TechBriefly
  • Tech
  • Business
  • Crypto
  • Science
  • Geek
  • How to
  • About
    • About TechBriefly
    • Terms and Conditions
    • Privacy Policy
    • Contact Us
    • Languages
      • 中文 (Chinese)
      • Dansk
      • Deutsch
      • Español
      • English
      • Français
      • Nederlands
      • Italiano
      • 日本语 (Japanese)
      • 한국인 (Korean)
      • Norsk
      • Polski
      • Português
      • Pусский (Russian)
      • Suomalainen
      • Svenska
  • FAQ
    • Articles
No Result
View All Result
 Hot Topics:
  • Diablo 4 class guide
  • Snapchat planets order
  • Microsoft AI copilot
  • GPT-4
  • Binance WOTD answers (Technical Analysis)
TechBriefly
No Result
View All Result
Home Tech Security

T-Mobile data breach: 37 million accounts impacted

On Thursday, T-Mobile disclosed that the data breach began on November 25, 2022 and the attacker had been accessing the impacted API

by Kerem Gülen
20 January 2023
in Security, Tech
Reading Time: 2 mins read
T-Mobile data breach
Share on FacebookShare on Twitter

T-Mobile recently announced a data breach in which a hacker obtained personal information of 37 million current postpaid and prepaid customer accounts by exploiting one of its Application Programming Interfaces (APIs). APIs are software interfaces that allow applications and computers to communicate with each other.

Many online web services use APIs to allow their online apps or external partners to access internal data by providing the correct authentication tokens. T-Mobile did not specify how their API was compromised, but it is common for hackers to exploit flaws in APIs to retrieve data without proper authentication.

New T-Mobile data breach affects 37 million accounts

On Thursday, T-Mobile disclosed that the data breach began on November 25, 2022 and the attacker had been accessing the impacted API. The company detected the unauthorized activity on January 5, 2023, and immediately cut off the attacker’s access to the API on the following day.

T-Mobile data breach
On Thursday, T-Mobile disclosed that the data breach began on November 25, 2022

T-Mobile also stated that the API that was targeted did not provide the attacker access to sensitive information such as driver’s licenses, government ID numbers, social security numbers/tax IDs, passwords/PINs, payment card information, or other financial account information of the affected customers.

“Rather, the impacted API is only able to provide a limited set of customer account data, including name, billing address, email, phone number, date of birth, T-Mobile account number and information such as the number of lines on the account and plan features. The preliminary result from our investigation indicates that the bad actor(s) obtained data from this API for approximately 37 million current postpaid and prepaid customer accounts, though many of these accounts did not include the full data set,” stated T-Mobile.

In a separate statement, T-Mobile defined the data stolen in this attack as “basic customer information.” The company has reported the incident to relevant federal agencies in the US and is cooperating with law enforcement to investigate the breach. T-Mobile is also informing customers whose personal information may have been compromised as a result of the breach.

T-Mobile data breach
The company has reported the incident to relevant federal agencies in the US

“We understand that an incident like this has an impact on our customers and regret that this occurred. While we, like any other company, are unfortunately not immune to this type of criminal activity, we plan to continue to make substantial, multi-year investments in strengthening our cybersecurity program. Our investigation is still ongoing, but the malicious activity appears to be fully contained at this time, and there is currently no evidence that the bad actor was able to breach or compromise our systems or our network,” T-Mobile stated.

T-Mobile is suffering from data breaches since 2018

This is the eighth data breach that T-Mobile has disclosed since 2018. The latest incident is the first one reported in 2023, but the company has had seven other breaches since 2018, including one where attackers gained access to data of roughly 3% of all T-Mobile customers.

In 2019, T-Mobile exposed prepaid customers’ data and in 2020, unknown threat actors accessed T-Mobile employees’ email accounts.

T-Mobile data breach
This is the eighth data breach that T-Mobile has disclosed since 2018

In December 2020, unknown threat actors also gained access to customer proprietary network information (phone numbers, call records) and in February 2021, attackers accessed an internal T-Mobile application without authorization.

In August 2021, hackers breached T-Mobile’s network after a security breach of the carrier’s testing environments. Despite paying the attackers $270,000 through a third-party firm, T-Mobile failed to prevent the stolen data from being leaked online. The company also confirmed in April 2022 that the Lapsus$ extortion gang had breached its network using stolen credentials.

 

Tags: data breachfeaturedt-mobile

Related Posts

You can finally try Google Bard AI

You can finally try Google Bard AI

How to use Bing Image Creator?

Bing Image Creator brings image generation feature via OpenAI’s DALL-E

iPhone 15

iPhone 15 will free you from unwanted calls

Ferrari data breach exposes customer information

Ferrari data breach exposes customer information, payment data safe

POPULAR

Diablo 4 class guide: Which class is best for you?

Fly away your assigments with Microsoft AI copilot

Is knowing ChatGPT the key to getting hired: Yes, Japanese startup says

Meta double downs on layoffs

ChatGPT prompt comparison: GPT-4 vs GPT-3.5

10 ways GPT-4 outperforms ChatGPT: A comparative analysis

New teacher in Duolingo: GPT-4 powered AI tutor

All LoLdle answers today (17.03): My last whisper will be yogurt mold

Sims 4 Growing Together not downloading error exlained

How to try GPT-4 and unlock the power of the most advanced chatbot?

RSS News Republic

  • Countdown to NHL Playoffs 2023: Format, rounds, and game schedules
  • Explained: How to have twins in BitLife?
  • DTB meaning and usage explained
  • TikTok Cold Moon Massacre: Story about Angela Parsons explained
  • AI prompt engineering 101

RSS Digital Report

  • What is the “Framing Effect” in marketing and how to use it?
  • How does in-house SEO compare to utilizing agencies and how to get started with it?
  • Hoping onto other blockchains using cross-chain bridges
  • UVP in marketing: Definition and more
  • Top 20 effective marketing tools

RSS Latest from LeaderGamer

  • Star Wars Jedi Survivor characters
  • CS GO FPS boost code
  • Wordle TR 22 Mart 2023 günün cevabı
  • Hyenas release date, story, gameplay
  • Final Fantasy 16 duration – How many hours does Final Fantasy 16 take?
TechBriefly

© 2021 TechBriefly is a Linkmedya brand.

  • Tech
  • Business
  • Science
  • Geek
  • How to
  • About
  • Privacy
  • Terms
  • Contact
  • FAQ
  • | Network Sites |
  • Digital Report
  • LeaderGamer
  • News Republic

Follow Us

No Result
View All Result
  • Tech
  • Business
  • Crypto
  • Science
  • Geek
  • How to
  • About
    • About TechBriefly
    • Terms and Conditions
    • Privacy Policy
    • Contact Us
    • Languages
      • 中文 (Chinese)
      • Dansk
      • Deutsch
      • Español
      • English
      • Français
      • Nederlands
      • Italiano
      • 日本语 (Japanese)
      • 한국인 (Korean)
      • Norsk
      • Polski
      • Português
      • Pусский (Russian)
      • Suomalainen
      • Svenska
  • FAQ
    • Articles