T-Mobile US and AT&T were slapped with hefty multimillion-dollar fines and public admonishment from the U.S. government tied to recent cybersecurity lapses that highlight a growing challenge for telecom operators sitting on tons of valuable consumer information.

T-Mobile US’ flogging was the most severe, with the carrier agreeing to fork over $31.5 million in total compensation split between a fine being paid to the U.S. Treasury and a financial commitment to bolster its cybersecurity stance. This bolstering is to include adopting more “robust modern architectures, like zero trust and phishing-resistant multifactor authentication.”

The settlement agreement also calls for T-Mobile US’ CISO to provide “regular reports to the board concerning T-Mobile’s cybersecurity posture and business risks posed by cybersecurity.”

The agreement is tied to several Federal Communications Commission (FCC) investigations into T-Mobile US cybersecurity breaches in 2021, 2022, and 2023. Those attacks revealed personal information on millions of T-Mobile US customers.

T-Mobile US after the 2021 attack, which one analyst said might have been “the largest carrier breach on record,” agreed to pay $350 million to compensate consumers hit by that cybersecurity breach and said it would spend $150 million on data security over the next 18 months. It also signed contracts with Mandiant and KPMG as part of a mea culpa.

Those efforts failed to prevent later attacks, including one in early 2023. That event lasted more than a month before it was noticed and impacted 37 million postpaid and prepaid customers and customers from Google’s Fi service that runs through T-Mobile US.

Neil Mack, VP and senior analyst at Moody’s Investors Service, claimed in a note at that time that the attack “raises questions about the company’s cyberrisk governance and management practices.”

“While these cybersecurity breaches may not be systemic in nature, their frequency of occurrence at T-Mobile is an alarming outlier relative to telecom peers, and it could negatively impact customer behavior, cause churn to spike, and potentially attract the scrutiny of the [Federal Communications Commission] and other regulators,” Mack wrote.

T-Mobile US earlier this year unveiled a cybersecurity “Trust Center” providing a clearer picture of the carrier’s cybersecurity posture, including access to T-Mobile US’ security documents, its International Organization for Standardization (ISO) 27001 certification, and Systems and Organization Controls (SOC) 2 audit reports. It also shows different vendors the telecom operator is using for its security systems, including Amazon Web Services (AWS) for hosting its cloud infrastructure, and its use of an intrusion prevention system (IPS), real-time common vulnerabilities and exposure (CVE)-based threat protection and security information and event management (SIEM) systems.

Jeff Simon, SVP and chief security officer at T-Mobile US, touted in a blog post that the carrier recently garnered that ISO certification and SOC Type 2 report.

“This report involves independent analysis of the security, availability, processing integrity, confidentiality and privacy of key systems and data over a period of 3 months to ensure we meet the highest standards set by the American Institute of Certified Public Accountants (AICPA),” Simon wrote of the telecom operator’s efforts.

Simon also noted the carrier is working with ImmuniWeb and Bitsight to benchmark areas for potential improvement and has revamped a recently launched bug bounty program to further flesh out possible attack vectors.

“As of today, we’ve secured an ‘A’ rating from ImmuniWeb and a 780/900 score from Bitsight,” Simon wrote. “While there’s room for improvement, these scores underpin the success of our hard work over the past few years.”

AT&T fined $13 million for cybersecurity breach

AT&T was hit with a more modest $13 million fine tied to a customer information breach from data that was stored by cloud data provider Snowflake.

The settlement noted that AT&T failed to ensure that its data storage vendor properly handled customer data. The carrier agreed to implement more robust data governance practices to bolster its “supply chain integrity.”

AT&T fessed up to the cyberattack in a Securities and Exchange Commission (SEC) filing that was initially filed in early May, but was not released until July 12. In it, the carrier states that on April 19 it learned of a “threat actor” that claimed to have hacked into a database at a third-party cloud platform, later shown to be Snowflake, used by the carrier where they accessed and copied AT&T call logs.

That information included records of “customer call and text interactions” that happened between May 1 and Oct. 31 of 2022 and on Jan. 2, 2023. That data included records of calls and texts of “nearly all of AT&T’s wireless customers and customers of mobile virtual network operators (MVNOs) using AT&T’s wireless network.”

AT&T noted in the filing that it believes the attacker had access to the data beginning on April 14 and had access until April 25, which was six days after AT&T first learned of a potential attack. The carrier did notify the U.S. Department of Justice (DoJ) after it learned of the attack as required by law but was provided with two deferments on having to publicly release information that it was breached. The AT&T data was rumored to have been in circulation on the dark web before April 1.

AT&T added that it believes at least one person tied to the cybersecurity attack has been detained and “that it does not believe the data is publicly available.”

AT&T CEO John Stankey during the carrier’s second-quarter earnings call expressed disappointment over the breach.

“There’s nobody more disappointed that we have to actually address your question and work through these issues than I am,” Stankey said in response to a question during the call.

Stankey laid some of the blame for the data breach on “geopolitical dynamics that are going on,” which “are putting pressure on that.” The breach is reported to have been carried out by the ShinyHunters group that has ties to Russia.

“Good companies just like ours are all having to learn some new things and are seeing new threats and new environments that they have to adjust to,” Stankey added.

The T-Mobile US and AT&T fines come just a couple of months after the FCC hit Verizon with $16 million in fines tied to cybersecurity breaches at its TracFone subsidiary. Results of that investigation found that the data breaches involved exploitation of APIs.