2023 API breach — 37M customer records
Data compromised
Names, billing addresses, emails, phone numbers, account details (no passwords or financial data per T-Mobile)
Technical writeup
An attacker abused a T-Mobile API to access customer data including name, billing address, email, phone number, and account details. No passwords or financial data were taken.
Root cause
API abuse; insufficient authentication or rate limiting on customer data API.