T-Mobile disclosed in a securities filing that it identified on 5 January 2023 a bad actor obtaining data through a single application programming interface without authorisation. The filing places the start of retrieval at on or around 25 November 2022, and states the API was addressed within a day of discovery.
The company reported that data was obtained for approximately 37 million current postpaid and prepaid customer accounts, and described the API as able to return a limited set of fields: name, billing address, email, phone number, date of birth, account number, number of lines and plan features.
The Interface Worked As Built
Nothing was exploited in the sense the word usually carries. An interface designed to return customer account data returned customer account data, to a caller it had no way of establishing was entitled to ask.
The corpus files the identical shape at 26-0609, where a ServiceNow endpoint allowed table queries without authentication. An API is a door built for machines, and machines do not look suspicious.
Six Weeks Of Retrieval, One Day Of Fixing
The ratio is the finding. Roughly six weeks passed between the first retrieval and discovery; the remedy took about a day once someone was looking.
That asymmetry recurs throughout this database — at 23-0331, where a ten-minute alert took 58 hours to act on, and at 26-0620, where an exploited weakness went ten months before detection. Time to fix is almost never the constraint. Time to notice is.
A Limited Field Set Is Still An Identity Set
T-Mobile was clear that the API could not return payment or password data. What it could return — name, address, date of birth, phone number — is precisely the combination used to pass identity verification elsewhere.
Telecom operators hold identity-grade data because billing and regulation require it, while being supervised as telecoms rather than as custodians of identity.
Built on T-Mobile’s Form 10-Q disclosure of the incident and on contemporaneous reporting. The 25 November 2022 start, the 5 January 2023 discovery, the approximately 37 million accounts and the field list are the company’s own statements to a securities regulator. The company noted many accounts did not include the full data set; this file does not assert a per-field breakdown. No actor attribution is made. No indicators are reproduced. Graded high. Corrections: corrections@forensicpost.com.
- T-Mobile US, Inc. — Form 10-Q, FY2023US Securities and Exchange Commission
- T-Mobile says hacker accessed personal data of 37 million customersTechCrunch