Unprotected T-Mobile API Let Anyone Get Customer Data With Just a Phone Number - MacRumors
Skip to Content

Unprotected T-Mobile API Let Anyone Get Customer Data With Just a Phone Number

A security vulnerability in T-Mobile's website let anyone gain access to the personal details of any T-Mobile customer using just a phone number, reports ZDNet.

An internal T-Mobile employee tool, promotool.t-mobile.com, had a hidden API that provided T-Mobile customer data when a customer's cell phone number was added to the end of the web address. Data that was available included full name, address, billing account number, and for some customers, tax identification numbers.

tmobile logo
Account data, such as service status and billing status was also included, but it does not appear that credit card numbers, passwords, or other sensitive information was compromised. ZDNet says that there were "references to account PINs used by customers as a security question" which could be used to hijack T-Mobile accounts.

The API was used by T-Mobile staff to look up customer data, but it was accessible to the public and not protected by a password. T-Mobile rectified the issue in early April after it was disclosed by security researcher Ryan Stevenson, who ultimately earned $1,000.

In a statement provided to ZDNet, T-Mobile says that it does not appear customer data was accessed using the API, but research suggests the API had been exposed since at least October 2017.

A T-Mobile spokesperson said: "The bug bounty program exists so that researchers can alert us to vulnerabilities, which is what happened here, and we support this type of responsible and coordinated disclosure." "The bug was patched as soon as possible and we have no evidence that any customer information was accessed," the spokesperson added.

This is not the first unprotected API issue that T-Mobile has faced. Last year, a similar bug also exposed customer data to hackers.

T-Mobile has more than 74 million customers, and had this most recent bug been exploited, a simple script could have provided hackers with access to data on millions of people.

Popular Stories

T Mobile Generic Feature Pink 1

T-Mobile Automatically Moving Legacy Plan Customers to New Plans

Monday June 29, 2026 4:46 pm PDT by
Some T-Mobile customers with legacy phone plans are being upgraded to newer T-Mobile plans automatically, reports CNET. The company has been sending out notifications to customers with older plans, letting them know that they're going to be transferred to a current plan. Customers being pushed to a new plan could get an automatic bill increase. The carrier plans to move customers to...
iphone 17 cyber

Apple Closes Unlocked iPhone Loophole for T-Mobile and Verizon Financing

Wednesday July 15, 2026 3:20 pm PDT by
Carrier-financed iPhones purchased from Apple will soon be locked to the carrier, ending a workaround customers used to purchase an unlocked iPhone on a payment plan. Until the rule change, buying an iPhone from Apple and opting for financing through Verizon or T-Mobile meant you would get an iPhone not locked to either carrier's network. That's no longer the case, and now iPhones financed...
iPhone 18 Pro Deep Red Feature

iPhone 18 Pro Launching in Two Months With These 12 New Features

Friday July 24, 2026 7:26 pm PDT by
It is now late July, and that means the iPhone 18 Pro and iPhone 18 Pro Max are less than two months away. The devices are expected to look similar to the iPhone 17 Pro and iPhone 17 Pro Max, but there will still be many year-over-year changes, with rumored features including a smaller Dynamic Island, 5G via satellite, and more. Apple is expected to unveil the iPhone 18 Pro, iPhone 18 Pro...

Top Rated Comments

107 months ago
Pro tip from someone that works in Information Assurance, and has been involved in cleaning up several companies’ similar messes: anytime you see “we have no evidence that any customer information was accessed”, you can assume that they have zero logging. They ‘have no evidence’ because they have no logs; they aren’t saying it didn’t happen, it’s just a nice way to make it seem like nothing bad happened. Ask for evidence proving nothing bad happened, and you’ll be met with a horrified stare.
Score: 19 Votes (Like | Disagree)
107 months ago
Makes me think back to this conversation with TMobile on Twitter about the passwords being stored in plaintext (though it was TMO Austria).

https://twitter.com/tmobileat/status/981418339653300224

“Our security is amazingly good” LOL



Attachment Image
Score: 16 Votes (Like | Disagree)
Analog Kid Avatar
107 months ago
Until we start punishing these stupid mistakes with penalties that actually hurt, this is just going to happen over and over...
Score: 15 Votes (Like | Disagree)
PlainviewX Avatar
107 months ago
Only $1000 for a catastrophic possible breach discovery? That's like getting paid $45 in a contest that was used as the Mets logo.
Score: 9 Votes (Like | Disagree)
brinary001 Avatar
107 months ago
Damn. Glad I switched to AT&T recently
Score: 2 Votes (Like | Disagree)
Jaspio Avatar
107 months ago
Makes me think back to this conversation with TMobile on Twitter about the passwords being stored in plaintext (though it was TMO Austria).

https://twitter.com/tmobileat/status/981418339653300224

“Our security is amazingly good” LOL

LOL never let a glorified marketing drone talk technology. They can only embarrass their company and expose it to malpractice suits.
Score: 2 Votes (Like | Disagree)