Skip to content

T-Mobile

Disclosed Oct 9, 20205 years ago53,800,000 affectedSettled

Official notice

Cyberattack steals data of tens of millions of T-Mobile customers and applicants

T-Mobile said stolen files held data on about 7.8 million current postpaid accounts and just over 40 million former or prospective customers, including names, birth dates, Social Security numbers and driver's license details.

What is known

People affected53,800,000 (as reported by the organization)
DisclosedOct 9, 2020
DiscoveredAug 17, 2021
HappenedAug 12, 2021
AttackHacking
Data exposedNames, Government IDs, Source code, Internal documents, Dates of birth, Social Security numbers, Phone numbers
SectorTelecom · US
StatusSettled
Lawsuit or fine$350M class action settlement plus $150M security spending commitment (2022) (about $350M)

Sources

Source
Notice letter filed with the Delaware DOJ: T-Mobilet-mobile.com · Official notice
Lapsus$ hackers targeted T-Mobile source code in latest data breachtechcrunch.com · News
T-Mobile 8-K Ex. 99.1 (August 18, 2021)sec.gov · SEC filing
T-Mobile 8-K on class action settlement (July 22, 2022)sec.gov · SEC filing
Indiana Attorney General 2021 data breach report: T-Mobilein.gov · Official notice
Indiana Attorney General 2020 data breach report: T‐Mobilein.gov · Official notice

Notices filed

WhereFiledPeople
Indiana AGresidents of INOct 9, 20202
Indiana AGresidents of INFeb 9, 20216
Indiana AGresidents of INMar 31, 20211
ResearchtotalAug 18, 2021
Delaware DOJresidents of DEAug 19, 2021
ResearchtotalApr 22, 2022

Other breaches at T-Mobile

BreachAffected
Disclosed Aug 29, 2025Aug 29, 20251 year ago2
Abused API leaks account data of 37 million T-Mobile customersJan 19, 20233 years agoHacking37M
Disclosed Dec 31, 2013Dec 31, 201312 years agoUnknown
History of this record
  • 2026-09-25 · source: empty to https://www.in.gov/attorneygeneral/consumer-protection-division/id-theft-prevention/files/DB-Year-to-Date-Report-2020.pdf · backfill source
  • 2026-09-25 · disclosed: 2021-02-09 to 2020-10-09 · backfill source
  • 2026-09-25 · disclosed: 2021-08-18 to 2021-02-09 · backfill source
  • 2026-09-25 · status: confirmed to settled · seed source
  • 2026-09-25 · fine_usd: empty to 350000000 · seed source
  • 2026-09-25 · lawsuit: empty to $350M class action settlement plus $150M security spending commitment (2022) · seed source
  • 2026-09-25 · data_types: ["names","government-id","source-code","internal-docs"] to ["names","government-id","source-code","internal-docs","dob","ssn","phone"] · seed source
  • 2026-09-25 · disclosed: 2021-08-19 to 2021-08-18 · seed source
  • 2026-09-25 · summary: T-Mobile said a bad actor used stolen credentials to access internal systems housing operational tools software, and that the intrusion was quickly shut down. KrebsOnSecurity reported the Lapsus$ group stole source code for a range of T-Mob to T-Mobile said stolen files held data on about 7.8 million current postpaid accounts and just over 40 million former or prospective customers, including names, birth dates, Social Security numbers and driver's license details. · seed source
  • 2026-09-25 · title: Lapsus$ uses stolen credentials to access T-Mobile internal tools and source code to Cyberattack steals data of tens of millions of T-Mobile customers and applicants · seed source
  • 2026-09-25 · attack: unknown to hacking · seed source
  • 2026-09-25 · data_types: ["names","government-id"] to ["names","government-id","source-code","internal-docs"] · seed source
  • 2026-09-25 · summary: empty to T-Mobile said a bad actor used stolen credentials to access internal systems housing operational tools software, and that the intrusion was quickly shut down. KrebsOnSecurity reported the Lapsus$ group stole source code for a range of T-Mob · seed source
  • 2026-09-25 · title: empty to Lapsus$ uses stolen credentials to access T-Mobile internal tools and source code · seed source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Delaware DOJ), confirmed by Delaware DOJ. Record counts are as reported. Not legal advice.

Everything about T-Mobile

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.