T-Mobile has issued a cybersecurity incident update to confirm that it has detected unauthorized access to its data. However, the company said it has yet to determine if customers’ information has been breached.
The mobile communications company said in its statement that it has started an investigation on the reported data breach and that it has been coordinating with law enforcement. “We have determined that unauthorized access to some T-Mobile data occurred, however we have not yet determined that there is any personal customer data involved,” the incident report reads.
The company’s confirmation comes after Motherboard reported on Sunday that hackers in an underground forum were claiming to have access to customer data. The sellers were reportedly offering “full customer info” that purportedly affects 100 million T-Mobile USA users. They were asking for 6 bitcoin, which currently converts to more than $270,000.
Hackers further claimed that the leaked data include customers’ names, phone numbers, and addresses. Other highly sensitive information like social security numbers, addresses, International Mobile Equipment Identity (IMEI) numbers that are unique to every phone, and driver license details were said to be part of the breach, per the hackers’ claims.
Flashpoint intelligence analyst Abigail Showman expressed concern about the leaked IMEI numbers, telling Wired that culprits could use it to launch SIM-swap attacks or SIM hijacking similar to what happened to some T-Mobile customers just last February. “This could lead to account takeover concerns since threat actors could gain access to two-factor authentication or one-time passwords tied to other accounts,” Showman explained.
While T-Mobile has yet to officially confirm that there was a data breach of this magnitude, Motherboard said it has seen samples of the for-sale information. The publication added it was able to confirm that the leaked data include “accurate information” of T-Mobile customers.
In the same statement, T-Mobile said it was able to secure the entry point that hackers exploited to access its servers. The hackers appear to have confirmed this as well after the seller reportedly said in the underground forum, “I think they already found out because we lost access to the backdoored servers.” But they also claimed that the data they gathered was already “backed up in multiple places.”
Photo by Mika Baumeister on Unsplash


Cybersecurity Stocks Tumble After Anthropic's Claude Mythos AI Leak Sparks Market Fears
SpaceX IPO Filing Expected This Week as Valuation Could Surpass $75 Billion
Microsoft Eyes $7B Texas Energy Deal to Power AI Data Centers
SpaceX Eyes Historic IPO at $1.75 Trillion Valuation
Reflection AI Eyes $25 Billion Valuation in Massive $2.5 Billion Funding Round
Meta and Google just lost a landmark social media addiction case. A tech law expert explains the fallout
Nanya Technology Shares Surge 10% After $2.5 Billion Private Placement from Sandisk and Cisco
Annie Altman Amends Sexual Abuse Lawsuit Against OpenAI CEO Sam Altman
Golden Dome Missile Defense: Anduril and Palantir Join Forces on Trump's $185B Space Shield
Rubio Directs U.S. Diplomats to Use X and Military Psyops to Counter Foreign Propaganda
NASA Artemis II: First Crewed Moon Mission Since Apollo Takes Four Astronauts on 10-Day Lunar Journey
California's AI Executive Order Pushes Responsible Tech Use in State Contracts
Palantir's Maven AI Earns Pentagon "Program of Record" Status, Reshaping Military AI Strategy
SMIC Allegedly Supplies Chipmaking Tools to Iran's Military, U.S. Officials Warn
OpenAI Pulls the Plug on Sora, Ending $1 Billion Disney Partnership
Elliott Investment Management Takes Multibillion-Dollar Stake in Synopsys
Elon Musk Announces Terafab: SpaceX and Tesla to Build Dual AI Chip Factories in Austin, Texas 



