T-Mobile US reported yet another security breach that impacted a limited number of customers, compiling what has been a recent rash of such cyberattacks impacting the carrier.
The latest breach, which was initially reported by BleepingComputer, impacted 836 customers. A report filed with the Maine Attorney General indicates the “external system breach” began February 24, was discovered on March 27, but continued until March 30.
In an accompanying letter to impacted customers, T-Mobile US said the breach might have exposed customer names, contact information, account numbers and associated phone numbers, T-Mobile account PINs, Social Security numbers, government IDs, dates of birth, balances due, internal codes used by T-Mobile US and the number of lines of service.
T-Mobile US noted it had proactively reset PIN numbers for customers that might have been impacted by the breach. It’s also offering two years of credit monitoring and identity theft detection services to customers that elect to sign up for those services.
T-Mobile US cyberattack track recordThe latest breach follows up on a much larger attack that was reported earlier this year. That event last more than a month before it was noticed and impacted 37 million postpaid and prepaid customers and customers from Google’s Fi mobile virtual network operator (MVNO) service that runs through T-Mobile US.
T-Mobile US explained in a Securities and Exchange Commission (SEC) filing that the attackers were able to gain access to “basic customer information,” which it tried to downplay by stating “nearly all of which is the type widely available in marketing databases or directories.”
That accessed information included names, billing addresses, emails, phone numbers, dates of birth, account numbers, and information such as the number of lines on an account and service plan features. The carrier confidently stated, “no passwords, payment card information, social security numbers, government ID numbers, or other financial account information were compromised.”
“We understand that an incident like this has an impact on our customers and regret that this occurred,” the statement added. “While we, like any other company, are unfortunately not immune to this type of criminal activity, we plan to continue to make substantial, multi-year investments in strengthening our cybersecurity program.”
Neil Mack, VP and senior analyst at Moody’s Investors Service, claimed in a note that the attack “raises questions about the company’s cyberrisk governance and management practices.”
“While these cybersecurity breaches may not be systemic in nature, their frequency of occurrence at T-Mobile is an alarming outlier relative to telecom peers, and it could negatively impact customer behavior, cause churn to spike, and potentially attract the scrutiny of the [Federal Communications Commission] and other regulators,” Mack wrote.
That attack came on the heels of a mid-2021 attack that one analyst said might have been “the largest carrier breach on record.” T-Mobile US last year agreed to pay $350 million to compensate consumers hit by that cybersecurity breach and said it will spend $150 million on data security over the next 18 months.
T-Mobile US CEO Mike Sievert during the carrier’s full-year 2022 earnings call said that investment allowed the operator to reduce the blast radius of the most recent attacks.
“While I am disappointed that the criminal actor was able to obtain any customer information, we are confident that our aggressive cybersecurity plan, working with the support of some of the world’s experts, will allow us to achieve our goal of becoming second-to-none in this area,” Sievert stated.
Comments