T-Mobile confirmed Thursday that an unidentified malicious intruder breached its network in late November and stole data on 37 million customers, according to a regulatory filing.
“Our investigation is still ongoing, but the malicious activity appears to be fully contained at this time,” T-Mobile said, adding that the data was first accessed around Nov. 25 but wasn’t discovered for weeks later.
The firm added that it hired a cybersecurity company to investigate the breach. It’s also working with law enforcement and will notify customers if their information was leaked, according to the filing.
“As soon as our teams identified the issue, we shut it down within 24 hours. Our systems and policies prevented the most sensitive types of customer information from being accessed, and as a result, customer accounts and finances should not be put at risk directly by this event,” the statement said. “There is also no evidence that the bad actor breached or compromised T-Mobile’s network or systems.”
With the announcement, it means the company has been hacked multiple times in recent years. In its filing, T-Mobile said it did not expect the latest breach to have material impact on its operations.
But a senior analyst for Moody’s Investors Service, Neil Mack, said in a statement that the breach raises questions about management’s cyber governance and could alienate customers and attract scrutiny by the Federal Communications Commission and other regulators.
“While these cybersecurity breaches may not be systemic in nature, their frequency of occurrence at T-Mobile is an alarming outlier relative to telecom peers,” Mack said.
Prior to the August 2021 intrusion, the company disclosed breaches in January 2021, November 2019 and August 2018 in which customer information was accessed.
In July, T-Mobile agreed to pay $350 million to customers who filed a class action lawsuit after the company disclosed in August 2021 that personal data including Social Security numbers and driver’s license info had been stolen. Nearly 80 million U.S. residents were affected by the breach.
T-Mobile said Thursday that after the latest breach, it began a “substantial multi-year investment” to improve its cybersecurity two years ago. “Protecting our customers’ data remains a top priority,” the company said. “We will continue to make substantial investments to strengthen our cybersecurity program.”
T-Mobile, based in Washington state, became one of the United States’ largest cellphone service carriers in 2020 after buying rival Sprint. It reported having more than 102 million customers after the merger.