was discovered on March 27, 2023. The breach, described as an external system hack, affected 836 individuals. The compromised information included names in combination with driver's license or non-driver identification card numbers. T-Mobile notified the affected individuals on April 28, 2023, and offered 24 months of complimentary credit monitoring and identity theft protection services through Transunion.
- 🌲Washington State AGvia T-MOBILE USA, INC.2023-01-19
T-Mobile USA, a business sector entity reported a unauthorized access incident to the Washington Attorney General. The organization became aware of the incident on 2023-01-05 and filed notice on 2023-01-19. 772,593 Washington residents were affected. 14 days elapsed between awareness and notification. 41 days to identify the breach. 0 days to contain the breach.
- 🦞Maine State AGvia USCC Services, LLC2021-12-23
USCC Services, LLC d/b/a UScellular reported a phishing-based breach occurring between December 13 and 19, 2021. The incident affected 405 individuals, including 40 Maine residents. UScellular notified affected consumers in writing on December 27, 2021. No identity theft protection services were offered.
- ⛰️New Hampshire State AGvia T-MOBILE USA, INC.2021-11-29
T-Mobile USA submitted a supplemental notice to the New Hampshire Attorney General on November 23, 2021, regarding a security event affecting New Hampshire residents. The company reported that it detected and shut down the event and sent individual notices to 116,079 residents between August 18 and October 24, 2021. The investigation was stated to be complete.
- 🌴South Carolina State AGvia T-MOBILE USA, INC.2021-08-31
T-Mobile notified South Carolina regulators on Oct 11, 2021, regarding a cyber incident affecting legacy Sprint and T-Mobile postpaid customers. Notifications were sent between Aug 18 and Sep 3, 2021, via SMS and email to cohorts including SSN and non-SSN data. Incident involved unauthorized access to customer records.
- 🦫Oregon State AGvia T-MOBILE USA, INC.2021-08-27
T-Mobile USA reported a data breach to the Oregon Attorney General. The breach was reported on 2021-08-27. The breach was discovered on 8/17/2021. Notice was sent on 8/19/2021.
- 🐻California State AGvia T-MOBILE USA, INC.2021-08-25
T-Mobile USA reported a cybersecurity incident on August 17, 2021, where unauthorized individuals accessed personal data. The breach affected a subset of customers, exposing names, driver's licenses, government IDs, Social Security numbers, dates of birth, addresses, and phone numbers. Prepaid PINs were reset. No financial or payment information was compromised. T-Mobile provided two years of McAfee ID Theft Protection and activated Scam Shield. The investigation was ongoing as of the August 19, 2021 notification.
- 🌲Washington State AGvia T-MOBILE USA, INC.2021-08-24
T-Mobile USA, a business sector entity reported a malware incident to the Washington Attorney General. The organization became aware of the incident on 2021-08-17 and filed notice on 2021-08-24. 2,079,648 Washington residents were affected. 7 days elapsed between awareness and notification. 26 days to identify the breach.