T-Mobile has been breached more times than almost any other company of comparable size. Between 2018 and 2023, the US wireless carrier suffered at least seven documented data security incidents, exposing the personal information of hundreds of millions of customers and would-be customers. The incidents ranged from employee account compromises to massive database thefts affecting over 76 million people. After each breach, T-Mobile announced enhanced security measures. After the next breach, the cycle repeated. The serial nature of T-Mobile's security failures became a case study in what happens when a company treats security as a reactive PR problem rather than an engineering priority.
The 2021 breach was the most damaging. An attacker accessed T-Mobile's systems and ultimately exfiltrated personal data for approximately 76.6 million people - including Social Security numbers, dates of birth, driver's license information, and IMEI (device identifier) numbers. The attacker, a 21-year-old American named John Binns who was living in Turkey, later gave an interview to the Wall Street Journal in which he expressed frustration at how easy it had been. He described finding an unprotected router in T-Mobile's network as his initial access point. From there, he spent roughly a week moving through T-Mobile's systems before reaching the customer database servers.
The 2021 Breach: John Binns and the Unprotected Router
John Binns described his 2021 T-Mobile attack to the Wall Street Journal as surprisingly accessible. He said he scanned T-Mobile's internet-facing infrastructure and found an unprotected router with access to T-Mobile's data center in Washington state. The router provided a foothold from which he spent approximately a week moving laterally through T-Mobile's network, discovering and accessing customer database servers containing sensitive personal information.
The data stolen included: first and last name, date of birth, SSN, driver's license/ID information for approximately 7.8 million current T-Mobile postpaid customers; approximately 40 million former or prospective customers who had applied for credit (including SSN and driver's license); approximately 850,000 active prepaid customers (names, phone numbers, account PINs); and approximately 52,000 names associated with Metro by T-Mobile accounts. The total affected count was approximately 76.6 million people.
The breadth of data - including SSNs, dates of birth, and driver's license numbers - was sufficient for identity theft and financial fraud. Credit monitoring offers were extended to affected customers. T-Mobile ultimately agreed to a $350 million class action settlement and committed $150 million to security improvements. The FTC investigated and required T-Mobile to implement a comprehensive data security program with third-party assessment.
The Pattern: Seven Breaches in Five Years
The documented T-Mobile incidents: August 2018 (prepaid account data exposed for approximately 3% of customers); November 2019 (customer proprietary network information accessed); March 2020 (small number of customers' information accessed via employee accounts); December 2020 (employee accounts used to access customer accounts for SIM swapping, approximately 400 customers); August 2021 (the Binns breach, 76.6 million people); November 2022 (37 million accounts accessed via API abuse over approximately 2 months before detection); January 2023 (personal information for 836 customers including PINs accessed).
The November 2022 - January 2023 breach was not detected for approximately 2 months. The attacker used a misconfigured API that allowed retrieval of customer data including names, billing addresses, email addresses, phone numbers, account numbers, and plan features - without proper authentication. T-Mobile's disclosure stated that the attacker began querying the API around November 25, 2022 and was not detected until January 5, 2023.
This detection gap - two months of API queries exfiltrating 37 million customer records before any alert - suggested that T-Mobile's monitoring for unusual API access patterns was either non-existent or ignored. An attacker querying an API for 37 million records over two months would generate traffic patterns distinguishable from normal use; the failure to detect this suggested monitoring infrastructure was not reviewing API access for anomalies.
John Binns: Profile of an Attacker
John Binns's Wall Street Journal interview following the 2021 breach was unusual - attackers rarely give post-breach interviews while presumably still facing potential criminal liability. Binns described himself as living in Turkey, where he had US citizenship through his Turkish-American background. He said he attacked T-Mobile because he was angry at the US government (specifically claiming mistreatment by federal agencies) and wanted to create problems for them and draw attention to himself.
Binns had a prior online history in SIM swapping communities - he had been involved in SIM swapping attacks and had been the target of a SIM swap himself. His motivations appeared to be a mix of grievance, notoriety-seeking, and demonstrated technical capability rather than financial gain from the T-Mobile breach specifically. He did not attempt to sell the data immediately and instead appeared primarily focused on public attention.
Binns was arrested in Turkey in 2022 at the request of US authorities. He was extradited to the US and indicted in connection with the T-Mobile hack as well as prior SIM swapping activity. His case remained in the US federal court system through 2024.