T-Mobile pays $31.5 million FCC settlement over 4 data breaches

Share:

The Federal Communications Commission (FCC) announced a $31.5 million settlement with T-Mobile over multiple data breaches that compromised the personal information of millions of U.S. consumers.

This agreement resolves the FCC Enforcement Bureau investigations into several cybersecurity incidents and resulting data breaches that impacted T-Mobile’s customers in 2021, 2022, and 2023 (an API incident and a sales application breach).

As part of the settlement, the telecom carrier must invest $15.75 million in cybersecurity enhancements and pay the U.S. Treasury an additional $15.75 million civil penalty.

The company has also committed to implementing more robust security measures, including adopting modern cybersecurity frameworks like zero-trust architecture and multi-factor authentication that resists phishing attacks.

“Today’s mobile networks are top targets for cybercriminals. Consumers’ data is too important and much too sensitive to receive anything less than the best cybersecurity protections,” said FCC Chairwoman Jessica Rosenworcel.

“We will continue to send a strong message to providers entrusted with this delicate information that they need to beef up their systems or there will be consequences.”

As part of the agreement, T-Mobile has committed to enhance privacy, data security, and cybersecurity practices by addressing foundational security flaws, improving cyber hygiene, and adopting robust modern architectures by:

  • Providing regular cybersecurity updates through the company’s Chief Information Security Officer to the board of directors to ensure greater oversight and governance,
  • Adopting data minimization, data inventory, and data disposal processes to limit the collection and retention of customer information,
  • Detecting and tracking critical network assets to prevent misuse or compromise,
  • Working toward implementing a modern zero-trust architecture, segmenting its networks to improve security,
  • Assesing information security practices through independent third-party audits,
  • Adopting multi-factor authentication across company systems to block breach risks linked to leakage, theft, and the sale of stolen credentials.
ADVERTISING

“With companies like T-Mobile and other telecom service providers operating in a space where national security and consumer protection interests overlap, we are focused on ensuring critical technical changes are made to telecommunications networks to improve our national cybersecurity posture and help prevent future compromises of Americans’ sensitive data,” Loyaan A. Egal, Chief of FCC’s Enforcement Bureau, added.

The FCC’s Privacy and Data Protection Task Force, established in 2023 by Chairwoman Rosenworcel, played a central role in the investigation and settlement, just as it did when the FCC reached similar settlements with AT&T in September 2024 ($13 million) and Verizon on behalf of its subsidiary TracFone Wireless in July 2024 ($16 million).

The FCC has also fined the largest U.S. wireless carriers almost $200 million in April 2024 for sharing their customers’ real-time location data without their consent.

The April forfeiture orders finalized Notices of Apparent Liability (NAL) issued against AT&T, Sprint, T-Mobile, and Verizon in February 2020 and slapped each of the four carriers with multi-million fines: $12 million for Sprintand $80 million for T-Mobile (the two carriers have merged since the investigation began), more than $57 million for AT&T, and an almost $47 million fine for Verizon.

In February, the FCC also updated its data breach reporting rules to require telecom companies to report data breaches impacting their customers’ personally identifiable information within 30 days.

Sergiu Gatlan

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
3:50 am, Jan 27, 2025
weather icon 8°C
L: 7° | H: 9°
few clouds
Humidity: 86 %
Pressure: 980 mb
Wind: 17 mph SW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 20%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 7:45 am
Sunset: 4:40 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
7° | 9°°C 1 mm 100% 19 mph 82 % 986 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
6° | 8°°C 1 mm 100% 20 mph 89 % 996 mb 0 mm/h
Wed Jan 29 9:00 pm
weather icon
5° | 7°°C 1 mm 100% 13 mph 94 % 1005 mb 0 mm/h
Thu Jan 30 9:00 pm
weather icon
3° | 6°°C 1 mm 100% 13 mph 95 % 1026 mb 0 mm/h
Fri Jan 31 9:00 pm
weather icon
2° | 5°°C 1 mm 100% 8 mph 93 % 1031 mb 0 mm/h
Today 6:00 am
weather icon
7° | 8°°C 0.8 mm 80% 14 mph 81 % 980 mb 0 mm/h
Today 9:00 am
weather icon
7° | 7°°C 0 mm 0% 18 mph 73 % 982 mb 0 mm/h
Today 12:00 pm
weather icon
5° | 5°°C 0.76 mm 76% 19 mph 82 % 986 mb 0 mm/h
Today 3:00 pm
weather icon
7° | 7°°C 1 mm 100% 15 mph 76 % 984 mb 0 mm/h
Today 6:00 pm
weather icon
7° | 7°°C 1 mm 100% 16 mph 81 % 984 mb 0 mm/h
Today 9:00 pm
weather icon
7° | 7°°C 1 mm 100% 17 mph 76 % 983 mb 0 mm/h
Tomorrow 12:00 am
weather icon
6° | 6°°C 1 mm 100% 20 mph 89 % 980 mb 0 mm/h
Tomorrow 3:00 am
weather icon
8° | 8°°C 1 mm 100% 19 mph 87 % 979 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€96,794.92
-3.54%
Ethereum(ETH)
€3,036.84
-4.80%
XRP(XRP)
€2.87
-4.22%
Tether(USDT)
€0.95
-0.02%
Solana(SOL)
€225.06
-8.83%
USDC(USDC)
€0.95
0.01%
Dogecoin(DOGE)
€0.314321
-7.37%
Shiba Inu(SHIB)
€0.000018
-6.78%
Pepe(PEPE)
€0.000012
-12.43%
Peanut the Squirrel(PNUT)
€0.342367
3.03%
Scroll to Top