Skip to content
cisonews.net

Incident · 8-K Item 8.01

T-Mobile reports data for about 37 million accounts obtained through an API

Compiled 2026-09-27 from public records. By the cisonews.net Desk.

T-Mobile US disclosed on January 19, 2023 that a bad actor had been obtaining customer account data through a single application programming interface without authorization. The company identified the activity on January 5 and said it traced and stopped it within a day. Its estimate was data from approximately 37 million postpaid and prepaid accounts.

What T-Mobile reported

The scale was given as a preliminary figure.

The company said the API could return name, billing address, email, phone number, date of birth, account number and plan details, but not payment card data, Social Security or tax ID numbers, passwords or other government IDs. It dated the start of the data retrieval to around November 25, 2022. That means the activity ran for roughly six weeks before detection.

Materiality

T-Mobile said it might incur significant expenses but did not expect a material effect on operations. The filing does not explain how the API was reached.

Sources

  1. 2023-01-19 · AT-Mobile US, Inc., Form 8-K (SEC EDGAR), published January 19, 2023

Tier A: the organization itself, a regulator or SEC EDGAR. Tier B: established press. Each fact on this page carries its supporting passage in the page source.

See an error? Corrections are made on the page and logged on the corrections page. Send them through contact.