The T-Mobile operator just suffered at least its fifth data breach since 2018, despite promising to spend a fortune shoring up its systems.
The mobile company therefore reported it suffered a big data breach on November 26 that impacts 37 million current customers on both prepaid and postpay accounts.
At a US Securities and Exchange Commission filing, the company stated that a “bad actor” manipulated one of the company's application programming interfaces (APIs) to steal customers' names, email addresses, phone numbers, billing addresses, dates of birth, account numbers, and service plan details.
The initial intrusion therefore occurred at the end of November and T-Mobile discovered the activity on January 5.
It is one of the largest mobile carriers of the U.S and is estimated to have more than a 100 million customers. But in the past 10 years, the company has therefore developed a reputation for having repeated data breaches alongside other security incidents.
The company had a mega breach in 2021, two breaches in 2020, one in 2019, and another in 2018. Most large organizations struggle with digital security, and no one is immune to data breaches, but T-Mobile seems to be approaching companies like Yahoo in the pantheon of repeated compromises.
"I'm certainly disappointed to hear that, after as many breaches as they've had, they still haven't been able to shore up their leaky ship," says Chester Wisniewski, field chief technical officer of applied research at the security firm Sophos.
"It is also concerning that the criminals were in T-Mobile's system for more than a month before being discovered. This suggests T-Mobile's defenses do not utilize modern security monitoring and threat hunting teams, as you might expect to find in a large enterprise like a mobile network operator."
Because of limits on the API (an interface that facilitates communication between two software programs), the attacker did not gain access to Social Security numbers or tax IDs, driver's license data, passwords and PINs, or financial information like payment card data.
Such data has been compromised in other recent T-Mobile breaches, though, including one in August 2021. In July 2022, T-Mobile agreed to settle a class action suit about that breach in a deal that included $350 million to customers. At the time, the company also committed to a two-year, $150 million initiative to improve its digital security and data defenses.
"How many of these does T-Mobile have to have?" wondered Jake Williams, a longtime incident responder and an analyst at the Institute for Applied Network Security, "API security is just starting to be something people are really focusing on, which was a mistake. Detecting API abuse is not easy, especially if the threat actor is moving low and slow. I suspect there's a large number of these in general that simply go undetected. But the bottom line is that T-Mobile's API security clearly needs work. You shouldn't be having mass API abuse for more than six weeks."