T-Mobile Got Popped, and I'm Probably in There

T-Mobile Got Popped, and I'm Probably in There

Tech News data breach privacy security t-mobile

So this weekend a hacker posted on some forum claiming to have scraped the personal data of over 100 million T-Mobile customers, and by this morning T-Mobile had put out a statement confirming they're "aware of claims made in an underground forum" and are investigating. That phrasing is doing a lot of work. Not "we got hacked," not "here's what happened," just a very lawyer-flavored acknowledgment that something is going on.

I've been on T-Mobile since they absorbed my old Sprint account in the merger, and my first reaction reading the Motherboard piece this morning wasn't panic, it was this weird resigned feeling, like watching a package tracking page stall on "in transit" for the third day. Of course. Of course this is happening. Every year or two one of the big carriers has some version of this moment, and every time the response is the same three stages: forum post nobody official confirms, days of "we're looking into it," then eventually a number that's always bigger than what got reported first.

What's actually being claimed here, as far as anyone can tell right now, is nasty. Not just names and phone numbers, the usual stuff you shrug at because it's already floating around from some other breach five years back. This one supposedly includes Social Security numbers, driver's license info, and IMEI numbers, pulled from current customers, former customers, and apparently people who never even signed up but had their info sitting in a prospective-customer database somewhere. The seller was reportedly asking six bitcoin for the full set, something like a quarter million dollars at today's prices, which tells you they think it's worth a lot more than the going rate for a pile of emails and passwords.

I don't have any special insight into whether I'm personally in that dataset. That's the part that actually irritates me most about how these things go. You find out your data might be exposed from a tech blog quoting a forum screenshot, not from the company that was supposed to be safeguarding it. T-Mobile hasn't sent me anything. I checked my email twice this morning out of habit, nothing. Given the merger, my account has technically existed under three different corporate umbrellas in the last decade (Sprint, then T-Mobile, then whatever internal system they migrated everyone into), so if this dump goes back far enough I'd bet money I'm somewhere in it. Not a comforting bet to be making before coffee.

Here's my actual complaint, and it's not really about T-Mobile specifically, it's about why a phone carrier needs my Social Security number sitting in a database at all, years after I signed up. I get that they wanted it for a credit check when I opened the account. Fine. But there's no reason that number needs to still be retrievable in bulk a decade later attached to a live customer record. Data you don't need to keep is just liability wearing a business-value costume. Every company treats "we might need this someday" as sufficient reason to hoard everything forever, and then we all get to find out what that decision costs when someone finally breaks in and takes it.

The scope of this is genuinely still unclear as I'm writing this, which is worth saying plainly instead of pretending I know more than the reporting does. T-Mobile hasn't confirmed how many people are affected or which specific fields of data got out. If the history of these things holds, expect a bigger, uglier number in about a week, probably paired with a free year of credit monitoring as the apology gift. I already have two of those running from previous breaches. At some point I should just build a spreadsheet tracking which company owes me the next one.

If you're on T-Mobile, this is probably a decent weekend to go freeze your credit if you haven't already, and maybe change your account PIN while you're at it, since a stolen SSN plus phone number is exactly the kind of combo that makes SIM-swapping easier for whoever's motivated enough to try it on you specifically. Most of us aren't interesting enough targets for that. Some of us are, and won't know it until the fraud alerts start.