On 19 January 2023, T-Mobile told the US Securities and Exchange Commission that a "bad actor" had been pulling customer data through one of its application programming interfaces (APIs) without authorisation since around 25 November 2022. T-Mobile detected the activity on 5 January 2023 and cut off access within a day. By then the attacker had obtained data for approximately 37 million current postpaid and prepaid customer accounts: names, billing addresses, email addresses, phone numbers, dates of birth, account numbers and plan details, though many records did not include every field. T-Mobile said the API could not return payment card data, Social Security numbers, government IDs or passwords. It has not explained how the attacker was able to use the API, which is itself the lesson: an interface built for machines to call returned customer records to someone who should never have been allowed to call it.
Key takeaways
- T-Mobile says a bad actor obtained data through a single API "without authorization", starting around 25 November 2022.
- The abuse ran for about six weeks before detection on 5 January 2023 and affected approximately 37 million current customer accounts.
- Exposed data included name, billing address, email, phone number, date of birth, account number and plan features; card data, Social Security numbers, government IDs and passwords were not available through the API.
- T-Mobile has not disclosed how the attacker authenticated to, or bypassed authorisation on, the API.
- The identity lesson: every API caller is an identity, and APIs that return customer data need strong authentication, per-caller authorisation and volume monitoring.
At a glance
| Organisation | T-Mobile US |
|---|---|
| When | API abuse from around 25 November 2022; detected 5 January 2023; contained within a day; disclosed 19 January 2023 |
| Attacker | Unidentified |
| Entry point | One T-Mobile API, used without authorisation according to T-Mobile; the method has not been disclosed |
| Identities abused | Not disclosed; the attacker acted as an unauthorised caller of a machine-facing API |
| Impact | Customer account data for approximately 37 million current postpaid and prepaid accounts; no payment, SSN, government ID or password data |
| Category | NHI. Incident class: confirmed breach through an abused API (how the attacker authenticated has not been disclosed) |
What happened
In its 8-K filing, T-Mobile said it identified on 5 January 2023 that a bad actor was obtaining data through a single API without authorisation, according to SecurityWeek and KrebsOnSecurity. Its investigation found the actor "first retrieved data through the impacted API starting on or around November 25, 2022." BleepingComputer reported that T-Mobile cut off the attacker's access one day after detection.
"The preliminary result from our investigation indicates that the bad actor(s) obtained data from this API for approximately 37 million current postpaid and prepaid customer accounts, though many of these accounts did not include the full data set," T-Mobile said. "The impacted API is only able to provide a limited set of customer account data, including name, billing address, email, phone number, date of birth, T-Mobile account number and information such as the number of lines on the account and plan features." It stressed that the API "does not provide access to any customer payment card information (PCI), social security numbers/tax IDs, driver's license or other government ID numbers, passwords/PINs or other financial account information."
T-Mobile said "there is currently no evidence that the bad actor was able to breach or compromise our systems or our network," and that it had notified federal agencies and was working with law enforcement. It did not say how the API was abused. BleepingComputer noted that APIs usually expect callers to "pass the right authentication tokens" and that attackers commonly look for flaws that return data without authenticating first; KrebsOnSecurity compared the case with the Optus breach in Australia a few months earlier, which also involved a poorly secured API.
This was T-Mobile's second major customer data breach in two years, after the August 2021 breach that exposed more than 40 million records, according to KrebsOnSecurity. T-Mobile told the SEC it did not expect the incident to have a material impact on its operations.
Timeline
| Date | Event |
|---|---|
| 25 November 2022 | The bad actor begins retrieving customer data through the API, according to T-Mobile. |
| 5 January 2023 | T-Mobile identifies the malicious activity. |
| 6 January 2023 | T-Mobile cuts off the attacker's access, within a day of detection. |
| 19 January 2023 | T-Mobile discloses the breach in an SEC 8-K filing and begins notifying customers. |
How it happened: the identity attack path
- An exposed API. A T-Mobile API could return customer account records to callers.
- Unauthorised calls. From around 25 November 2022, a bad actor called the API without authorisation; the method has not been disclosed.
- Bulk harvesting. Over about six weeks, the actor retrieved records for approximately 37 million accounts.
- Late detection. T-Mobile identified the activity on 5 January 2023 and cut off access within a day.
Impact
- Customers: approximately 37 million current postpaid and prepaid accounts, many with partial data.
- Data exposed: name, billing address, email, phone number, date of birth, account number, number of lines and plan features.
- Not exposed, according to T-Mobile: payment card data, Social Security numbers and tax IDs, government IDs, passwords and PINs.
- Downstream risk: KrebsOnSecurity warned the data could be used for phishing, account takeover and identity theft.
What this means for NHI governance
APIs are built for software to talk to software, and every caller is a non-human identity of some kind: an app, a partner integration, a service. When an API returns customer data, the questions that matter are who may call it, with what credential, for which records, and how much. T-Mobile has not said which of those failed, but six weeks of bulk retrieval of 37 million accounts means neither authorisation nor volume monitoring stopped it.
API inventories often miss older or internal endpoints, and those are the ones attackers find. Treating API clients as governed identities, with per-client credentials, least-privilege scopes, object-level authorisation and anomaly detection on data volumes, turns an API from an open door into a monitored one. See our API Key Management Guide and Authorisation Models Guide.
Recommendations
- Inventory every API that returns customer data. Include internal, partner and legacy endpoints, each with an owner.
- Require strong client authentication. Give each calling app or partner its own credential, and prefer short-lived tokens over static keys. See our API Key Management Guide.
- Enforce object-level authorisation. Check on every request that the caller may see that specific record. See the Authorisation Models Guide.
- Monitor and rate-limit data volumes per client. Millions of record lookups by one caller should trigger an alert within hours, not weeks.
- Test APIs as an attacker would. Include authentication bypass and enumeration in regular API security testing.
Frequently asked questions
How was T-Mobile hacked in 2023?
T-Mobile says a bad actor obtained customer data through one of its APIs without authorisation, from around 25 November 2022 until it was detected on 5 January 2023. It has not disclosed exactly how the API was abused.
What data was exposed in the T-Mobile API breach?
Names, billing addresses, email addresses, phone numbers, dates of birth, T-Mobile account numbers and plan details for approximately 37 million accounts. Payment data, Social Security numbers, government IDs and passwords were not exposed.
How long did the T-Mobile API abuse last?
About six weeks, from around 25 November 2022 until T-Mobile detected it on 5 January 2023 and cut off access within a day.
Related NHI Mgmt Group resources
Mailchimp Breach 2022 · Salt Typhoon Telecom Breaches · API Key Management Guide · Authorisation Models Guide · ITDR Guide
How NHI Mgmt Group can help
APIs and the clients that call them are often missing from identity programmes. We help teams inventory API clients, give each one a governed identity and set monitoring that spots bulk harvesting early. See our NHI and AI agent security training.