Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Data Breach - Hackers claim leak of 64 million T-Mobile records, but company denies breach
Data Breach Attacks Data Protection Identity & Access Management News & Analysis

Hackers claim leak of 64 million T-Mobile records, but company denies breach

Katrina ThompsonBy Katrina ThompsonJune 19, 20254 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Leak T-Mobile records
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

It has been reported that hackers have recently shared a new database they claim contains sensitive customer information stolen from the American telecommunications giant, T-Mobile. However, the company denied any connection to the archive, saying it had nothing to do with it, or its clients.

A “Trove of Sensitive Details”

The Cybernews report asserts that a sample of the dataset was uploaded to a popular data leak site at 2am on June 13th, with the attackers claiming the information was as recent as the first of June. This is especially concerning as relatively “new” data would put impacted individuals at risk of high-level security concerns.

Contained in the dataset were:

  • Names (first and last)
  • Birthdates
  • Phone numbers and email addresses
  • Tax IDs
  • Device IDs
  • Cookie IDs
  • IP addresses

According to the Cybernews research team, “If this data is legitimate, exposing 64M lines of highly sensitive information poses a serious threat of identity theft/fraud, surveillance, and further, better-targeted attacks on customers.”

T-Mobile Denies Breach Association

For not the first time, the second-largest mobile carrier in the US denied having been the target of a data breach.

Last year, the company was allegedy compromised by well-known threat actor IntelBroker, with source code available for sale on the dark web: SQL files, Siloprograms, Terraform data, Images, and t-mobile.com certifications. As proof, the attackers posted screenshots of internal developer Slack channels and administrative access to a Confluence server.

However, one source told Bleeping Computer that the screenshots of T-Mobile’s architecture were taken from earlier images posted to a third-party vendor’s servers.

This time, the company stated to Cybernews, “Any reports of a T-Mobile data breach are inaccurate. We have reviewed the sample data provided and can confirm the data does not relate to T-Mobile or our customers.”

What Is Unclear

Researchers have been unable to verify claims of T-Mobile’s connection to the breach, or whether the 64 million lines of code held in the database represent 64 million people. According to the research team, various data points like phone numbers appeared in previous T-Mobile associations, but “it was impossible to verify the archive with 100% accuracy.”

Without these pieces in place, customers cannot be notified of possible risk or take appropriate actions to prevent further damage.

These actions, designed to protect users following a breach, typically include resetting passwords and PINs, enabling 2FA, checking credit reports, using a password manager, closely watching bank and credit card accounts, and receiving credit monitoring services paid for by the compromised entity; in this case, potentially T-Mobile.

As Jamie Akhtar, CEO and Co-founder at CyberSmart, states, “Although there’s not necessarily any reason to doubt T-Mobile’s denial of the breach, it’s certainly worth being cautious if you’re a customer. The sensitive data hackers claim to have stolen could be used to launch personalised phishing attacks, steal identities, or commit fraud.”

It Is No Longer Enough to Rely on Company Cybersecurity Alone

As even enterprises with the money to invest in generous cybersecurity programs continue to get breached, or serve as enticing targets for attack, end-users must go beyond trust in company-based protections alone.

Akhtar offers a simple list of three things customers can do to ensure peace of mind where data sharing with large companies is concerned.

  1. Reset Passwords and Invest in Multi-factor Authentication (MFA): “if you haven’t already, reset your password and switch on multi-factor authentication. This will make it very tricky for hackers to compromise your account even if they have login credentials. As a rule, it’s worth doing this for every account you use, not just T-Mobile.”
  2. Be On the Watch for Unsolicited Calls and Emails – They Could be Scams: “If this data is legitimate, hackers will likely use it to target you with phishing scams. Remember, if you’re at all in doubt about whether a communication is genuine, trust your gut.”
  3. Monitor All Financial Accounts: “[In this case] it doesn’t appear that any financial data has been stolen, but that doesn’t mean cybercriminals won’t try to commit fraud or identity theft with the data they do have.”

In a climate where threat actors are eager to brag about, or fabricate, their latest heist, users need to realize on thing: that the value of their data goes hand-in-hand with their shared burden of data security.

Katrina Thompson

An ardent believer in personal data privacy and the technology behind it, Katrina Thompson is a freelance writer leaning into encryption, data privacy legislation, and the intersection of information technology and human rights. She has written for Bora, Venafi, Tripwire, and many other sites.

  • Katrina Thompson
    What Are AI SOC Agents? Use Cases, Architecture, and the Leading Vendors
  • Katrina Thompson
    How EM is boosting the career trajectory of VM analysts
  • Katrina Thompson
    The 7 Top AI SOC Platforms to Watch in 2026
  • Katrina Thompson
    The Best Exposure Assessment Platforms for 2026

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

7-Eleven Notifies Franchise Applicants After Breach Exposes Personal Data

May 19, 20262 Mins Read

Canvas cyberattack disrupts universities as ShinyHunters threatens massive data leak

May 12, 20267 Mins Read

Zara Owner Inditex Confirms Customer Data Breach Affecting Nearly 200,000 People

May 11, 20263 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}