← Case Files · The Breach Files
T-Mobile, 2021: an exposed router, and 76 million people who were mostly not customers
- People affected
- over 76 million records, including about 40 million former and prospective customers
- When it happened
- August 2021
- Made public
- 16 August 2021
- How they got in
- An internet-exposed router, then lateral movement into a data centre
- Attributed to
- John Binns, who described the intrusion to journalists at the time
- What it cost
- $350 million class settlement plus a $150 million security spending commitment; a later $31.5 million settlement with the FCC
What was exposed: Names · Dates of birth · Social Security numbers · Driver's licence and ID numbers · Phone numbers · Account PINs for some prepaid customers
In August 2021 a 21-year-old told reporters how he had done it: an unprotected router exposed to the internet, then a route into a data centre, then more than a hundred servers holding customer data. What made the T-Mobile breach unusual was not the method. It was who was in the file — tens of millions of people who had applied for a phone contract and, in many cases, never got one.
What happened
T-Mobile confirmed on 16 August 2021 that customer data had been accessed. As the investigation progressed the count grew past 76 million records, broken into categories that matter:
- Around 7.8 million current postpaid customers, with names, dates of birth, Social Security numbers and driver's licence or identification numbers.
- Around 40 million former and prospective customers — people who had applied for credit with T-Mobile, whether or not they ever became customers — with the same categories of data.
- Around 850,000 prepaid customers, with names, phone numbers and account PINs.
The middle group is the one worth pausing on. If you walked into a store in 2015, asked about a contract, had your credit checked and then walked out, you were in this breach. You had no relationship with the company, no account to log into, and no particular reason to be watching for a notification.
The retention question. Nothing about processing a credit application in 2015 requires holding the applicant's Social Security number in 2021. Data that is kept because deleting it was never anyone's job is the most common form of unnecessary exposure in this archive, and it is the one that costs nothing to fix except the discipline of deciding when records expire.
The SIM-swap angle
The account PINs exposed for prepaid customers deserve their own note, because they sit at the centre of a specific and damaging fraud.
A SIM swap works like this: the attacker contacts the carrier posing as the customer, passes whatever verification the carrier uses, and has the phone number moved to a SIM they control. From that moment, every SMS verification code goes to them. Bank accounts, email accounts and cryptocurrency exchanges that rely on SMS as a second factor fall in sequence.
The account PIN is the control designed to stop exactly that. Leaking PINs alongside names and phone numbers hands over both the target and the key, which is why those customers were forced through a reset immediately.
The pattern, which is the real story
T-Mobile disclosed security incidents in 2018, 2019, 2020, 2021 and again in January 2023, when an API was abused to pull data on 37 million accounts. That repetition is why the US Federal Communications Commission's September 2024 settlement was structured the way it was: a $31.5 million resolution split evenly between a penalty and a commitment to spend on specific security improvements — zero-trust architecture, phishing-resistant multi-factor authentication, and better data inventory and segmentation.
Regulators tend to treat a first breach as an incident and a fifth as a governance failure. The remedy shifts accordingly, from a fine towards a supervised programme of work with deadlines.
The timeline
- Early August 2021 — An internet-exposed router provides a foothold; lateral movement reaches servers holding customer records.
- 16 August 2021 — T-Mobile confirms unauthorised access.
- Late August 2021 — The scope is revised upward repeatedly, past 76 million records; prepaid PINs are reset.
- July 2022 — A $350 million class settlement is announced, alongside a commitment to spend $150 million on data security.
- January 2023 — A separate incident: an API is abused to obtain data on 37 million accounts.
- September 2024 — The FCC settles its investigations into the 2021 and later breaches for $31.5 million, half of it earmarked for security investment.
What it changed
Applicant data entered the conversation. Breach notifications had historically been framed around customers. This case made "and everyone who ever applied" a standard question, and it put retention schedules for credit-check data under regulatory scrutiny.
Carrier security became an FCC enforcement priority. The 2024 settlement was one of several actions signalling that telecommunications data — which underpins phone-based authentication for everything else — would be regulated as critical rather than commercial.
SMS authentication lost more ground. Each carrier breach that exposes PINs or enables SIM swaps strengthens the case that a phone number is an identifier, not an authenticator. The move to passkeys and app-based factors is downstream of exactly this.
If you ever applied to T-Mobile
- Freeze your credit files. Social Security numbers and licence numbers in this breach map directly onto new-account fraud.
- Set a port-out PIN and account lock with your current carrier, whoever that is. It is free and it is the single best defence against SIM swapping.
- Move critical accounts off SMS codes — the practical hierarchy of second factors.
- Check your exposure across the other carrier breaches too. Anyone who has changed provider a few times is likely to appear in more than one — the archive tracks them as they are confirmed.
Questions people ask
I only applied to T-Mobile and never joined. Was I affected?
Very possibly. Roughly 40 million of the exposed records belonged to former customers and to people who had applied for credit with T-Mobile — a category that includes anyone whose application was declined. Credit checks generate exactly the data an identity thief wants, and companies routinely keep those records for years.
How did the attacker get in?
He described it publicly: an internet-exposed router with weak protection gave a foothold, from which he reached a data centre and, eventually, servers holding customer data. He characterised T-Mobile's security as poor, which the subsequent regulatory settlements did not seriously contest.
Why does T-Mobile appear in breach lists so often?
Because it has disclosed a series of incidents across 2018, 2019, 2020, 2021, 2023 and beyond — a pattern the US Federal Communications Commission referenced when it settled with the company in 2024, requiring both a penalty and specific security investments. Repetition is itself a finding: it points at governance rather than at any single technical failure.
What is an account PIN and why did it matter?
It is the code that authenticates you to the carrier when you call support — and the control that is supposed to stop somebody else moving your number to their SIM. Prepaid account PINs were among the exposed data, which made SIM-swap attacks against those customers materially easier until they were reset.
Sources
- Federal Communications Commission — T-Mobile data breach settlement, September 2024
- T-Mobile customer notifications and updates, August 2021
- Class settlement in In re T-Mobile Customer Data Security Breach Litigation, 2022
Read next
Case files are written from the public record: regulatory findings, court filings, company disclosures and contemporaneous reporting, cited above. Figures are the ones the organisation or its regulator finally settled on, which is often not the number first reported — where that differs, the page says so. Disputed accounts are marked as disputed rather than resolved in either direction.