Back to the archive

The encyclopedia · Legal & Compliance · Legal decision · 2021–2022

A hacker took Social Security numbers for 76M T-Mobile customers — settlement: $350M

T-Mobile disclosed in 2021 that SSNs and license numbers for nearly 80 million people had been stolen. It settled for $350M plus $150M in security upgrades.

T-Mobile US · 2022-07-22

What happened

T-Mobile disclosed in August 2021 that an attacker had accessed servers holding personal records for close to 80 million current, former and prospective customers. The stolen data included names, addresses, dates of birth, Social Security numbers and driver's license numbers — the specific fields identity thieves need, rather than account metadata alone.

At least 44 proposed class actions were filed and consolidated into a single case in federal court in Kansas City, Missouri. T-Mobile did not admit wrongdoing but agreed in July 2022 to settle for $350 million in direct payments to affected customers, plus a further $150 million commitment to upgrade its data security through 2023.

Settlement terms included cash reimbursement up to $25,000 for documented fraud losses, compensation for time spent resolving fraud, a flat alternative payment for class members without documented losses, and two years of free identity-monitoring service. The case closed without any admission that T-Mobile's security practices had been deficient, but the size of the payout followed directly from the scale and sensitivity of the data exposed.

Why it happened

  • The breach exposed Social Security and driver's license numbers, not just account details — data that enables identity theft rather than just account fraud.
  • Nearly 80 million records meant the exposure covered a large share of T-Mobile's customer base at once, driving the scale of the eventual settlement.
  • Dozens of separate lawsuits were filed and consolidated, showing the breach's reach extended across multiple states and legal jurisdictions simultaneously.
  • The settlement bundled compensation with a forward-looking security spending commitment, an implicit acknowledgment that the existing security posture needed to change even without admitting fault.
What it cost$350M settlement plus $150M in security upgradescostly

The lesson

The fields a breach exposes set the size of the liability more than the number of records does — SSNs and government ID numbers turn a data incident into an identity-theft enabler.

Sources

spotted an error? The club wants to know.

Comments · 0

    Sign in to join the comments.

    More like this

    Somewhere, someone solved the problem this company failed at. 2nd Opinion →