← T-Mobile US

2023 API breach — 37M customer records

2023 37.0M records affected Share on X

Data compromised

Names, billing addresses, emails, phone numbers, account details (no passwords or financial data per T-Mobile)

Technical writeup

An attacker abused a T-Mobile API to access customer data including name, billing address, email, phone number, and account details. No passwords or financial data were taken.

Root cause

API abuse; insufficient authentication or rate limiting on customer data API.

References