T-Mobile has warned millions of its customers that a threat actor used an Application Programming Interface (API) to gain access to some of their sensitive data.
In a warning published on the company’s website, T-Mobile tried to play down the importance of the incident, saying some “basic customer information (nearly all of which is the type widely available in marketing databases or directories)” was obtained.
The data, however, includes people’s names, billing addresses, email addresses, phone numbers, dates of birth, and account numbers, all valuable information for identity theft attacks, phishing, and similar social engineering attacks.
Millions of victims
Passwords, payment card information, Social Security numbers, government ID numbers, as well as financial account information, remained safe, the company confirmed. It also said its investigation concluded that there was no evidence of a breach in its networks or systems.
While the warning does not say how many people were affected by the breach, and which account types were compromised, a total of 37 million customers had their data accessed, including both prepaid and postpaid customers.
The attack was taking place between November 25, 2022, and January 5, 2023. It was on January 6 that T-Mobile finally cut the threat actors’ access.
The company reported the attack to both law enforcement and federal agencies in the United States, whose investigation is now ongoing, it was said. T-Mobile also added that it started notifying customers who might have had their data compromised.
The German telecommunications giant’s track record for data breaches is far from ideal. The company’s had multiple incidents over the years, including one in 2018, one in 2019, and at least three in 2020. In 2021, it was found that the company paid hundreds of thousands of dollars to not have its sensitive data leaked to the web, which happened anyway, and a year later, in 2022, confirmed being targeted by the Lapsus$ extortion gang.
- Keep your business safe with the best endpoint protection for small business
Via: BleepingComputer