← Blog

T-Mobile Data Breaches: Full Timeline Through 2026

Share on X

People search T-Mobile data breach timeline because the brand sits on billions of accounts, credentials, and cloud workloads. BreachHistory indexes 15 T-Mobile-linked incidents, with headline counts up to 76M+ in catalog rows. This page maps every attested event through 2026 with internal links to canonical records.

Why T-Mobile breach history matters

T-Mobile operates in Technology (United States). Across indexed rows, recurring themes include unverified actor or scraping claims. Understanding the chronological pattern helps security teams, customers, and regulators separate confirmed disclosures from forum marketing.

Full timeline through 2026

2023 — — 37M records

Cataloged incident. Hacked. 37M records. Exposed categories include Names, emails, addresses, and other PII. BreachHistory cites approximately 370 affected records in this row. See the t-mobile-20232023 and canonical BreachHistory entry.

2023 — — T-Mobile: Hacking, 37,000,000 records

Cataloged incident. Data breach reported. telecom organization. Method: hacked. Source: Wikipedia List of data breaches. Exposed categories include Personal and demographic data. BreachHistory cites approximately 37M+ affected records in this row. See the t-mobile2023-37000000-wiki2 and canonical BreachHistory entry.

2021 — — 54M records

Cataloged incident. Hacked. 54M records. Exposed categories include Names, emails, addresses, and other PII. BreachHistory cites approximately 540 affected records in this row. See the t-mobile2021 and canonical BreachHistory entry.

2021 — — T-Mobile: Hacking, 76,000,000 records

Cataloged incident. Exposed the names, date of birth, Social Security number and driver's license/ID information of more than 40 million current, former or prospective customers who applied for credit with the company. Exposed categories include Personal and demographic data. BreachHistory cites approximately 76M+ affected records in this row. See the t-mobile2021-iib and canonical BreachHistory entry.

2021 — — T-Mobile: Hacking, 45,000,000 records

Cataloged incident. Data breach reported. telecom organization. Method: hacked. Source: Wikipedia List of data breaches. Exposed categories include Personal and demographic data. BreachHistory cites approximately 45M+ affected records in this row. See the t-mobile2021-45000000-wiki2 and canonical BreachHistory entry.

2020 — — T-mobile: Hacking, 200,000 records

Cataloged incident. The information exposed in this breach includes phone numbers, call records, and the number of lines on an account. Exposed categories include Personal and demographic data. BreachHistory cites approximately 200K+ affected records in this row. See the t-mobile2020-iib and canonical BreachHistory entry.

2018 — — T-Mobile: ZDNet's Zach Whittaker reports:A bug in T-Mobile's…

Cataloged incident. ZDNet's Zach Whittaker reports:A bug in T-Mobile's website let anyone access the personal account details of any customer with just their cell phone number.The flaw, since fixed, could have been exploited by anyone who knew where to look -- a little-known T-Mobile subdomain that staff use as a customer care portal to access the company's internal tools. The subdomain -- promotool.t-mobile.com, which can be easily found on search engines -- contained a hidden API that would return T-Mobile custom Exposed categories include Personal information. BreachHistory cites approximately 74M+ affected records in this row. See the t-mobile2018 and canonical BreachHistory entry.

2018 — — T-Mobile: Hacking, 2,000,000 records

Cataloged incident. Personal data along with passwords encrypted by a notoriously weak algorithm (MD5) were stolen. Exposed categories include Personal and demographic data. BreachHistory cites approximately 2M+ affected records in this row. See the t-mobile2018-iib and canonical BreachHistory entry.

2017 — — T-Mobile: A bug on T-Mobile‘s website may have allowed…

Cataloged incident. A bug on T-Mobile‘s website may have allowed hackers to view your personal information. The bug, which has since been patched, allowed hackers to view your email address, account number, and even your phone’s IMSI number (a unique number that identifies subscribers). According to the researcher that found the bug, there was no way to prevent someone writing a script and finding out the information for all 69.6 million potential victims. Exposed categories include Personal information. BreachHistory cites approximately 69.6M+ affected records in this row. See the t-mobile2017 and canonical BreachHistory entry.

