Wednesday, April 9, 2025
HomeCyber Security NewsWashington State Filed Lawsuit Against T-Mobile Massive Data Breach

Washington State Filed Lawsuit Against T-Mobile Massive Data Breach

Published on

SIEM as a Service

Follow Us on Google News

Washington State Attorney General Bob Ferguson filed a consumer protection lawsuit against T-Mobile for its alleged failure to secure sensitive personal information of over 2 million residents.

This lawsuit comes in the wake of a massive data breach that exposed the personal details of Washingtonians, putting them at heightened risk of fraud and identity theft.

The complaint, submitted to King County Superior Court, accuses T-Mobile of neglecting known cybersecurity vulnerabilities for years. Ferguson claims that despite being aware of these risks, T-Mobile misled consumers about its commitment to protecting their data.

- Advertisement - Google News

Furthermore, the lawsuit alleges that the company did not adequately inform customers about the breach’s severity and failed to provide complete disclosure regarding the compromised information.

T-Mobile Massive Data Breach

“This significant data breach was entirely avoidable,” Ferguson stated emphatically. “T-Mobile had years to fix key vulnerabilities in its cybersecurity systems — and it failed.”

The breach, which was discovered in August 2021, revealed that hackers accessed T-Mobile’s internal network, compromising the personal data of over 79 million customers across the nation.

T-Mobile had already been the target of numerous cyberattacks
T-Mobile had already been the target of numerous cyberattacks

Among them, 2,025,634 residents from Washington were affected, with approximately 183,406 individuals having their Social Security numbers exposed. Other compromised data included names, phone numbers, physical addresses, and driver’s license information.

According to the lawsuit, the data breach spanned from March 2021 until August 12, 2021. It states that T-Mobile was unaware of the breach due to inadequate security monitoring until an external source alerted the company about its data being sold on the dark web.

Attorney General Ferguson criticized T-Mobile’s breach notification process, describing it as inadequate. Customers who were notified received vague texts that lacked crucial information and, in some instances, misrepresented the severity of the breach.

Strikingly, those whose Social Security numbers were compromised did not receive notifications regarding this critical exposure, while customers unaffected by such breaches were informed about their status.

The lawsuit also highlights T-Mobile’s ongoing cybersecurity failures leading up to the breach. Despite acknowledging its vulnerability to cyberattacks, T-Mobile reportedly continued to use weak passwords to protect sensitive information.

Prior to the 2021 incident, the company had faced several cyberattacks and had been warned that it remained a prime target for hackers.

Ferguson’s lawsuit alleges that T-Mobile’s actions violate Washington’s Consumer Protection Act, seeking civil penalties and restitution for affected residents.

It also calls for measures to enhance T-Mobile’s cybersecurity policies and improve transparency in communications regarding data protection.

Assistant Attorneys General Mina Shahin, Kathleen Box, Bret Finkelstein, Gardner Reed, Paralegal Matt Hehemann, Legal Assistant Luis Oida, and Investigator Steuart Markley are spearheading this case for Washington State.

As the legal proceedings unfold, the spotlight remains on the urgent need for robust cybersecurity practices in the telecommunications industry.

ANY.RUN Threat Intelligence Lookup - Extract Millions of IOC's for Interactive Malware Analysis: Try for Free

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Latest articles

Windows Kerberos Vulnerability Enables Security Feature Bypass

Microsoft has disclosed a new security vulnerability in Windows operating systems, tracked as CVE-2025-29809.This flaw,...

Ransomware Groups Target Organizations to Exfiltrate Data and Blackmail via Leak Site Posts

Ransomware attacks have continued their relentless assault on organizations worldwide, with a focus on...

Hellcat Ransomware Upgrades Arsenal to Target Government, Education, and Energy Sectors

The cybersecurity community has raised alarms over the rapid evolution of the Hellcat ransomware...

Ransomware Group Actively Exploits Windows CLFS Zero-Day Vulnerability

Microsoft has uncovered a sophisticated ransomware campaign exploiting a zero-day vulnerability in the Windows...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Windows Kerberos Vulnerability Enables Security Feature Bypass

Microsoft has disclosed a new security vulnerability in Windows operating systems, tracked as CVE-2025-29809.This flaw,...

Ransomware Groups Target Organizations to Exfiltrate Data and Blackmail via Leak Site Posts

Ransomware attacks have continued their relentless assault on organizations worldwide, with a focus on...

Hellcat Ransomware Upgrades Arsenal to Target Government, Education, and Energy Sectors

The cybersecurity community has raised alarms over the rapid evolution of the Hellcat ransomware...