Close Menu
New York Examiner News

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Blink-182’s Mark Hoppus reveals how he sang on unreleased Linkin Park song

    September 27, 2026

    Coastal erosion is so bad in California that this mostly GOP city may tax itself to restore beach

    September 27, 2026

    Trump Can’t Get Even Go To The Golf Course Without Being Called A Pedo

    September 27, 2026
    Facebook X (Twitter) Instagram
    New York Examiner News
    • Home
    • US News
    • Politics
    • Business
    • Science
    • Technology
    • Lifestyle
    • Music
    • Television
    • Film
    • Books
    • Contact
      • About
      • Amazon Disclaimer
      • DMCA / Copyrights Disclaimer
      • Terms and Conditions
      • Privacy Policy
    New York Examiner News
    Home»Technology»T-Mobile’s New Data Breach Shows Its $150 Million Security Investment Isn’t Cutting It
    Technology

    T-Mobile’s New Data Breach Shows Its $150 Million Security Investment Isn’t Cutting It

    By AdminJanuary 21, 2023
    Facebook Twitter Pinterest LinkedIn WhatsApp Email Reddit Telegram
    T-Mobile’s New Data Breach Shows Its 0 Million Security Investment Isn’t Cutting It


    Yesterday, mobile giant T-Mobile said that it suffered a data breach beginning on November 26 that impacts 37 million current customers on both prepaid and postpay accounts. The company said in a US Securities and Exchange Commission filing that a “bad actor” manipulated one of the company’s application programming interfaces (APIs) to steal customers’ names, email addresses, phone numbers, billing addresses, dates of birth, account numbers, and service plan details. The initial intrusion occurred at the end of November, and T-Mobile discovered the activity on January 5.  

    T-Mobile is one of the US’s largest mobile carriers and is estimated to have more than 100 million customers. But in the past 10 years, the company has developed a reputation for suffering repeated data breaches alongside other security incidents. The company had a mega breach in 2021, two breaches in 2020, one in 2019, and another in 2018. Most large companies struggle with digital security, and no one is immune to data breaches, but T-Mobile seems to be approaching companies like Yahoo in the pantheon of repeated compromises.

    “I’m certainly disappointed to hear that, after as many breaches as they’ve had, they still haven’t been able to shore up their leaky ship,” says Chester Wisniewski, field chief technical officer of applied research at the security firm Sophos. “It is also concerning that the criminals were in T-Mobile’s system for more than a month before being discovered. This suggests T-Mobile’s defenses do not utilize modern security monitoring and threat hunting teams, as you might expect to find in a large enterprise like a mobile network operator.”

    Because of limits on the API (an interface that facilitates communication between two software programs), the attacker did not gain access to Social Security numbers or tax IDs, driver’s license data, passwords and PINs, or financial information like payment card data. Such data has been compromised in other recent T-Mobile breaches, though, including one in August 2021. In July 2022, T-Mobile agreed to settle a class action suit about that breach in a deal that included $350 million to customers. At the time, the company also committed to a two-year, $150 million initiative to improve its digital security and data defenses.

    T-Mobile, which did not respond to multiple requests for comment from WIRED, wrote in its SEC disclosure that in 2021, “We commenced a substantial multi-year investment working with leading external cybersecurity experts to enhance our cybersecurity capabilities and transform our approach to cybersecurity. We have made substantial progress to date, and protecting our customers’ data remains a top priority.”

    It clearly hasn’t been enough, given the recent incident, which exposed data for roughly a third of the company’s US-based customers. 

    “How many of these does T-Mobile have to have?” wondered Jake Williams, a longtime incident responder and an analyst at the Institute for Applied Network Security. “API security is just starting to be something people are really focusing on, which was a mistake. Detecting API abuse is not easy, especially if the threat actor is moving low and slow. I suspect there’s a large number of these in general that simply go undetected. But the bottom line is that T-Mobile’s API security clearly needs work. You shouldn’t be having mass API abuse for more than six weeks.”