2016 — — T-Mobile: On Wednesday afternoon, T-Mobile unveiled a new…

Cataloged incident. On Wednesday afternoon, T-Mobile unveiled a new program called Digits, which will allow T-Mobile subscribers to use a single mobile phone number across multiple devices and use multiple phone numbers on a single device. Unfortunately, the launch of the exciting new Digits beta was quickly overshadowed by a major error on T-Mobile’s website that was sharing private account information with anyone who visited the sign-up page for the beta program.According to multiple Twitter users, the form on T- Exposed categories include Personal information. No attested victim count is published for this row yet. See the t-mobile2016 and canonical BreachHistory entry.

2013 — — T-Mobile: A supplier for T-Mobile reported a breach of files…

Cataloged incident. A  supplier  for T-Mobile reported a breach of files stored on their servers. This breach included the breach of names, addresses, Social Seurity numbers and/or Driver's License numbers. This access was discovered in late November 2013.  They believe that the primary goal of the hackers was to obtain credit card data, but credit card information was not included in these files. Exposed categories include Personal information. No attested victim count is published for this row yet. See the t-mobile2013 and canonical BreachHistory entry.

2012 — — T-Mobile: A hacker or hackers accessed and posted online…

Cataloged incident. A hacker or hackers accessed and posted online information.  A total of 44 employee names, email addresses, phone numbers, and passwords were exposed. Exposed categories include Personal information. BreachHistory cites approximately 44 affected records in this row. See the t-mobile2012 and canonical BreachHistory entry.

2009 — — T-Mobile: T-Mobile USA is investigating claims that a hacker…

Unverified claim — treat actor counts cautiously. T-Mobile USA is investigating claims that a hacker has broken into its data bases and stolen customer and company information. Someone anonymously posted the claims on the security mailing list Full Disclosure. In that post, the hacker claims to have gotten access to everything -- their databases, confidential documents, scripts and programs from their servers, financial documents up to 2009. They claim they have been in touch wit Exposed categories include Personal information. No attested victim count is published for this row yet. See the t-mobile2009 and canonical BreachHistory entry.

2006 — — T-Mobile: A laptop computer holding personally identifiable…

Cataloged incident. A laptop computer holding personally identifiable information of approximately 43,000 current and former T-Mobile employees disappeared from a T-Mobile employee's checked luggage. T-Mobile has reportedly sent letters to all those affected. The data are believed to include names, addresses, SSNs, dates of birth and compensation information. Exposed categories include Personal information. BreachHistory cites approximately 43K+ affected records in this row. See the t-mobile2006 and canonical BreachHistory entry.

2006 — — T-Mobile, Deutsche Telekom: Lost / stolen device, 17,000,000 records

Cataloged incident. Data breach reported. telecoms organization. Method: lost / stolen media. Source: Wikipedia List of data breaches. Exposed categories include Personal and demographic data. BreachHistory cites approximately 17M+ affected records in this row. See the t-mobile2006-17000000-wiki2 and canonical BreachHistory entry.

Patterns and analysis

  • Unverified actor or scraping claims — appears across multiple T-Mobile catalog entries; prioritize controls that address this class of failure.
  • Record-count hygiene — BreachHistory indexes actor-cited figures separately from company-confirmed totals; read each row's technicalWriteup before treating counts as fact.
  • 2026 monitoring — New disclosures roll into this timeline as they are verified or labeled unverified per catalog policy.

What to do if you may be affected

  1. Step 1: Enable phishing-resistant MFA on every account tied to this brand.
  2. Step 2: Use unique passwords and a password manager—breach rows often involve credential reuse.
  3. Step 3: Monitor official company breach notices and regulator filings, not dark-web downloads.
  4. Step 4: Review OAuth app permissions and revoke unused third-party integrations.
  5. Step 5: Bookmark the T-Mobile company page for new 2026+ disclosures.

Canonical BreachHistory hub

Explore every indexed row: breachhistory.com/t-mobile · Latest: t-mobile-20232023.

Sources: BreachHistory catalog (15 rows for T-Mobile), company and regulator disclosures cited in individual breach records.