logo

T-Mobile: Leaky API Exposes Data on 37 Million

ID: 9d0e23f5-8262-5683-b50b-74298948270e

STIX ID: report--9d0e23f5-8262-5683-b50b-74298948270e

Feed Name: Security Ledger

Threat Score
75/100

Date Published: 2023-01-20

Date Updated: 2026-04-26

Author: Paul Roberts

...
...

T-Mobile disclosed that a threat actor exploited a vulnerable customer-facing API to access personal data for about 37 million customers (names, addresses, emails, phone numbers, dates of birth, account numbers and plan information) beginning around November 25, 2022 and discovered on January 5, 2023; the company states its network and customer financial data were not compromised and it has notified authorities and affected customers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.