Data Breaches

T-Mobile $350M Data Breach Settlement: Is It Too Late to Claim?

T-Mobile data breach settlement illustration showing a sea of uncashed checks under a stormy sky

In 2021, approximately 76 million T-Mobile customers were victims of a cyberattack that resulted in the exposure of their sensitive information, including Social Security Numbers (SSNs) and driver’s license data. Due to this, the organisation faced a lawsuit that led to the introduction of the T-Mobile data breach settlement a few years later.

The settlement scheme was designed specifically for customers (both current and former, as well as affected prospective customers) whose information was compromised during the 2021 T-Mobile data breach. The affected people were able to claim from the $350 million class action settlement fund, though that claim window has since closed.

In this article, we will be covering everything you need to know about the data breach settlement scheme. From what it is, how it started, how it affected customers, who was eligible for compensation, how claims were filed, and where the settlement stands today. Without further delay, let’s get started!

2021 T-Mobile Data Breach: How It Happened

T-Mobile US, Inc. is a wireless network operator in the United States. The company has been in service since 1994, when it started as VoiceStream Wireless. Currently, the company stands as the second-largest wireless network in the United States by total connections, ending the third quarter of 2025 with 139.9 million customer connections against Verizon’s 146.1 million.

In 2021, the network company experienced its largest and most damaging data breach. This came after earlier data breaches in 2009, 2015, 2017, 2018, 2019, and 2020. However, the 2021 breach was far more consequential in T-Mobile’s history.

On August 12, 2021, the company began an internal investigation into a potential intrusion. On August 16, 2021, T-Mobile publicly confirmed that unauthorised access to some of its data had occurred, and the following day it verified that personal customer information had been stolen.

The attack resulted in the extraction of records covering approximately 76 million people, including personal identifiers such as names, addresses, account PINs, dates of birth, Social Security numbers, and driver’s license details. Social Security numbers and driver’s license or ID information were exposed for about 7.8 million current postpaid customers and just over 40 million former or prospective customers who had applied for credit with T-Mobile. The compromised information included that of current customers, former customers, and individuals who had applied for credit with T-Mobile.

The data breach was a result of an unprotected GPRS gateway. The hacker, John Erin Binns — known online as “IRDev” — brute-forced an SSH login on an exposed device, then moved laterally through T-Mobile’s network, which lacked the segmentation needed to contain him. Public disclosure of the attack began in mid-August 2021 after reports that T-Mobile data was being sold on a hacking forum — a pattern that plays out in nearly every large breach, where stolen records surface for sale within days.

Binns publicly claimed his motivation was to expose T-Mobile’s weak security, though federal prosecutors allege he and his co-conspirators stole the data to raise their standing among hackers and to sell it on criminal forums. He was indicted by a federal grand jury in 2022; the charges were unsealed in January 2024, and he was arrested in Turkey in May 2024.

However, the company experienced another data breach in 2023, making it the U.S. carrier with the most significant breaches in recent memory. That intrusion began around November 25, 2022, was discovered on January 5, 2023, and exposed data on approximately 37 million customers, including names, billing addresses, phone numbers, email addresses, dates of birth and account numbers. T-Mobile said no Social Security numbers, government ID numbers, passwords, PINs or financial information were involved.

The 2021 T-Mobile data breach triggered significant legal consequences, resulting in the introduction of the T-Mobile data breach settlement. Find out what the $350 million data breach settlement means for affected customers and how they can claim it in the next section of this article.

T-Mobile Data Breach Settlement

After the 2021 data breach, those who were victims of the cyber attack likely faced out-of-pocket costs for obtaining credit reports, credit freezes, credit monitoring services and other protective measures to deter and detect identity theft.

Because T-Mobile did not protect its data properly, the organisation faced multiple class action lawsuits. The plaintiffs alleged that T-Mobile had failed to protect customer data despite promising customers privacy and protection.

