Summary
T-Mobile US, Inc. (TMUS) filed an 8-K on August 27, 2021, disclosing a significant cyberattack that occurred on August 17, 2021. The breach compromised the personal information of millions of customers, former customers, and prospective customers, including Social Security numbers, names, addresses, dates of birth, and driver's license/ID information. Crucially, the company stated that no customer financial information, credit card, or debit card details were exposed. The CEO, Mike Sievert, expressed deep disappointment and apologized for failing to protect customer data, emphasizing that the company has contained the breach and closed the exploited access points. T-Mobile is taking immediate steps to support affected individuals by offering two years of free identity protection services, recommending its Scam Shield service, and making Account Takeover Protection available to postpaid customers. The company is also partnering with cybersecurity experts Mandiant and KPMG for a multi-year investment in enhancing its security infrastructure and protocols to prevent future incidents.
Key Highlights
- 1Confirmed a criminal cyberattack occurred on August 17, 2021, impacting millions of customers, former customers, and prospective customers.
- 2Compromised data includes SSN, name, address, date of birth, and driver's license/ID information; financial and payment data were NOT exposed.
- 3The breach has been contained, and compromised access points have been closed.
- 4T-Mobile is offering two years of free identity protection services through McAfee's ID Theft Protection Service to all potentially affected individuals.
- 5Customers are encouraged to sign up for T-Mobile's free Scam Shield and Account Takeover Protection services.
- 6The company is making a substantial multi-year investment in cybersecurity, partnering with experts Mandiant and KPMG to enhance security measures and protocols.