T-Mobile US, Inc. discovered that a malicious attacker was illegally accessing data through a single Application Programming Interface (“API”).
The research revealed that the threat actors accessed information for about 37 million active postpaid and prepaid customer accounts using this API, however many of these accounts did not include the complete data set.
Date of report (Date of earliest event reported): January 19, 2023
https://www.sec.gov/Archives/edgar/data/1283699/000119312523010949/d641142d8k.htm