8-KRegulation FD

T-Mobile US, Inc. 8-K Report, Regulation FD Disclosure (Aug 27, 2021)

Filed August 27, 2021For Securities:TMUSTMUSZTMUSITMUSL

Summary

T-Mobile US, Inc. (TMUS) filed an 8-K on August 27, 2021, disclosing a significant cyberattack that occurred on August 17, 2021. The breach compromised the personal information of millions of customers, former customers, and prospective customers, including Social Security numbers, names, addresses, dates of birth, and driver's license/ID information. Crucially, the company stated that no customer financial information, credit card, or debit card details were exposed. The CEO, Mike Sievert, expressed deep disappointment and apologized for failing to protect customer data, emphasizing that the company has contained the breach and closed the exploited access points. T-Mobile is taking immediate steps to support affected individuals by offering two years of free identity protection services, recommending its Scam Shield service, and making Account Takeover Protection available to postpaid customers. The company is also partnering with cybersecurity experts Mandiant and KPMG for a multi-year investment in enhancing its security infrastructure and protocols to prevent future incidents.

Key Highlights

  • 1Confirmed a criminal cyberattack occurred on August 17, 2021, impacting millions of customers, former customers, and prospective customers.
  • 2Compromised data includes SSN, name, address, date of birth, and driver's license/ID information; financial and payment data were NOT exposed.
  • 3The breach has been contained, and compromised access points have been closed.
  • 4T-Mobile is offering two years of free identity protection services through McAfee's ID Theft Protection Service to all potentially affected individuals.
  • 5Customers are encouraged to sign up for T-Mobile's free Scam Shield and Account Takeover Protection services.
  • 6The company is making a substantial multi-year investment in cybersecurity, partnering with experts Mandiant and KPMG to enhance security measures and protocols.

Frequently Asked Questions

The compromised data includes Social Security numbers, names, addresses, dates of birth, and driver's license/ID information. Importantly, T-Mobile stated that no customer financial information, credit card, or debit card details were exposed.

T-Mobile is offering two years of free identity protection services with McAfee's ID Theft Protection Service to all potentially affected individuals. They are also recommending customers sign up for their free Scam Shield service and are making Account Takeover Protection available for postpaid customers.

T-Mobile stated that the breach has been contained and the access points used by the attacker have been closed. They are confident that there is no ongoing risk to customer data from this specific breach.

T-Mobile is entering into long-term partnerships with cybersecurity experts Mandiant and consulting firm KPMG. This is part of a substantial multi-year investment to transform their cybersecurity approach, adopt best-in-class practices, and enhance their ability to protect against future threats.