EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/t-mobile-breach-2021
177/430

File EL-0254CriticalResolvedData Breach / Credential Theft

T-Mobile Data Breach

Also filed as T-Mobile US Data Breach · T-Mobile Customer Data Leak

The breach involved the unauthorized access and exfiltration of personal identifying information (PII) belonging to millions of T-Mobile customers. The exposed data included names, Social Security Numbers (SSNs), birth dates, and account details. The incident highlighted significant vulnerabilities in the company's network security protocols.

  • #t-mobile
  • #data-breach
  • #pii
  • #credential-theft
  • #2021
  • #telecom
Notoriety8/10
Event
17 Aug 2021
Disclosed
17 Aug 2021
Target
T-Mobile US
Actor
John Erin Binns
Scale
Millions of records
Status
Resolved

01Summary

The breach, disclosed in August 2021, involved the theft of sensitive customer data from T-Mobile US. The attacker, identified as John Erin Binns, gained access to a database containing records for millions of customers. The compromised data included highly sensitive PII such as full names, Social Security Numbers, and dates of birth. T-Mobile subsequently launched investigations and offered credit monitoring services to affected customers. The incident prompted regulatory scrutiny regarding the company's data security practices and led to significant legal and financial repercussions for T-Mobile.

02Background

The telecommunications industry is a frequent target for cybercriminals due to the sheer volume and sensitivity of customer data held by providers. T-Mobile, as a major US carrier, maintained vast databases of personal information, making it a high-value target for data theft and identity fraud.

03Key revelations

  1. 01The theft of full Social Security Numbers (SSNs) for millions of customers.
  2. 02The exposure of sensitive PII, enabling large-scale identity theft.
  3. 03The failure of T-Mobile's internal security protocols to prevent mass data exfiltration.

04Technical analysis

The breach was attributed to unauthorized access to a core customer database. While specific zero-day exploits were not publicly detailed, the attack vector suggested a failure in perimeter security or internal access controls, allowing the attacker to exfiltrate large volumes of structured PII data.

Attack vector
Unauthorized network access (likely via compromised credentials or exploited vulnerability)
Attack method
Data Exfiltration
Initial access
Compromised Credentials or Network Exploitation
Lateral movement
Internal Network Access
Exfiltration
Database Dump/Bulk Transfer
Malware type
Stealer

Vulnerabilities exploited

  • Internal Network Vulnerability

MITRE ATT&CK techniques

  • T1021.001
  • T1046

05Threat actor

The perpetrator, John Erin Binns, was an individual hacker whose motivation was purely financial. His actions exemplify the threat posed by opportunistic, non-state actors who target large, poorly secured databases for immediate monetary gain.

MITRE groups

  • T1113
  • T1078

Attribution sources

  • Media Reports
  • Law Enforcement

06Victims and impact

Countries affected

  • United States

07Data exposed

Data types

  • Names
  • Social Security Numbers
  • Dates of Birth
  • Account Details
  • PII

Notable documents

  • Customer Database Dump

08Financial damage

Estimated costs include regulatory fines, credit monitoring services, and class-action lawsuit settlements.

09Timeline

  1. 2021-08-17Breach discovered and publicly disclosed by T-Mobile.

10Key figures

  • John Erin BinnsAttacker/PerpetratorCharged with cybercrime

11Reaction and fallout

Public reaction

The public reaction was characterized by alarm and concern over identity theft risks. Consumers demanded immediate and robust security measures from major telecommunications providers.

Political impact

The incident increased regulatory pressure on the telecommunications sector, leading to calls for stricter federal oversight of data handling and cybersecurity compliance.

12Legal

T-Mobile faced multiple class-action lawsuits and regulatory investigations, resulting in mandated security improvements and financial penalties.

Prosecutions

  • John Erin BinnsCharged
    Charge
    Cybercrime/Theft of PII
    Jurisdiction
    United States

Civil lawsuits

  • Class-action lawsuits filed by affected customers

13Aftermath

Policy changes

  • Increased focus on mandatory data encryption and access control in the telecom sector.

Regulatory changes

  • Increased scrutiny from the Federal Trade Commission (FTC) regarding data security practices.

Security improvements

  • Mandatory multi-factor authentication (MFA) implementation for customer accounts.
  • Enhanced internal network segmentation and access logging.

14Significance and legacy

Significance

This breach served as a major case study in the risks associated with storing highly sensitive PII, particularly SSNs, in large, centralized corporate databases. It underscored the necessity of robust, layered security defenses and highlighted the inadequacy of previous industry-standard compliance measures.

Legacy

The incident contributed to a heightened awareness among consumers and regulators regarding the necessity of data minimization and the secure disposal of sensitive customer records. It accelerated the adoption of advanced security frameworks across the US corporate sector.

15Disclosure and media

Authentication
Forensic Analysis

Media partners

  • Reuters
  • The New York Times

Publishing organisations

  • Media Outlets

16Field notes

  1. 01The breach was reportedly facilitated by exploiting a weakness in the company's internal network infrastructure.
  2. 02The sheer volume of SSNs exposed made the data highly valuable on underground criminal marketplaces.

17Resolution

T-Mobile implemented significant security upgrades, including enhanced encryption and access controls, and settled multiple class-action lawsuits.

18Sources

Official documents

  • FTC Investigation Reports

References

  1. [1]T-Mobile Security Advisory
  2. [2]Major News Outlets Reporting
Fact sheetEL-0254

Dates

Event
17 Aug 2021
Started
17 Aug 2021
Discovered
17 Aug 2021
Disclosed
17 Aug 2021
Ongoing
No

Target

Organisation
T-Mobile US, Inc.
Type
Corporation
Sector
Telecommunications
Country
United States

Actor

Name
John Erin Binns
Type
Individual Hacker
Motivation
Financial gain through data sale and identity theft
Attribution
Medium
Status
Charged
Arrested
Yes
Convicted
No

Data

Volume
Millions of records
Sensitivity
Top Secret
Published
No
Sold (dark web)
Yes

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.