vz-risk / VCDB

VERIS Community Database
Other
578 stars 180 forks source link

T-Mobile data breach exposes about 37 mln accounts #19377

Open swidup opened 1 year ago

swidup commented 1 year ago

https://www.reuters.com/technology/t-mobile-says-investigating-data-breach-affecting-37-mln-accounts-2023-01-19/

https://www.cnet.com/tech/mobile/another-data-breach-has-hit-t-mobile-impacting-37-million-accounts/

swidup commented 1 year ago

https://www.bleepingcomputer.com/news/security/t-mobile-hacked-to-steal-data-of-37-million-accounts-in-api-data-breach/

https://techcrunch.com/2023/01/19/t-mobile-data-breach/

etgifford commented 11 months ago

https://www.sec.gov/ix?doc=/Archives/edgar/data/0001283699/000119312523010949/d641142d8k.htm https://www.t-mobile.com/news/business/customer-information

etgifford commented 11 months ago

T-Mobile, HQ: Bellevue, WA, EMP: 71000, NAICS: 81811 (telephony and wireless, telecommunications) identified malicious activity Jan 5, 2023 and contained it within a day. The hackers did not breach any company system, but rather abused an application programming interface (API). The company's API revealed other user information for 37MM users: names, billing addresses, email addresses, phone numbers and birth dates of its customers, their T-Mobile account numbers, and information on which plan features they have with the carrier and the number of lines on their accounts. The breach first occurred Nov 25, 2022. Notification was published on their website Jan 19, 2023.