Mint Mobile told customers a hacker obtained their account data
- Organization
- Mint Mobile
- Exploit
- Hacking
- Industry
- Telecommunications
Mint Mobile, the prepaid mobile virtual network operator that T-Mobile US agreed to buy in March 2023 in a deal that did not close until May 1, 2024, began emailing customers on December 22, 2023 to say an unauthorized party had obtained some of their account information.
The notice, sent under the subject line "Important information regarding your account," listed the exposed fields as customer names, phone numbers, email addresses, SIM serial numbers, IMEI device identifiers and service plan descriptions. Mint Mobile said credit card numbers and passwords were not involved, and that it does not collect dates of birth or government-issued identifiers such as Social Security or driver's licence numbers.
Security researchers noted that a phone number paired with a SIM serial and IMEI is the material needed for SIM swapping, in which an attacker moves a victim's number onto a device they control and then intercepts the one-time codes used for account recovery and two-factor authentication.
The company told customers the incident had been resolved and that no action was required on their part, and it opened a dedicated phone line to handle questions. Mint Mobile did not publish how many accounts were affected and did not describe how the intrusion happened. It was the carrier's second disclosed incident, following a July 2021 breach that involved account information and number porting.