T-Mobile US disclosed a cybersecurity incident where a bad actor accessed customer data via an unauthorized API call starting around November 25, 2022. The incident was discovered on January 5, 2023. Approximately 37 million customer accounts were affected, with data including names, billing addresses, emails, phone numbers, dates of birth, and account numbers exposed. Sensitive data like SSNs and payment info was not accessed. The activity is contained, and the investigation is ongoing.
Affected (this filing): 37,000,000