    Original Source Link

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Email Reddit Telegram
    Previous ArticleLargest plane yet tested with hydrogen-powered engine
    Next Article Andie MacDowell can’t live without these 8 lifestyle essentials

    RELATED POSTS

    Anthropic’s Dario Amodei gets the SNL treatment

    September 27, 2026

    Old-School Credit Card Scams Are Far From Dead

    September 27, 2026

    Levoit’s new air purifier is for the pet odors that have taken over your apartment

    September 26, 2026

    Quince Luggage Is Affordable but Doesn’t Feel Cheap (2026)

    September 26, 2026

    Meta is putting its muscle behind Muse as the AI app takes off

    September 25, 2026

    Altra Running Promo Codes: 10% Off September 2026

    September 25, 2026
    latest posts

    Blink-182’s Mark Hoppus reveals how he sang on unreleased Linkin Park song

    Blink-182’s Mark Hoppus has revealed that he recorded vocals for an unreleased Linkin Park song…

    Coastal erosion is so bad in California that this mostly GOP city may tax itself to restore beach

    September 27, 2026

    Trump Can’t Get Even Go To The Golf Course Without Being Called A Pedo

    September 27, 2026

    Brain fog and memory loss may signal reversible causes, neurologist says

    September 27, 2026

    Anthropic’s Dario Amodei gets the SNL treatment

    September 27, 2026

    The Data Center Backlash Should Also Be a Climate Reckoning. It Isn’t Yet

    September 27, 2026

    Sophie Thatcher: ‘It felt like the most I’d ever…

    September 27, 2026
    Categories
    • Books (1,516)
    • Business (6,420)
    • Events (77)
    • Film (6,354)
    • Lifestyle (4,419)
    • Music (6,484)
    • Politics (6,408)
    • Science (5,772)
    • Technology (6,353)
    • Television (6,045)
    • Uncategorized (9)
    • US News (6,407)
    popular posts

    Spot and Avoid the Most Common Unsafe Work Practices

    In the USA, there are over 5,000 deaths per year as a direct result of…

    ‘The Flash’ Boss Looks Back on the Season 8 Finale That Almost Was

    June 30, 2022

    Ford reaches tentative deal with striking autoworkers, marking a huge breakthrough in a work stoppage that’s cost the industry billions

    October 26, 2023

    UN International Day of Peace 2025, September 21, Expands to a Global Weekend To Pause the World for Peace Worldwide, Moment/Meditative Minute of Silence, Plant Peace Pole Virtually/Physical at Noon in 24 Regions (Time Zones). A World Cease Fire, Peace Acts, Unity, Music, & Climate Week Action. New York City Leads the Call.

    September 1, 2025
    Archives
    Browse By Category
    • Books (1,516)
    • Business (6,420)
    • Events (77)
    • Film (6,354)
    • Lifestyle (4,419)
    • Music (6,484)
    • Politics (6,408)
    • Science (5,772)
    • Technology (6,353)
    • Television (6,045)
    • Uncategorized (9)
    • US News (6,407)
    About Us

    We are a creativity led international team with a digital soul. Our work is a custom built by the storytellers and strategists with a flair for exploiting the latest advancements in media and technology.

    Most of all, we stand behind our ideas and believe in creativity as the most powerful force in business.

    What makes us Different

    We care. We collaborate. We do great work. And we do it with a smile, because we’re pretty damn excited to do what we do. If you would like details on what else we can do visit out Contact page.

    Our Picks

    The Data Center Backlash Should Also Be a Climate Reckoning. It Isn’t Yet

    September 27, 2026

    Sophie Thatcher: ‘It felt like the most I’d ever…

    September 27, 2026

    Bill Maher & Roseanne Barr Eviscerate ‘Insane’ Far Left — Then Things Get Heated

    September 27, 2026
    © 2026 New York Examiner News. All rights reserved. All articles, images, product names, logos, and brands are property of their respective owners. All company, product and service names used in this website are for identification purposes only. Use of these names, logos, and brands does not imply endorsement unless specified. By using this site, you agree to the Terms & Conditions and Privacy Policy.

    Type above and press Enter to search. Press Esc to cancel.

    We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.
    Cookie SettingsAccept All
    Manage consent

    Privacy Overview

    This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
    Necessary
    Always Enabled
    Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
    CookieDurationDescription
    cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
    cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
    cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
    cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
    cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
    viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
    Functional
    Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
    Performance
    Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
    Analytics
    Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
    Advertisement
    Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
    Others
    Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
    SAVE & ACCEPT