Skip to main content
Federal Communications Commission · Announced 2024-09-30

T-Mobile USA, Inc., $15,750,000

T-Mobile entered an FCC consent decree resolving investigations into multiple data-breach incidents in 2021, 2022, and 2023 that affected millions of current, former, or prospective customers and some mobile-virtual-network-operator customers.

Case identifiers

Respondent
T-Mobile USA, Inc.
Agency
Federal Communications Commission
Announced
2024-09-30
Monetary relief
$15,750,000
Case number
FCC File Nos. EB-TCD-21-00032661; EB-TCD-23-00034726; EB-TCD-23-00035152; EB-TCD-23-00035233
Statutes cited
Communications Act §§ 201(b), 222 · 47 CFR § 64.2010(a)

Key facts

  • 1

    The FCC order says the incidents affected millions of current, former, or prospective T-Mobile customers and end-user customers of mobile virtual network operators.

  • 2

    The exposed information included names, addresses, dates of birth, Social Security numbers, driver’s-license numbers, and customer proprietary network information.

  • 3

    T-Mobile agreed to a $15.75 million civil penalty and an additional $15.75 million in cybersecurity spending over two years.

  • 4

    The consent decree required a designated Chief Information Security Officer with direct reporting to the CEO or designee and the board, plus reporting of confirmed covered incidents affecting more than 500 consumers within 48 hours.

What the order requires

Injunctive terms imposed by the Federal Communications Commission. These bind T-Mobile USA, Inc.'s data practices going forward.

  • Move toward modern zero-trust architecture and segment T-Mobile networks.
  • Adopt broad multi-factor authentication methods within the network.
  • Maintain a comprehensive written information-security program with annual review and revision.
  • Provide direct CISO reporting to company leadership and the board, including the consent decree’s covered-incident reporting requirement.

Primary sources

Read the original government documents. These are the authoritative records, everything on this page is derived from them.

Generate requests in under 60 seconds

Generate a deletion request for $9

The FCC order binds T-Mobile USA, Inc.'s future practices, but doesn't automatically delete your existing data. State privacy law (CCPA, CPA, TDPSA, VCDPA) gives you that right. OfflistMe generates a compliant deletion email pre-addressed to T-Mobile USA, Inc.'s registered privacy contact.

FAQ

What did the FCC charge T-Mobile USA, Inc. with?+

T-Mobile entered an FCC consent decree resolving investigations into multiple data-breach incidents in 2021, 2022, and 2023 that affected millions of current, former, or prospective customers and some mobile-virtual-network-operator customers. The Federal Communications Commission cited Communications Act §§ 201(b), 222, 47 CFR § 64.2010(a).

How much did T-Mobile USA, Inc. pay?+

T-Mobile USA, Inc. had monetary relief of $15,750,000, announced on 2024-09-30. The settlement also imposed injunctive terms (see below).

Does the T-Mobile USA, Inc. settlement mean my data has been deleted?+

No, the order does not automatically delete your data. You retain full rights under state privacy law (CCPA, CPA, TDPSA, VCDPA, and others) to submit your own deletion request. OfflistMe can generate a compliant deletion email pre-addressed to the respondent’s privacy contact.

How can I read the original FCC order?+

The Federal Communications Commission press release is available at https://docs.fcc.gov/public/attachments/DOC-405937A1.pdf. The case / matter number is FCC File Nos. EB-TCD-21-00032661; EB-TCD-23-00034726; EB-TCD-23-00035152; EB-TCD-23-00035233.

Related enforcement actions

Related