T-Mobile disclosed that an attacker had been querying a customer-facing API since November 2022 — undetected for about six weeks.
The API was designed to allow authorized systems to look up customer account information. But the authorization check wasn't working correctly. An attacker discovered they could query the API with any phone number and receive full account data: name, billing address, email, phone number, date of birth, T-Mobile account number, and plan details.
No passwords or financial data were exposed — but the attacker pulled 37 million customer records before T-Mobile detected the activity.
The attacker wasn't smashing through a wall. They were walking through an unlocked door, calmly, 37 million times. No alarm went off. No rate limit stopped them. No anomaly was flagged — until T-Mobile found it themselves.