8-KOther Events

T-Mobile US, Inc. 8-K Report, Corporate Update (Jan 19, 2023)

Filed January 19, 2023For Securities:TMUSTMUSZTMUSITMUSL

Summary

T-Mobile US, Inc. (TMUS) filed an 8-K on January 19, 2023, to disclose a cybersecurity incident that occurred on or around November 25, 2022. A bad actor gained unauthorized access to data through a single Application Programming Interface (API). T-Mobile promptly contained the malicious activity and is conducting an ongoing investigation with external experts and law enforcement. Crucially, the breached API does not contain sensitive customer data such as payment card information, social security numbers, or passwords. The exposed data is limited to names, billing addresses, email addresses, dates of birth, T-Mobile account numbers, and plan details for approximately 37 million postpaid and prepaid customer accounts. While the company is notifying affected customers and federal agencies, it currently does not expect this incident to have a material impact on its operations. This event underscores T-Mobile's ongoing commitment to cybersecurity investments, which have been a focus since 2021, and highlights the ongoing challenges in protecting customer data in the digital landscape. Investors should monitor any developments from the ongoing investigation and the potential for any unforeseen costs or reputational impacts.

Key Highlights

  • 1Cybersecurity incident identified on January 5, 2023, stemming from unauthorized API access around November 25, 2022.
  • 2Malicious activity was promptly contained by T-Mobile within a day of discovery.
  • 3The compromised API did not expose sensitive data like payment card information, SSNs, or passwords.
  • 4Limited customer data, including name, billing address, email, DOB, account number, and plan information, was accessed for approximately 37 million accounts.
  • 5T-Mobile is cooperating with federal agencies and law enforcement, and is notifying affected customers.
  • 6The company does not currently anticipate a material impact on its operations, but may incur significant expenses related to the incident.
  • 7T-Mobile reaffirms its ongoing, substantial investments in cybersecurity enhancements.

Frequently Asked Questions

The compromised API exposed limited customer data, including name, billing address, email, phone number, date of birth, T-Mobile account number, and information about plan features and the number of lines on the account. Critically, the breach did not include sensitive personal information such as payment card details, social security numbers, driver's license numbers, passwords, or financial account information.

Based on the preliminary investigation, approximately 37 million current postpaid and prepaid customer accounts had data accessed through the compromised API. However, the company notes that many of these accounts did not include the full set of available data.

T-Mobile currently believes the incident will not have a material effect on the company's operations. However, the company does anticipate incurring significant expenses in connection with this incident, and the full financial impact is still subject to ongoing investigation.

T-Mobile has been undertaking substantial multi-year investments in cybersecurity since 2021, working with external experts to enhance its capabilities. The company states that protecting customer data remains a top priority and it will continue to invest in strengthening its cybersecurity program.