---
title: "A Seller, a Broker and 100 Gigabytes: T-Mobile Investigates a Claimed Breach of 100 Million Customers"
description: "Hackers offering the data say it includes Social Security numbers, plaintext PINs and device identifiers going back to the mid-1990s"
author: "Walter Pine"
published: 2026-09-26T00:42:20.001Z
modified: 2026-09-26T11:45:22Z
url: https://rews.cc/a/a-seller-a-broker-and-100-gigabytes-t-mobile-investigates-a--a91483
language: en
tags: ["cybersecurity", "t-mobile", "data-breach", "hacking", "ssn", "tech"]
publisher: "Rews (https://rews.cc)"
---

# A Seller, a Broker and 100 Gigabytes: T-Mobile Investigates a Claimed Breach of 100 Million Customers

*Hackers offering the data say it includes Social Security numbers, plaintext PINs and device identifiers going back to the mid-1990s*

By Walter Pine · September 26, 2026 · https://rews.cc/a/a-seller-a-broker-and-100-gigabytes-t-mobile-investigates-a--a91483

## In brief

- Hackers are selling data they say covers 100 million T-Mobile USA customers, including SSNs, PINs and device identifiers
- T-Mobile confirmed unauthorized access to ‘some T-Mobile data’ but initially said it had not confirmed personal data was involved
- The self-described broker claimed the intruders entered via T-Mobile’s wireless network and pulled over 100 gigabytes from two data centers
- A hacker linked to the Mirai-derived Satori botnet, who says he is John Erin Binns, was identified as involved; the attackers cited retaliation
- T-Mobile later said the breach exposed names, birth dates, SSNs and driver’s license data of more than 40 million current, former and prospective customers

One hundred gigabytes. That, according to the people trying to sell it, is the size of the customer data taken from T-Mobile USA — a haul of databases said to hold names, Social Security numbers, dates of birth, addresses, phone numbers, plaintext security PINs and the unique identifiers burned into each customer’s mobile device, in records reaching back to the mid-1990s. T-Mobile says it is investigating the extent of the intrusion. It has not confirmed how much was taken, or from whom.

The story broke on a Sunday, when Vice.com reported that someone was selling data on 100 million people and that the data came from T-Mobile. The company, in a statement on its website, acknowledged an intrusion involving what it called “some T-Mobile data,” but said it was too early to know what was stolen or how many customers might be affected.

“We have determined that unauthorized access to some T-Mobile data occurred, however we have not yet determined that there is any personal customer data involved,” the company wrote. “We are confident that the entry point used to gain access has been closed, and we are continuing our deep technical review of the situation across our systems to identify the nature of any data that was illegally accessed.” Until its assessment was complete, T-Mobile said, it could not confirm the reported number of records or “the validity of statements made by others.” It declined to comment further.

## The broker and the data

The intrusion surfaced on Twitter, where an account called @und0xxed began posting the details. Reached by direct message, Und0xxed said they had not stolen the databases but was in charge of finding buyers for them. The account’s telling of the breach is specific. The hackers, Und0xxed said, found an opening in T-Mobile’s wireless data network that allowed access to two of the company’s customer data centers, and from there the intruders dumped customer databases totaling more than 100 gigabytes.

One of those databases, the sellers claim, holds the name, date of birth, Social Security number, driver’s license information, plaintext security PIN, address and phone number of 36 million T-Mobile customers in the United States. Another claim attaches to that: IMSI and IMEI data for the same 36 million customers. Those are the numbers embedded in a mobile device that identify the device itself and the SIM card tying it to a telephone number — the hardware-level identity of a phone, as distinct from the number it answers to.

> “If you want to verify that I have access to the data/the data is real, just give me a T-Mobile number and I’ll run a lookup for you and return the IMEI and IMSI of the phone currently attached to the number and any other details,”

So Und0xxed offered, adding: “All T-Mobile USA prepaid and postpaid customers are affected; Sprint and the other telecoms that T-Mobile owns are unaffected.”

The other databases allegedly accessed were thinner. Prepaid accounts, Und0xxed said, are “usually are just phone number and IMEI and IMSI.” Because the collection includes historical entries, many phone numbers carry 10 or 20 IMEIs accumulated over the years, with service dates attached. And there is, by this account, a database that includes credit card numbers with six digits of the cards obfuscated.

## A company already under pressure

None of this arrives at T-Mobile as a new species of problem. In 2015, a breach at Experian, one of the big three credit bureaus, exposed the Social Security numbers and other data of 15 million people who had applied for financing from T-Mobile. Like other mobile providers, the company is also in a running fight with scammers who target its own employees through SIM-swapping attacks and other techniques meant to seize control of employee accounts that open backdoor paths to customer data. In at least one case, retail store employees were complicit in the account takeovers.

## Who claims the hack

The Twitter profile of @und0xxed includes a shout-out to @IntelSecrets, the account of an elusive hacker who has also gone by IRDev and V0rtex. Asked whether IntelSecrets was involved in the T-Mobile intrusion, Und0xxed confirmed that it was. The IntelSecrets handles correspond to an individual who has claimed responsibility for modifying the source code of the Mirai “Internet of Things” botnet to produce a variant known as Satori, and for supplying it to others who used it for criminal gain and were later caught and prosecuted. Kenny “NexusZeta” Schuchmann pleaded guilty in 2019 to operating the Satori botnet; two other young men have been charged in connection with it. IntelSecrets was not among them.

What is known of IntelSecrets comes in part from an unusual quarter: a series of lawsuits filed by a person who claims their real name is John Erin Binns, the same identity that operates the website intelsecrets\[.\]su. On that site, Binns claims he fled to Germany and Turkey to evade prosecution in the Satori case, only to be kidnapped in Turkey and subjected to psychological and physical torture. According to Binns, the CIA falsely told the Turkish authorities that he was a supporter or member of the Islamic State, a claim he says led to his alleged capture and torture. He has since filed a flood of suits naming federal agencies — the FBI, the CIA and U.S. Special Operations Command among them — demanding information the government holds about him and seeking restitution for the alleged kidnapping.

Speaking to the researcher Alon Gal, the hackers responsible for the T-Mobile intrusion said they carried it out to “retaliate against the US for the kidnapping and torture of John Erin Binns in Germany by the CIA and Turkish intelligence agents in 2019. We did it to harm US infrastructure.”

The day after the sale became public, T-Mobile moved partway toward its accusers. More than 40 million current, former or prospective customers, the company acknowledged in a blog post Monday evening, had their names, dates of birth, Social Security numbers and driver’s license or ID information exposed. That is fewer than half of the 100 million the sellers advertise — but it is confirmation that the databases Und0xxed was brokering, 100 gigabytes of names and numbers going back a quarter-century, are real enough to count.