To address the lawsuits, the organisation agreed to pay $350 million to settle those class action claims. Plaintiffs filed for preliminary approval on July 22, 2022, and the U.S. District Court for the Western District of Missouri preliminarily approved the settlement on July 26, 2022. Final approval followed on June 29, 2023.

The class action settlement was aimed at covering cash payments, identity defence services, restoration services, notification costs, and attorneys’ fees. As part of the agreement, the company also agreed to separately commit to upgrading its data security infrastructure by spending $150 million on data security and cybersecurity investments.

Payments began rolling out on May 30, 2025. Victims who documented out-of-pocket losses and lost time — such as credit monitoring costs, identity theft expenses, and hours spent dealing with fraud — could receive up to $25,000 combined. Claimants who chose the alternative cash payment instead received $25, or $100 if they were California residents at the time of the breach, with final amounts varying because the fund was fixed and paid out proportionally.

Notably, filing a claim or doing nothing released all breach-related legal claims against T-Mobile except SIM-swap claims, which were carved out of the settlement.

How The Data Breach Affected Customers

The 2021 T-Mobile data breach affected tens of millions of subscribers. Because the major data that were exposed were sensitive personal information and identifiers, the impact on affected customers was primarily identity theft.

These exposures placed users at a significant long-term risk. In response to the stolen identity, affected customers had to spend time and money to protect themselves from the future impact of the cyberattack.

Who is eligible for the compensation?

The T-Mobile settlement payout is only open to users, both current, former and prospective customers who were a victim to the 2021 data breach attack and their information was compromised. In summary, to be eligible for benefits from the class action settlement:

  • You must be part of the approximately 76 million people who were affected in 2021.
  • And you must have filed a valid claim before the stipulated deadline.
  • Must be a resident in the United States and territories.

Those who were not eligible to make a claim include the presiding judge and court staff, T-Mobile’s officers and directors, class counsel, and anyone who opted out of the settlement.

How To File a Claim

Affected customers filed a claim through the official settlement website. It involved:

  • Visiting the official portal.
  • Entering the Notice ID and confirmation code from the notice they received to verify their identity.
  • Select the compensation type, which could be cash, reimbursement, or services.
  • Uploading proof of fraud-related losses.
  • Afterwards, keep track of the submission through confirmation emails or the online status tracker.

However, the claim deadline has passed. It ended on January 23, 2023. Meaning, if you were a victim of the 2021 breach and would have qualified for the T-Mobile settlement payout, you can no longer file a claim.

For more information and inquiries on how to file a claim, you can contact the administrator through the official website or by phone at (833) 512-2314. Be aware that closed settlements attract impostors: no legitimate administrator charges a fee to file, and unsolicited texts claiming to be a settlement payout follow the same playbook as other brand-impersonation scams.

T-Mobile Breach Settlement: Payout Timeline

The claim process of the data breach settlement started in late October and ended on January 23, 2023. The payout was originally expected around April 2025, but appeals over class counsel’s fee award pushed it back — the Eighth Circuit ruled in July 2024, and the district court entered a revised fee order in January 2025. The settlement administrator, Kroll Settlement Administration, began distributing payments on May 30, 2025. According to the official settlement website, that initial distribution is now complete and the deadline to request a reissued payment has passed. A residual distribution of leftover and uncashed funds is still expected, with no date announced.

How Were Victims Compensated

The T-Mobile settlement payout was distributed to claimants through physical and digital payment methods. Class members who filed a valid claim could choose between the following compensation options.

Flat Cash Payment

Those who filed a valid claim and were approved could receive flat cash compensation. This was the simpler option: a claim form was still required, but no proof of loss was needed. The payment was $25, or $100 for claimants who were California residents at the time of the breach.

Reimbursement for Losses

Claimants who could show proof of fraud or identity theft tied to the breach and evidence of the money spent on dealing with the fallout were eligible to receive up to $25,000 per person, covering out-of-pocket losses and lost time combined. Time spent dealing with the aftermath was compensated at $25 per hour for up to 15 hours, or at the claimant’s documented hourly wage if they took time off work. Qualifying expenses for this reimbursement include:

  • Credit monitoring
  • Professional fees for identity theft remediation
  • Direct fraud losses traceable to the breach

Non-Cash Compensation

Claimants connected to the 2021 breach were entitled to non-cash benefits, which included two years of free identity-defence and restoration services. The enrolment window for these services has since closed, so anyone still wanting coverage will need to arrange it independently — our dark web monitoring reviews compare what the main providers actually detect.

