Personal customer information exposed in T-Mobile system glitch

The company also suffered a data breach impacting employees in April 2023

Add bookmark
A neon pink T-Mobile logo mounted on a glass wall

Telecommunications company T-Mobile has been accused of two data breaches – one caused by a “system glitch” that accidentally exposed the personal information of its customers and the other that allegedly exposed employee personal information.

The data breach was recognized by customers on September 20, who noticed that, upon logging into the T-Mobile app, that other customer’s information was being displayed instead of their own. This meant that personally identifying information including address, credit card information and purchase history was exposed. Those affected took to social media sites to post about the cyber security incident.

T-Mobile addressed the data breach, telling news site The Register that the cyber security incident affected less than 100 customers and was “quickly resolved”.

“There was no cyber attack or breach at T-Mobile. This was a temporary system glitch related to a planned overnight technology update involving limited account information for fewer than 100 customers,” a spokesperson explained to The Register.

While less than 100 customers’ data was impacted by the glitch, it has not been made public how many people their data was exposed to.

On September 22, vx underground, which refers to itself as “the largest collection of malware source code, samples, and papers on the internet”, posted allegations that T-Mobile had suffered a data breach in April of this year, which saw 90GB of employee’s personal data stolen. It was later clarified that the data breach impacted an independtly owned authorized T-Mobile retailer.

The leak was shared to infamous dark web hacking forum, BreachForum on September 21. Data stolen in the cyber attack allegedly included employee’s full names, job titles, social security numbers and email addresses, among other data.

T-Mobile addressed the breach, saying that it was a T-Mobile franchise, rather than T-Mobile corporate, which was the victim of a breach. According to the telecommunications company, the data breach was disclosed in court on May 10 of this year and affected 17,835 past and present employees.

Using this information, it has been suggested that independently owned T-Mobile dealer, Connectivity Source, was the victim of the data breach. 


Upcoming Events

Cyber Security for Healthcare

September 23 - 25, 2018

Fairmont Chicago – Millennium Park, IL

Cyber Security for Healthcare

7th Edition Cyber Security for Energy and Utilities 2018

27 - 29 March, 2018

Dusit Thani Hotel, Abu Dhabi, United Arab Emirates

7th Edition Cyber Security for Energy and Utilities 2018

Cyber Security for Financial Services Exchange 2018

June 10 - 12, 2018

Millennium Broadway Hotel, Times Square, NY

Cyber Security for Financial Services Exchange 2018

2nd Cyber Security Financial Services Exchange Asia

13 - 15 May, 2018

Grand West Sands Resort & Villas, Phuket, Thailand

2nd Cyber Security Financial Services Exchange Asia

CISO Exchange

March 11 - 13, 2018

Pullman Hotel San Francisco Bay, Redwood City, CA

CISO Exchange

Latest Webinars

From Dependencies to Defences: Navigating Software Supply Chain Security

2025-09-24

11:00 AM - 12:00 PM SGT

Learn how to defend your software supply chain from dependency threats and build resilient security...

Unpacking global regulatory frameworks to enhance third-party operational resilience

2024-11-14

11:00 AM - 12:00 PM EST

Join this webinar to explore the resilience-focused requirements of DORA, NIS2 and other global regu...

Preventing financial and reputational risk with process intelligence

2024-05-23

11:00 AM - 12:00 PM EDT

Learn how to manage risk stemming from poorly controlled processes in a collaborative way

Recommended