T-Mobile US has again been hit with a cyberattack despite agreeing just months ago to spend $500 million on data security and customer remediation efforts that came off the back of what one analyst called “the largest carrier breach on record.”

The carrier noted in a statement late Thursday that it was “in the process of informing impacted customers that after a thorough investigation we have determined that a bad actor used a single [API] to obtain limited types of information on their accounts.”

“While no information was obtained for impacted customers that would compromise the safety of customer accounts or finances, we want to be transparent with our customers and ensure they are aware,” the carrier added.

In an accompanying Securities and Exchange Commission (SEC) filing, the carrier said the breach began around November 25, and impacted 37 million current postpaid and prepaid customer accounts.

T-Mobile US explained that it believes attackers were only able to gain access to “basic customer information,” which it tried to downplay by stating “nearly all of which is the type widely available in marketing databases or directories.”

That accessed information included names, billing addresses, emails, phone numbers, dates of birth, account numbers, and information such as the number of lines on an account and service plan features. The carrier confidently stated, “no passwords, payment card information, social security numbers, government ID numbers, or other financial account information were compromised.”

“We understand that an incident like this has an impact on our customers and regret that this occurred,” the statement added. “While we, like any other company, are unfortunately not immune to this type of criminal activity, we plan to continue to make substantial, multi-year investments in strengthening our cybersecurity program.”

T-Mobile US did not respond by press time for more details on the attack.

Neil Mack, VP and senior analyst at Moody’s Investors Service, claimed in a note that the attack “raises questions about the company’s cyberrisk governance and management practices.”

“While these cybersecurity breaches may not be systemic in nature, their frequency of occurrence at T-Mobile is an alarming outlier relative to telecom peers, and it could negatively impact customer behavior, cause churn to spike, and potentially attract the scrutiny of the [Federal Communications Commission] and other regulators,” Mack wrote.

Another T-Mobile US Cyberattack?!?

T-Mobile US has been repeatedly hacked over the past several years, with analysts counting at least six successful cyberattacks against the carrier over a four-year period prior to the latest breach.

“T-Mobile has been a favorite target of hackers over the past few years, and they really need a complete rethink of security,” Zeus Kerravala, principal analyst at ZK Research, said in connection to a mid-2021 attack, adding, “I believe this is the largest carrier breach on record.”

That data included in that attack involved names, phone numbers, social security numbers, physical addresses, unique device identifier data, security PINs, and drivers license information, according to Vice, which initially reported that cyberattack and viewed samples of the compromised data.

T-Mobile US last year agreed to pay $350 million to compensate consumers hit by that cybersecurity breach and said it will spend $150 million on data security over the next 18 months.

The breach comes on the heels of T-Mobile US hitting a significant cloudification milestone for its growing 5G network. The carrier late last year stated it had launched a Cisco-powered cloud-native 5G core gateway platform that sets the operator up to more quickly standup new services and can help it better monetize its 5G network investments.

The carrier explained that system’s embedded automation simplifies “network functions across the cloud, edge, and data centers to significantly reduce operational lifecycle management.” The distributed nature of T-Mobile US’ 5G standalone (SA) core running in that environment also provides a reported 10% improvement in speed and latency, which is key for mobile edge computing (MEC) use cases.