8-KRegulation FD

T-Mobile US, Inc. 8-K Report, Regulation FD Disclosure (Aug 20, 2021)

Filed August 20, 2021For Securities:TMUSTMUSZTMUSITMUSL

Summary

This 8-K filing from T-Mobile US, Inc., dated August 20, 2021, provides crucial updates regarding an ongoing investigation into a significant cyberattack. The company has expanded its understanding of the data compromised, affecting a larger number of current and former customer accounts than initially reported. While the investigation is ongoing, T-Mobile is confident that the attack vectors have been closed. The filing details the types of personal information exposed, distinguishing between different customer segments (postpaid, prepaid, former/prospective) and reassuring investors that financial data, credit card, or payment information does not appear to have been compromised. In response to the incident, T-Mobile is implementing several protective measures for affected individuals. These include offering two years of free identity protection services via McAfee, recommending Scam Shield for all eligible customers, and providing guidance on security best practices. The company emphasizes its commitment to transparency and ongoing collaboration with industry experts to enhance security. Investors should note the potential for continued updates as the investigation progresses and be aware of the forward-looking statements within the filing concerning cybersecurity risks and their impact.

Key Highlights

  • 1T-Mobile has identified additional compromised customer accounts, expanding the scope of the cyberattack's impact.
  • 2New data indicates phone numbers, IMEI, and IMSI information were compromised for an additional 5.3 million current postpaid customer accounts.
  • 3Data from an additional 667,000 former customer accounts was accessed, with names, phone numbers, addresses, and dates of birth exposed, but not SSNs or driver's license information.
  • 4The company has reset PINs for approximately 850,000 active prepaid customer accounts due to exposure.
  • 5T-Mobile explicitly states there is no indication that customer financial information, credit card, or other payment information was compromised in the breach.
  • 6Affected individuals are being offered two years of free identity protection services from McAfee.
  • 7T-Mobile is reinforcing its commitment to transparency and will provide further updates as the investigation evolves.

Frequently Asked Questions

T-Mobile has identified more affected accounts. This includes an additional 5.3 million current postpaid customer accounts with names, addresses, dates of birth, phone numbers, IMEIs, and IMSIs compromised (but not SSNs or driver's license info). Additionally, 667,000 former customer accounts had names, phone numbers, addresses, and dates of birth accessed. Phone numbers, IMEI, and IMSI were also identified in separate stolen data files with no personally identifiable information.

The compromised data varies by customer segment. For current postpaid customers, this included names, dates of birth, SSNs, driver's license/ID information, phone numbers, IMEIs, and IMSIs. For some former or prospective customers, names, dates of birth, SSNs, and driver's license/ID information were involved. For other former customers, names, phone numbers, addresses, and dates of birth were accessed. For active prepaid customers, names, phone numbers, and account PINs were exposed. Importantly, T-Mobile states there is no indication that any financial, credit card, or payment information was compromised.

T-Mobile is offering two years of free identity protection services with McAfee's ID Theft Protection Service to all affected individuals. They are also recommending that eligible customers sign up for their free scam-blocking service, Scam Shield, and are providing guidance on best practices for security, such as resetting PINs and passwords. Communications have been sent to millions of customers and affected individuals.

Yes, T-Mobile reported that approximately 850,000 active T-Mobile prepaid customer names, phone numbers, and account PINs were exposed. They have proactively reset ALL of the PINs on these accounts. Similar information from additional inactive prepaid accounts was also accessed, along with names from up to 52,000 current Metro by T-Mobile accounts, none of which included personally identifiable information.