The US division of communications brand T-Mobile will pay $500 million as part of class action lawsuit over a data breach that hit the company in 2021.
Of the fine, $350m of it will be paid into a settlement fund while the remaining $150m will be used by the company to enhance its data security measures through to 2023.
The money will be paid to around 76.6m US residents who reportedly had their data affected by the T-Mobile breach. How the money will be divided has not been revealed, though an even split would provide each victim with a little over $4.50.
According to court documents, the aftermath of the attack saw victims suffer actual and attempted identity theft and fraud, such as unauthorised credit and account applications filed in their names.
The data breach took place in summer 2021, after a hacker claimed to have information on 100m of the company’s customers.
However, the exact number of people has since been revised. While around 48m people – 7.8m current customers and 40m former or prospective – were said to have been hit, the number has since increased to around 80m. In addition, more people affected by the breach may still be identified.
The data reportedly included phone numbers, names, physical addresses, unique IMEI numbers, and driver licences.
The hackers claimed that they had begun selling the stolen information on the dark web, with the price set at six bitcoins, equivalent to around £194,000 at the time.
With the company having around 100 million customers in the US at the time, the breach represented a significant share of its userbase.
In the aftermath of the breach, T-Mobile reset the PINs on the affected accounts as a precaution. The company did not, however, specify how hackers were able to access its systems.
However, in the case, plaintiffs accused T-Mobile of failing to properly disclose information about the breach and lacking proper defences to keep their data safe.
While the company has agreed to pay the settlement money, it has admitted no guilt over the breach. The move is still pending a judge’s decision.
Recommended
- Comment | What is the future of data management?
- Southern Co-op’s “Orwellian” facial recognition tech faces legal challenge
- AI to help Scottish dentists identify tooth decay begins testing
In a statement, T-Mobile laid out the steps it would take to boost its security and protect its customers.
These include creating a Cybersecurity Transformation Office that reports directly to its CEO. It will also engage with industry experts Mandiant, Accenture, and KPMG to design strategies and execute plans to further transform its cybersecurity programme.
In addition, the company has committed to investing hundreds of millions of dollars to enhance its current cybersecurity tools and capabilities and will conduct nearly 900,000 training courses for its employees and partners.
“Customers are first in everything we do and protecting their information is a top priority,” the company said in a statement. “Like every company, we are not immune to these criminal attacks. Our efforts to guard against them continue and over the past year we have doubled down on our extensive cybersecurity program to enhance existing programmes.”
T-Mobile was previously hit by data breaches in 2020 and 2018. The earlier one saw data on 2m customers, including names, billing post-codes, phone numbers, email addresses, account numbers, and account type of users, leaked.
Get the latest news from DIGIT direct to your inbox
Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.
To subscribe, click here.





