Washington state sues T-Mobile over 2021 data breach security failures

Washington state sues T-Mobile over 2021 data breach security failures

Latest News on T-Mobile Data Breach Lawsuit

Summary:
Washington State Attorney General Bob Ferguson has filed a consumer protection lawsuit against T-Mobile over the 2021 data breach that exposed the personal information of over 79 million customers, including more than 2 million Washington residents. The lawsuit alleges that T-Mobile failed to implement adequate security measures despite being aware of vulnerabilities in their systems for years25.

Key Highlights:

  1. Data Breach Details:

    • The breach occurred in March 2021 and was discovered in August of that year2.
    • The compromised information included sensitive personal data such as phone numbers, names, physical addresses, driver’s license information, and Social Security numbers (SSNs) for 183,000 Washington state consumers25.
  2. Security Failures:

    • T-Mobile allegedly failed to implement adequate security measures despite knowing about vulnerabilities in their systems for years25.
    • The company used "obvious" passwords to safeguard accounts containing sensitive personal data5.
  3. Customer Notification:

    • T-Mobile’s notification to affected customers was insufficient, particularly regarding the exposure of SSNs25.
    • The company sent a text message stating, “We have no evidence that your debit/credit card information was compromised,” which misled customers about the severity of the breach2.
  4. Previous Settlement:

    • In July 2022, T-Mobile agreed to a $350 million settlement in a related class-action lawsuit but made no admission of liability or wrongdoing2.
  5. Current Lawsuit:

    • The Washington State Attorney General’s office seeks civil penalties and institutional reforms to protect Washington residents affected by the breach25.
    • The lawsuit also asks for T-Mobile to bolster its cybersecurity program5.
  6. Telecom Security Regulations:

    • The lawsuit could set a precedent for stricter telecom regulations, particularly in light of recent breaches attributed to Chinese state-backed APT groups like Salt Typhoon3.
    • The Federal Communications Commission (FCC) is already working to enhance telecom security, including efforts to remove and replace equipment from Chinese companies deemed a security risk4.

Trustworthy Citations:

  • 2 Washington AG Sues T-Mobile Over 79M-Customer Data Breach ...
  • 5 Washington state sues T-Mobile over allegedly shoddy cyber practices leading to 2021 breach
  • 3 Salt Typhoon Victims Stack up, Over 2000 Critical Infrastructure ...

These sources provide detailed context and reliable information about the lawsuit, T-Mobile's security failures, and the broader implications for telecom security regulations in Washington state.