SPRINT LLC
ent_9a5756b782b1aea9117301c2
Disclosures
11
State AG · 8 jurisdictions
Multi-filing incidents
3
incidents joining 2+ filings here
Max affected reported
26,801
nationwide · State AG WA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- SPRINT LLC
- Normalized
- sprint— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300ZTTY7CXOLJ6539
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- hub-sprint.com
- Corporate parent
- T-MOBILE US, INC.— per SEC Exhibit 21 filing
Disclosure history (11)newest first
- Massachusetts State AGas victim2020-04-15
Sprint reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2020-04-15. 6 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2020-04-02
Sprint reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2020-04-02. 3 Massachusetts residents were affected. The report records the breach type as electronic.
- South Carolina State AGas victim2019-08-09
Sprint Corporation notified South Carolina consumers of unauthorized access to customer accounts via the Samsung.com 'add a line' website. The breach involved account credentials used to access personal data including names, billing addresses, phone numbers, and financial account details. Sprint reset affected account PINs and secured accounts on June 25, 2019.
- Delaware State AGas victim2019-07-11
Sprint Business notified a Delaware resident of unauthorized access to their account via stolen credentials on the Samsung.com 'add a line' website. Access occurred on June 22, 2019. Data viewed included phone number, device ID, billing address, and account details. Sprint reset the account PIN and secured the account.
- Montana State AGas victim2019-07-11
Sprint notified Montana residents of unauthorized access to their accounts via the Samsung.com 'add a line' website on June 22, 2019. Access was gained using stolen credentials. Affected data included phone numbers, device IDs, billing addresses, and account numbers. Sprint reset account PINs and secured accounts.
- Washington State AGas reporting2019-07-09
Sprint Corporation notified Washington AG of unauthorized access to customer accounts via Samsung.com 'add a line' site on June 22, 2019. 26,801 customers affected (596 in WA). Data included names, addresses, phone numbers, account numbers, and billing info. Sprint reset PINs and notified customers starting July 11, 2019.
- California State AGas victim2019-07-03
Sprint reported unauthorized access to customer accounts via the Samsung.com 'add a line' website using stolen credentials. The breach occurred between June 8 and June 23, 2019, and was discovered on June 22, 2019. Affected data included names, phone numbers, billing addresses, and account numbers. Sprint reset account PINs and re-secured accounts.
- New Hampshire State AGas victim2019-05-13
Sprint Corporation (Boost Mobile) notified the NH Attorney General of a brute force attack on Boost.com starting March 14, 2019. An unauthorized person accessed customer accounts using phone numbers and PIN codes. Access was blocked on March 18, 2019, and a permanent fix deployed April 1, 2019. 25,909 customers were impacted, including 17 New Hampshire residents. Affected data included credentials (PINs) and basic identity information (phone numbers). Sprint reset PINs and established a care team.
- California State AGas victim2019-05-09
On March 14, 2019, Boost Mobile (Sprint Corporation) experienced unauthorized online account activity where an unauthorized person accessed customer accounts using phone numbers and PIN codes. The incident was discovered by the fraud team, and a permanent solution was implemented. Customers were notified via SMS/WAP and advised to reset their PINs. No specific count of affected individuals was disclosed in the notice.
- Illinois State AGas victim2019-01-01
SPRINT filed a data-breach notice with the Illinois Attorney General during 2019 (case 2019-249). The register records the breach as discovered on June 22, 2019. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- California State AGas victim2017-09-20
Sprint reported a security incident involving a fraudulent device insurance claim attempted on customer accounts between May 7 and July 22, 2017. The incident compromised Sprint account Personal Identification Numbers (PINs) and/or security questions/answers. No other personal information was compromised, and no costs were incurred by customers. Sprint notified customers via SMS starting August 22, 2017, and reset credentials for those who had not updated them by August 24, 2017.