Note: Cash compensation can be through a paper check, direct deposit, prepaid cards or through any digital payment services.

Impact of The Data Breaches on The Organisation

The organisation has faced multiple data breaches since 2009. These attacks have affected the company’s operation, reputation and revenue. The effects of the data breaches include:

  • Loss of customer trust and loyalty
  • Decline in the company’s reputation
  • The organisation has committed roughly $530 million across settlements, penalties, and mandated security spending tied to these incidents — the $350 million class action fund, $150 million in voluntary security investment, and a $31.5 million FCC settlement in September 2024 split evenly between a civil penalty and required cybersecurity investment.

 

A single door fitted with seven different locks, two of them left open, illustrating the layered steps — credit freeze, MFA, fraud alert, SIM-swap protection — needed after a data breach exposes your information.

What To Do if Your Data Shows Up on The Dark Web

Data breaches happen so often that hundreds of millions of people have fallen victim — the dark web statistics for 2026 put the scale in context. If your data shows up on the dark web, it is important to follow necessary safety measures to contain the exposure. Some of the common steps you can take to protect your data during a breach include:

1. Identify the problem

The first step is to identify the problem and its cause. You can use trusted and reliable data breach trackers, such as Have I Been Pwned, to check which of your email addresses or credentials have been exposed on the dark web. If you are new to how these layers of the internet actually work, our guide on the deep web vs the dark web explains where leaked data typically ends up.

2. Change Compromised Password

After identifying the problem, the next thing to do is to change every password that was exposed. It’s possible that threat actors haven’t fully gained access to your credentials; changing your password immediately can be one of the proactive steps to take after a data breach.

3. Enable 2FA/MFA

Afterwards, ensure that all of your accounts use two-factor authentication (2FA) or multi-factor authentication (MFA). This ensures that even if an attacker has the email address and password for a given account, they still need access to a trusted device to verify your identity. This matters more than it used to, because criminals now use AI tools built for fraud to write convincing phishing messages at scale.

4. Place a Credit Freeze

Most breaches result in the exposure of Social Security numbers and other sensitive personal identifiers, and even financial credentials. If this is the case, you have to add a security freeze to your credit. This approach is highly recommended because it blocks access to your credit report, preventing cyber attackers from opening a new credit account in your name without your knowledge. The FTC explains how to place a free credit freeze with each of the three bureaus.

5. Monitor Your Credit Reports

Keep an eye out for your credit reports, investment, and crypto accounts for any unusual activity or inquiries you do not recognise. You can request your reports for free at AnnualCreditReport.com. Given that the T-Mobile network has faced multiple data breaches, this is worth doing even if you think your information was not involved in any of the breach scandals.

6. Try to Add SIM-Swapping Protection to Your Phone

The organisation has recorded multiple SIM swapping incidents, notably in 2020. During this incident, attackers were able to convince or trick customer service representatives to transfer a victim’s phone number to a SIM card they controlled. This resulted in the sudden loss of service for no apparent reason.

Once they have control over your phone number, they can receive verification codes, have your text message MFA codes, etc. Therefore, adding SIM swapping protection to your phone can help protect you from SIM swapping attacks. Fortunately, mobile phone carriers now offer this type of protection service in order to protect their users from forceful takeover.

7. Add a Fraud Alert

You also have the option to add a fraud alert to your credit reports. This will alert potential lenders or creditors that you may have been a victim of identity theft. This instructs them to verify the identity by contacting you before extending credit in your name. The FTC’s guide to credit freezes and fraud alerts covers the difference between the two, and if your identity has already been misused, IdentityTheft.gov will generate a personalised recovery plan.

