Affiliate Disclosure
If you buy through our links, we may get a commission. Read our ethics policy.

Hackers selling data on 100M T-Mobile customers after server attack

Last updated

T-Mobile is looking into a breach of its servers that has apparently resulted in harvested data on over 100 million customers being sold on a hacker forum.

On Sunday, T-Mobile confirmed it was investigating a post on a hacker forum claiming to sell a cache of data relating to its customers. It is claimed by the poster that they had managed to acquire the data on over 100 million people, taken from servers operated by the carrier.

The data stems from "T-Mobile USA. Full customer info," the forum poster told Motherboard, and that multiple servers were compromised to get it.

The trove of data appears to consist of names, phone numbers, physical addresses, IMEI numbers, driver license information, and social security numbers. Samples obtained in reports appear to be genuine.

According to cybersecurity firm Cyble speaking to BleepingComputer, the attacker claims to have stolen multiple databases, acquiring some 106GB of data in the process.

The seller was openly offering data on 30 million social security numbers and driver licenses via the forum, requesting 6 bitcoin ($283,000) for the trove. They said the rest of the data is being sold privately through other deals.

It is believed that T-Mobile knows about the intrusion, as the seller said "I think they already found out because we lost access to the backdoored servers."

In its statement, T-Mobile says it is "aware of claims made in an underground forum and have been actively investigating their validity. We do not have any additional information to share at this time."

The hack is the latest for the carrier, and probably the biggest it has suffered so far. In 2018, a breach saw data on 2 million customers swiped, followed by another breach in 2019.

With some 104.8 million subscribers as of Q2 2021, the latest breach may have theoretically affected almost all of T-Mobile's customers.



17 Comments

Dogperson 137 comments · 4 Years

Not just this company, but ALL the personal info hacks - WHY IS NONE OF THIS INFORMATION ENCRYPTED???????

tedz98 80 comments · 6 Years

Even if the data is encrypted, if your hack is through a compromised userid and password the data will be decrypted. The real question should be why there isn’t two factor authentication?

MacPro 19845 comments · 18 Years

Next T-Mobile Ad, 'We 5G have coverage everywhere, so is your data!" ;)

davgreg 1050 comments · 9 Years

MacPro said:
Next T-Mobile Ad, 'We 5G have coverage everywhere, so is your data!" ;)

Do not worry, your data has already been compromised.
Between all the differing hacks over the years, your info sits in some database for sale.

Cannot believe that anyone would be stupid enough to give a Social Security number for a cell phone.

OutdoorAppDeveloper 1292 comments · 15 Years

Dogperson said:
Not just this company, but ALL the personal info hacks - WHY IS NONE OF THIS INFORMATION ENCRYPTED???????

Great question. Why is none of your information encrypted on iCloud? We know it isn't because Apple can scan your photos for illegal images and then have humans review them before sending all your data unencrypted to the government.