DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

CONSUMER ALERT: Consumers Impacted by T-Mobile Data Breach At Risk of Potential Identity Theft

Posted on March 3, 2022 by Dissent

The following alert was published by New York State Attorney General, but it applies to consumers in all states, so if you were a former, then-current, or prospective T-Mobile customer in 2021, you should read this:

NEW YORK – New York Attorney General Letitia James today provided guidance to consumers who may have been impacted by a 2021 T-Mobile data breach, following reports that the stolen information was put for sale on the dark web. Alongside a bipartisan coalition of attorneys general, Attorney General James advised all New York residents who believe they were impacted by the data breach to take appropriate steps to protect their information from identity theft. This comes after several individuals received alerts that their information was circulating online following the August 2021 data breach.

“I have an urgent message for T-Mobile customers and other consumers: Be aware of any misuse of your personal information and follow the guidance provided by my office to protect yourself from identity theft,” said Attorney General James. “Information stolen in a massive data breach has fallen into the wrong hands and is circulating on the dark web. The guidance offered by my office can help prevent identity theft. I advise all New Yorkers to maintain their financial safety by following the guidance my office has laid out. No consumer should have to deal with the devastating realities of identity theft.”

In August 2021, T-Mobile reported a massive data breach compromising the sensitive personal information of millions of current, former, and prospective T-Mobile customers. The breach impacted more than 53 million individuals, including more than 4 million New Yorkers. Among other categories of impacted information, millions had their names, dates of birth, Social Security numbers, and driver’s license information compromised.

Recently, a large subset of the information compromised in the breach was discovered for sale on the dark web — a hidden portion of the Internet where cyber criminals buy, sell, and track personal information. Many individuals received alerts through various identity theft protection services informing them that their information was found online in connection with the breach, confirming that impacted individuals are at heightened risk for identity theft.

Attorney General James urges anyone who believes they were impacted by the T-Mobile breach to take the following steps to protect themselves:

  • Monitor your credit. Credit monitoring services track your credit report and alert you whenever a change is made, such as a new account or a large purchase. Most services will notify you within 24 hours of any change to your credit report.
  • Consider placing a free credit freeze on your credit report. Identity thieves will not be able to open a new credit account in your name while the freeze is in place. You can place a credit freeze by contacting each of the three major credit bureaus:
    • Equifax | https://www.equifax.com/personal/credit-report-services/credit-freeze
      +1 (888) 766-0008
    • Experian | https://www.experian.com/freeze/center.html
      +1 (888) 397-3742
    • TransUnion | https://www.transunion.com/credit-freeze
      +1 (800) 680-7289
  • Place a fraud alert on your credit report. A fraud alert tells lenders and creditors to take extra steps to verify your identity before issuing credit. You can place a fraud alert by contacting any one of the three major credit bureaus.
  • Additional Resources. If you believe you are a victim of identity theft, go to identitytheft.gov for assistance on how to report it and recover from it — or contact our office for help by completing and submitting a complaint with the Bureau of Internet and Technology or by calling (800) 771-7755.

Related:

  • Des Moines Man Charged with Computer Fraud
  • CrowdStrike catches insider feeding information to ScatteredLapsus$Hunters
  • Fired techie admits sabotaging ex-employer, causing $862K in damage
  • Threat actors have reportedly launched yet another campaign involving an application connected to Salesforce
  • Researchers claim 'largest leak ever' after uncovering WhatsApp enumeration flaw
  • Eurofiber admits crooks swiped data from French unit after cyberattack
Category: Business SectorID Theft

Post navigation

← The Tel Aviv company paid millions to stop cyber criminals
NIS 2.0—the EU looks to bolster its cybersecurity laws →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Teen who allegedly stole millions of personal data records arrested in Spain
  • Akira ransomware: FBI tallies 250 million in payouts
  • IE: HSE confirms second ransomware attack but ‘no evidence’ patient data was stolen
  • Examining impact of federal relief program after major healthcare cyberattack — Research Brief
  • Justice Department Announces Actions to Combat Two Russian State-Sponsored Hacking Groups
  • Should entities be required to disclose the name of a vendor if the breach was at the vendor’s?
  • The Hidden Risks of Information Disclosure: A Costly Lesson from Cornwall
  • Defense Bill Would Require New Cyber Requirements for Some DoD Telecom Contracts
  • Tell the truth, or someone will tell it for you — Trumbull County, Ohio edition (1)
  • US Posts $10 Million Bounty for Iranian Hackers

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • U.S. Plans to Scrutinize Foreign Tourists’ Social Media History
  • ANNOUNCEMENT: EFF Launches Age Verification Hub as Resource Against Misguided Laws
  • FTC Denies Petition from SpyFone App CEO to Vacate 2021 Order
  • Privacy concerns raised as Grok AI found to be a stalker’s best friend
  • PRIVACY—S.D. Cal.: Employee did not waive privacy right in personal email data on company provided laptop, (Dec 5, 2025)

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: Dissent.73
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.