Business Context and Reporting Period
This Form 8-K Current Report was filed by T-Mobile US, Inc. on August 27, 2021, pursuant to Item 7.01 (Regulation FD Disclosure). The filing addresses a significant cybersecurity incident confirmed on August 17, 2021, which compromised the data of millions of current, former, and prospective customers.
Key Financial Metrics
The filing text does not provide specific financial metrics such as revenue, profit, cash flow, margins, debt, or liquidity figures. The document focuses exclusively on the operational and security implications of the cyberattack.
Material Changes and Incident Details
- Incident Scope: A criminal cyberattack compromised customer data including names, addresses, dates of birth, Social Security numbers, and driver's license/ID numbers.
- Exclusions: The breach did not expose customer financial information, credit card data, debit card data, or other payment information.
- Methodology: The attacker utilized specialized tools to access testing environments and employed brute force attacks to infiltrate IT servers containing customer data.
- Current Status: The breach has been contained, access points closed, and the investigation is substantially complete. Management states there is no ongoing risk to customer data from this specific breach.
Guidance, Outlook, and Management Commentary
CEO Mike Sievert expressed deep regret and apologized for the failure to prevent the exposure. Management outlined a multi-year investment strategy to enhance cybersecurity, including:
- Customer Remediation: Offering two years of free identity protection via McAfee, promoting Scam Shield, and providing Account Takeover Protection for postpaid customers.
- Strategic Partnerships: Entering long-term partnerships with cybersecurity experts Mandiant (for forensic investigation and strategic planning) and consulting firm KPMG (for security policy review and gap analysis).
- Risks: The filing highlights legal, reputational, and financial risks associated with the incident and the evolving nature of cyber threats.
Investor Verification Checklist
- Verify the total number of affected individuals (current, former, and prospective customers) as the filing states "millions" without a precise count.
- Monitor future filings for quantification of legal liabilities, regulatory fines, and remediation costs.
- Assess the impact of the incident on customer churn rates and brand reputation in upcoming quarterly reports.
- Review the specific scope of the Mandiant and KPMG engagements for details on the multi-year investment amount.