T-Mobile Data Breach – Phone numbers & Call Records Exposed

United States telecommunications giant T-Mobile has unveiled that the personal data of its employees and customers have been hacked. This is the second security breach T-Mobile has admitted in the last six months.

T-Mobile Data Breach

“The Cybersecurity team discovered and shut down malicious, unauthorized access to some information related to the T-Mobile account”, T-Mobile said in a notice of data breach.

The data accessed did not include names on the account, physical or email addresses, financial data, credit card information, social security numbers, tax ID, passwords, or PINs.

With support from leading cybersecurity forensics experts, the company started an investigation to determine what happened and what information was involved.

What information was involved?

T-Mobile has found that threat actors gained access to telecommunications information generated by customers, known as CPNI.

Customer Proprietary Network Information (CPNI) as defined by the Federal Communications Commission (FCC) rules was accessed.

The CPNI accessed can include a phone number, number of lines in an account and some cases, call-related information collected as part of the normal operation of wireless service.

Measures Executed by T-Mobile

The company is sending out SMS notifications to all impacted users. The company also informed that those who received the text alert about this breach should be on the lookout for suspicious texts claiming to be from T-Mobile asking for information or containing links to non-T-Mobile web pages.

It is not uncommon for threat actors to use stolen information for further targeted phishing campaigns that attempt to steal sensitive information such as login names and passwords.

T-Mobile earlier suffered from breaches in 2018 that exposed customer information, in 2019 for prepaid customers, and in March 2020 that exposed customer and financial data.

As a final point, the company ensures to work further to enhance security measures to mitigate these types of activities.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

3 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

13 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

14 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

14 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

14 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

14 hours ago