T-Mobile Data Breach Summary: 2009 ~ 2026

Year Casualties Data Exposed Mode of Access
2009 No sensitive or damaging customer information was compromised. Confidential documents and programming information Insider threat
2015 About 15 million people Names, addresses, DOBs, SSNs, driver’s licenses, passport numbers Third-party breach at Experian
2017 Undisclosed Phone numbers and account details API vulnerability
2018 More than 2 million exposed data points Names, phone numbers, emails, and account numbers Direct network intrusion
2019 Over 1 million prepaid customer records Customer names, billing addresses, phone numbers, account numbers, rate plan details Unauthorised access to prepaid customer data
2021 Approximately 76 million SSNs, DOBs, driver’s licenses, account PINs Brute force via unprotected GPRS gateway
2023 Over 37 million customers Names, billing addresses, phone numbers, emails, DOBs, account numbers, plan details (no SSNs, government IDs, PINs or financial data) Vulnerable API endpoint
2026 1 individual Name, address, account details, account PIN, DOB, driver’s license number, SSN Insider access by a third-party vendor employee

Breaches on this scale are no longer unusual, and smaller platforms are hit just as often — the MyLovely.AI leak in March 2026 exposed only about 106,000 accounts but caused disproportionate harm because of the type of data involved. We track new incidents in our data breach and news archive.

Conclusion

T-Mobile has recorded several issues of data breaches since 2009. The major cyber scandal the organisation faced was the 2021 T-Mobile data breach that exposed approximately 76 million users’ sensitive data like SSNs, driver’s licenses, etc. The organisation faced multiple lawsuits afterwards that led to the T-Mobile data breach settlement of $350 million. While the organisation is committed to improving its cybersecurity, individuals should adopt personal safety measures like tracking sensitive data for potential exposure using reliable data breach trackers. If, unfortunately, some data is exposed, victims are recommended to update their passwords, place a credit freeze, and keep a close eye on their credit reports for any unauthorised activities.

Frequently Asked Questions (FAQs)

What should I do if I receive a breach notice?

If you receive a breach notification or suspect your information has been compromised, immediately identify the compromised data and document any unusual or unauthorised activities. Also, freeze your credit and change passwords. Then, contact a data breach lawyer to explore your legal options.

Who is eligible for the T-Mobile breach settlement?

The data breach settlement was issued to those whose information was exposed during the 2021 cyber attack. However, the presiding judge and court staff, T-Mobile’s officers and directors, and class counsel were excluded, as was anyone who opted out.

How many times has T-Mobile been hacked?

T-Mobile has disclosed at least nine significant data security incidents, with the major crisis being the 2021 breach affecting approximately 76 million people. The FCC’s 2024 consent decree alone covered four separate incidents between 2021 and 2023.

What is T-Mobile doing to prevent future breaches?

As part of the 2022 class action settlement, T-Mobile committed $150 million to data security improvements. Separately, its September 2024 FCC consent decree requires a $15.75 million cybersecurity investment alongside binding commitments to adopt zero trust architecture, deploy phishing-resistant multi-factor authentication, implement data minimisation and disposal processes, submit to independent third-party assessments, and have a CISO report directly to the board.

Can I still file a claim for the T-Mobile data breach settlement in 2026?

No, victims of the 2021 cyber attack can no longer file a claim for the $350 million class action settlement. The claim deadline was January 23, 2023. The initial distribution of payments finished on May 30, 2025, and the only remaining step is a residual distribution of leftover and uncashed funds to claimants who already filed.

Aartif

Written by Aartif

I'm Aartif, a Physics graduate, researcher, and passionate content writer with more than four years of experience. My journey as a writer started in 2022, and since then, I've worked on diverse projects across various niches, with particular interest in Science, Technology, Cybersecurity, Education, business, and Research and Career Guide. My role is to turn complex ideas into clear, engaging, and easy-to-understand content that connects with real people. Outside of my professional time, I love exploring the world, discovering new places, and going sightseeing.

0 0 votes
Article Rating
Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted