Business Context and Reporting Period
This Form 8-K was filed by T-Mobile US, Inc. on August 20, 2021, under Item 7.01 (Regulation FD Disclosure). The filing provides an update regarding an ongoing forensic investigation into a significant cyberattack against T-Mobile systems. The company states it has closed off the access and egress points used by the bad actor, though the investigation remains ongoing.
Key Financial Metrics
The filing text does not provide specific values for revenue, profit, cash flow, margins, debt, or liquidity. This report focuses exclusively on the scope of a cybersecurity incident and remediation efforts rather than financial performance metrics.
Material Changes and Incident Scope
The filing details expanded findings regarding the data breach compared to previous reports:
- Current Postpaid Customers: Previously reported 7.8 million accounts with compromised SSNs and driver's license/ID information. An additional 5.3 million current postpaid accounts were identified with compromised names, addresses, dates of birth, phone numbers, IMEIs, and IMSIs (no SSNs or driver's license/ID information).
- Former/Prospective Customers: Previously reported approximately 40 million accounts with compromised SSNs and driver's license/ID information. An additional 667,000 former customer accounts were identified with compromised names, phone numbers, addresses, and dates of birth (no SSNs or driver's license/ID information).
- Prepaid Customers: Approximately 850,000 active prepaid customer names, phone numbers, and account PINs were exposed; all PINs have been reset. Up to 52,000 names related to current Metro by T-Mobile accounts may have been included.
- Device Identifiers: Additional stolen data files containing phone numbers, IMEI, and IMSI numbers were identified, containing no personally identifiable information.
- Financial Data: The company reports no indication that customer financial information, credit card information, or debit/payment information was compromised.
Guidance, Outlook, and Management Commentary
Management is committed to transparency and will provide updates if new information impacts those affected. The company is taking proactive steps to protect customers, including:
- Offering two years of free identity protection services via McAfee's ID Theft Protection Service to affected individuals.
- Recommending eligible customers sign up for free scam-blocking protection through Scam Shield.
- Supporting customers with security best practices, such as resetting PINs and passwords.
- Collaborating with industry-leading experts to enhance security across platforms.
The filing includes standard forward-looking statements cautioning that actual results may differ due to risks associated with the cybersecurity incident, including legal, reputational, and financial risks.
Investor Verification Checklist
- Verify the total number of affected accounts across current, former, and prepaid segments.
- Confirm the specific types of data compromised for each customer segment (e.g., presence or absence of SSNs).
- Monitor for updates on the forensic investigation timeline and potential legal or regulatory consequences.
- Review the company's investor relations website and designated social media channels (@TMobileIR, @MikeSievert) for further material disclosures.
- Assess the potential financial impact of the identity protection services and remediation costs, which are not quantified in this filing.