T-Mobile
Disclosed Oct 9, 20205 years ago53,800,000 affectedSettled
Cyberattack steals data of tens of millions of T-Mobile customers and applicants
T-Mobile said stolen files held data on about 7.8 million current postpaid accounts and just over 40 million former or prospective customers, including names, birth dates, Social Security numbers and driver's license details.
What is known
| People affected | 53,800,000 (as reported by the organization) |
|---|---|
| Disclosed | Oct 9, 2020 |
| Discovered | Aug 17, 2021 |
| Happened | Aug 12, 2021 |
| Attack | Hacking |
| Data exposed | Names, Government IDs, Source code, Internal documents, Dates of birth, Social Security numbers, Phone numbers |
| Sector | Telecom · US |
| Status | Settled |
| Lawsuit or fine | $350M class action settlement plus $150M security spending commitment (2022) (about $350M) |
Sources
| Source | |
|---|---|
| Notice letter filed with the Delaware DOJ: T-Mobilet-mobile.com · Official notice | Official notice |
| Lapsus$ hackers targeted T-Mobile source code in latest data breachtechcrunch.com · News | News |
| T-Mobile 8-K Ex. 99.1 (August 18, 2021)sec.gov · SEC filing | SEC filing |
| T-Mobile 8-K on class action settlement (July 22, 2022)sec.gov · SEC filing | SEC filing |
| Indiana Attorney General 2021 data breach report: T-Mobilein.gov · Official notice | Official notice |
| Indiana Attorney General 2020 data breach report: T‐Mobilein.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| Indiana AGresidents of IN | Oct 9, 2020 | 2 |
| Indiana AGresidents of IN | Feb 9, 2021 | 6 |
| Indiana AGresidents of IN | Mar 31, 2021 | 1 |
| Researchtotal | Aug 18, 2021 | |
| Delaware DOJresidents of DE | Aug 19, 2021 | |
| Researchtotal | Apr 22, 2022 |
Other breaches at T-Mobile
| Breach | Affected | ||||
|---|---|---|---|---|---|
| Disclosed Aug 29, 2025Aug 29, 20251 year ago | Aug 29, 20251 year ago | Not stated | Telecom | Confirmed | 2 |
| Abused API leaks account data of 37 million T-Mobile customersJan 19, 20233 years agoHacking | Jan 19, 20233 years ago | Hacking | Telecom | Confirmed | 37M |
| Disclosed Dec 31, 2013Dec 31, 201312 years ago | Dec 31, 201312 years ago | Not stated | Telecom | Confirmed | Unknown |
History of this record
- 2026-09-25 · source: empty to https://www.in.gov/attorneygeneral/consumer-protection-division/id-theft-prevention/files/DB-Year-to-Date-Report-2020.pdf · backfill source
- 2026-09-25 · disclosed: 2021-02-09 to 2020-10-09 · backfill source
- 2026-09-25 · disclosed: 2021-08-18 to 2021-02-09 · backfill source
- 2026-09-25 · status: confirmed to settled · seed source
- 2026-09-25 · fine_usd: empty to 350000000 · seed source
- 2026-09-25 · lawsuit: empty to $350M class action settlement plus $150M security spending commitment (2022) · seed source
- 2026-09-25 · data_types: ["names","government-id","source-code","internal-docs"] to ["names","government-id","source-code","internal-docs","dob","ssn","phone"] · seed source
- 2026-09-25 · disclosed: 2021-08-19 to 2021-08-18 · seed source
- 2026-09-25 · summary: T-Mobile said a bad actor used stolen credentials to access internal systems housing operational tools software, and that the intrusion was quickly shut down. KrebsOnSecurity reported the Lapsus$ group stole source code for a range of T-Mob to T-Mobile said stolen files held data on about 7.8 million current postpaid accounts and just over 40 million former or prospective customers, including names, birth dates, Social Security numbers and driver's license details. · seed source
- 2026-09-25 · title: Lapsus$ uses stolen credentials to access T-Mobile internal tools and source code to Cyberattack steals data of tens of millions of T-Mobile customers and applicants · seed source
- 2026-09-25 · attack: unknown to hacking · seed source
- 2026-09-25 · data_types: ["names","government-id"] to ["names","government-id","source-code","internal-docs"] · seed source
- 2026-09-25 · summary: empty to T-Mobile said a bad actor used stolen credentials to access internal systems housing operational tools software, and that the intrusion was quickly shut down. KrebsOnSecurity reported the Lapsus$ group stole source code for a range of T-Mob · seed source
- 2026-09-25 · title: empty to Lapsus$ uses stolen credentials to access T-Mobile internal tools and source code · seed source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Delaware DOJ), confirmed by Delaware DOJ. Record counts are as reported. Not legal advice.