← Blog

T-Mobile Data Breaches: Full Timeline Through 2026

Share on X

People search T-Mobile data breach timeline because the brand sits on billions of accounts, credentials, and cloud workloads. BreachHistory indexes 6 T-Mobile-linked incidents, with headline counts up to 54M+ in catalog rows. This page maps every attested event through 2026 with internal links to canonical records.

Why T-Mobile breach history matters

T-Mobile operates in Technology (United States). Across indexed rows, recurring themes include mixed intrusion and disclosure events. Understanding the chronological pattern helps security teams, customers, and regulators separate confirmed disclosures from forum marketing.

Full timeline through 2026

2023 — 37M customer records

Cataloged incident. An attacker abused a T-Mobile API to access customer data including name, billing address, email, phone number, and account details. No passwords or financial data were taken. Exposed categories include Names, billing addresses, emails, phone numbers, account details (no passwords or financial data per T-Mobile). BreachHistory cites approximately 37M+ affected records in this row. See the tmob and canonical BreachHistory entry.

2021 — 50M+ records

Cataloged incident. An attacker accessed T-Mobile's systems and exfiltrated customer data including names, DOBs, SSNs, driver's license info, and IMEI numbers. Data was offered for sale on the dark web. Exposed categories include Names, Social Security numbers, Dates of birth, Driver's license numbers, Internal documents. BreachHistory cites approximately 54M+ affected records in this row. See the qhxn and canonical BreachHistory entry.

2018 — — T-Mobile US: T-Mobile initially said that personal data was…

Cataloged incident. Aug 2018. T-Mobile initially said that personal data was stolen, but no passwords or financial info. They later admitted that encrypted passwords had been stolen. BreachHistory cites approximately 2M+ affected records in this row. See the tmobile2018 and canonical BreachHistory entry.

2010 — — T-Mobile US: Thieves got their hands on a storage device with…

Cataloged incident. Thieves got their hands on a storage device with the data, which included the names, addresses, cell phone numbers, and some birth dates and e-mail addresses for high-profile German citizens. The company said the records did not contain bank details, credit card numbers, or call data. BreachHistory cites approximately 17M+ affected records in this row. See the tmobileu and canonical BreachHistory entry.

2008 — — T-Mobile US: Thieves got their hands on a storage device with…

Cataloged incident. Oct 2008. Thieves got their hands on a storage device with the data, which included the names, addresses, cell phone numbers, and some birth dates and e-mail addresses for high-profile German citizens. The company said the records did not contain bank details, credit card numbers, or call data. BreachHistory cites approximately 17M+ affected records in this row. See the tmobile2008 and canonical BreachHistory entry.

2006 — — T-Mobile US: Thieves got their hands on a storage device with…

Cataloged incident. Thieves got their hands on a storage device with the data, which included the names, addresses, cell phone numbers, and some birth dates and e-mail addresses for high-profile German citizens. The company said the records did not contain bank details, credit card numbers, or call data. BreachHistory cites approximately 17M+ affected records in this row. See the tmobile2006 and canonical BreachHistory entry.

Patterns and analysis

  • Mixed intrusion and disclosure events — appears across multiple T-Mobile catalog entries; prioritize controls that address this class of failure.
  • Record-count hygiene — BreachHistory indexes actor-cited figures separately from company-confirmed totals; read each row's technicalWriteup before treating counts as fact.
  • 2026 monitoring — New disclosures roll into this timeline as they are verified or labeled unverified per catalog policy.

What to do if you may be affected

  1. Step 1: Enable phishing-resistant MFA on every account tied to this brand.
  2. Step 2: Use unique passwords and a password manager—breach rows often involve credential reuse.
  3. Step 3: Monitor official company breach notices and regulator filings, not dark-web downloads.
  4. Step 4: Review OAuth app permissions and revoke unused third-party integrations.
  5. Step 5: Bookmark the T-Mobile company page for new 2026+ disclosures.

Canonical BreachHistory hub

Explore every indexed row: breachhistory.com/tmobile · Latest: tmob.

Sources: BreachHistory catalog (6 rows for T-Mobile), company and regulator disclosures cited in individual breach records.