T-Mobile USA, Inc., $15,750,000
T-Mobile entered an FCC consent decree resolving investigations into multiple data-breach incidents in 2021, 2022, and 2023 that affected millions of current, former, or prospective customers and some mobile-virtual-network-operator customers.
Case identifiers
- Respondent
- T-Mobile USA, Inc.
- Agency
- Federal Communications Commission
- Announced
- 2024-09-30
- Monetary relief
- $15,750,000
- Case number
- FCC File Nos. EB-TCD-21-00032661; EB-TCD-23-00034726; EB-TCD-23-00035152; EB-TCD-23-00035233
- Statutes cited
- Communications Act §§ 201(b), 222 · 47 CFR § 64.2010(a)
Key facts
- 1
The FCC order says the incidents affected millions of current, former, or prospective T-Mobile customers and end-user customers of mobile virtual network operators.
- 2
The exposed information included names, addresses, dates of birth, Social Security numbers, driver’s-license numbers, and customer proprietary network information.
- 3
T-Mobile agreed to a $15.75 million civil penalty and an additional $15.75 million in cybersecurity spending over two years.
- 4
The consent decree required a designated Chief Information Security Officer with direct reporting to the CEO or designee and the board, plus reporting of confirmed covered incidents affecting more than 500 consumers within 48 hours.
What the order requires
Injunctive terms imposed by the Federal Communications Commission. These bind T-Mobile USA, Inc.'s data practices going forward.
- Move toward modern zero-trust architecture and segment T-Mobile networks.
- Adopt broad multi-factor authentication methods within the network.
- Maintain a comprehensive written information-security program with annual review and revision.
- Provide direct CISO reporting to company leadership and the board, including the consent decree’s covered-incident reporting requirement.
Primary sources
Read the original government documents. These are the authoritative records, everything on this page is derived from them.
- Federal Communications Commission press releasehttps://docs.fcc.gov/public/attachments/DOC-405937A1.pdf
- Consent order / final orderhttps://docs.fcc.gov/public/attachments/DA-24-860A1_Rcd.pdf
Generate requests in under 60 seconds
Generate a deletion request for $9
FAQ
What did the FCC charge T-Mobile USA, Inc. with?+
T-Mobile entered an FCC consent decree resolving investigations into multiple data-breach incidents in 2021, 2022, and 2023 that affected millions of current, former, or prospective customers and some mobile-virtual-network-operator customers. The Federal Communications Commission cited Communications Act §§ 201(b), 222, 47 CFR § 64.2010(a).
How much did T-Mobile USA, Inc. pay?+
T-Mobile USA, Inc. had monetary relief of $15,750,000, announced on 2024-09-30. The settlement also imposed injunctive terms (see below).
Does the T-Mobile USA, Inc. settlement mean my data has been deleted?+
No, the order does not automatically delete your data. You retain full rights under state privacy law (CCPA, CPA, TDPSA, VCDPA, and others) to submit your own deletion request. OfflistMe can generate a compliant deletion email pre-addressed to the respondent’s privacy contact.
How can I read the original FCC order?+
The Federal Communications Commission press release is available at https://docs.fcc.gov/public/attachments/DOC-405937A1.pdf. The case / matter number is FCC File Nos. EB-TCD-21-00032661; EB-TCD-23-00034726; EB-TCD-23-00035152; EB-TCD-23-00035233.