T-Mobile 5G telco
– Sebastian Moss

T-Mobile US unveiled a cybersecurity “Trust Center” providing a clearer picture of the carrier’s cybersecurity posture that has come under scrutiny following several hacks that compromised customer information.

The new public facing site provides access to T-Mobile US’ security documents, including its International Organization for Standardization (ISO) 27001 certification and Systems and Organization Controls (SOC) 2 audit reports. It also shows different vendors the telecom operator is using for its security systems, including Amazon Web Services (AWS) for hosting its cloud infrastructure, and its use of an intrusion prevention system (IPS), real-time common vulnerabilities and exposure (CVE)-based threat protection and security information and event management (SIEM) systems.

Jeff Simon, SVP and chief security officer at T-Mobile US, touted in a blog post that the carrier recently garnered that ISO certification and SOC Type 2 report.

“This report involves independent analysis of the security, availability, processing integrity, confidentiality and privacy of key systems and data over a period of 3 months to ensure we meet the highest standards set by the American Institute of Certified Public Accountants (AICPA),” Simon wrote of the telecom operator's efforts.

Simon also noted the carrier is working with ImmuniWeb and Bitsight to benchmark areas for potential improvement and has revamped a recently launched bug bounty program to further flesh out possible attack vectors.

“As of today, we’ve secured an ‘A’ rating from ImmuniWeb and a 780/900 score from Bitsight,” Simon wrote. “While there’s room for improvement, these scores underpin the success of our hard work over the past few years.”

T-Mobile US’ cybersecurity has struggled

Simon’s work with the carrier began in May 2023, when he joined T-Mobile US as its chief sustainability officer (CSO). Simon had previously spent more than 13 years at fintech security firm FIS.

Simon joined T-Mobile US shortly after one of many cybersecurity breaches to hit the carrier over a several year period. That attack was a relatively small breach that impacted 836 customers.

However, it came on the heels of a much larger attack that was reported in early 2023. That event lasted more than a month before it was noticed and impacted 37 million postpaid and prepaid customers and customers from Google’s Fi service that runs through T-Mobile US.

T-Mobile US explained in a Securities and Exchange Commission (SEC) filing that the attackers were able to gain access to “basic customer information,” which it tried to downplay by stating “nearly all of which is the type widely available in marketing databases or directories.”

That accessed information included names, billing addresses, emails, phone numbers, dates of birth, account numbers, and information such as the number of lines on an account and service plan features. The carrier confidently stated, “no passwords, payment card information, social security numbers, government ID numbers, or other financial account information were compromised.”

“We understand that an incident like this has an impact on our customers and regret that this occurred,” the statement added. “While we, like any other company, are unfortunately not immune to this type of criminal activity, we plan to continue to make substantial, multi-year investments in strengthening our cybersecurity program.”

Neil Mack, VP and senior analyst at Moody’s Investors Service, claimed in a note that the attack “raises questions about the company’s cyberrisk governance and management practices.”

“While these cybersecurity breaches may not be systemic in nature, their frequency of occurrence at T-Mobile is an alarming outlier relative to telecom peers, and it could negatively impact customer behavior, cause churn to spike, and potentially attract the scrutiny of the [Federal Communications Commission] and other regulators,” Mack wrote.

That attack came on the heels of a mid-2021 attack that one analyst said might have been “the largest carrier breach on record.” T-Mobile US last year agreed to pay $350 million to compensate consumers hit by that cybersecurity breach and said it will spend $150 million on data security over the next 18 months.

T-Mobile US CEO Mike Sievert during the carrier’s full-year 2022 earnings call said that investment allowed the operator to reduce the blast radius of the most recent attacks.

“While I am disappointed that the criminal actor was able to obtain any customer information, we are confident that our aggressive cybersecurity plan, working with the support of some of the world’s experts, will allow us to achieve our goal of becoming second-to-none in this area,” Sievert stated.