Telecom provider T-Mobile has revealed that it has suffered a data breach after it became aware that some of its customers had fallen victim to SIM swapping attacks. Fraudsters carry out SIM swapping attacks with the aim of taking control of victims’ phone numbers by tricking company employees into transferring them to SIMs under the control of the fraudsters. Once a SIM card is compromised, hackers can steal money, cryptocurrency and personal information, including contacts synced with online accounts. Cybercriminals could also compromise social media accounts and bypass SMS- based 2FA services used by online services .
Unidentified individuals gained access to customers' account information, including personal information and personal identification numbers (PINs), and T-Mobile has already notified affected customers. Specifically, the company states the following in its relevant notification: "Recently, we detected unauthorized activity on your T-Mobile account, during which an unknown individual gained access to your account information, including personal information and your personal identification number (PIN). T-Mobile immediately discovered and terminated the unauthorized activity, however, we recommend that you change your account PIN."

The information exposed may include full name, address, home or email, account number, social security number, customer account personal identification number (PIN), account security questions and answers, date of birth, plan information and the number of customers associated with the account.
According to Bleeping Computer, hackers used an internal app to target up to 400 customers in attempted SIM swapping attacks. It should be noted, however, that the security breach did not affect business customers.

Therefore, affected T-Mobile customers are advised to change password, PIN, and security questions. Additionally, T-Mobile is offering two years of free credit monitoring and identity theft detection services to affected customers.
This is not the first time the mobile phone company has suffered a data breach.

- In 2017, hackers stole personal information from T-Mobile customers by exploiting a known vulnerability. By exploiting the vulnerability, attackers were able to gain access to data , including email addresses, billing account numbers, and phone IMSI numbers. Such information could be used by malicious actors in social engineering attacks against T-Mobile customer support employees, with the aim of stealing the victim’s phone number.
- In May 2018, a bug on T-Mobile's site allowed malicious actors to gain access to any customer's personal account information by providing them with a phone number.
- In August 2018, T-Mobile suffered a security breach in which the personal information of up to 2 million T-Mobile customers was exposed.
- In November 2019, T-Mobile disclosed a security breach that, according to the company, affected a small number of its prepaid customers.
- In March 2020, T-Mobile fell victim to a sophisticated cyberattack targeting its email provider. A data breach notification posted by the telecommunications giant on its website revealed that the security breach affected both employees and customers.
- Finally, in December 2020, the company revealed a new data breach that exposed customer network information (CPNI), including phone numbers and call records.
