As cited
Copy frozen at (site build).
breaches incidents
T-Mobile violated WA data breach notification law, judge rules
A King County Superior Court judge ruled that T-Mobile violated Washington state data breach notification law by failing to properly notify customers of a 2024 breach affecting 40 million people whose sensitive personal information was stolen and sold on the dark web. The Washington attorney general's office filed the civil lawsuit against T-Mobile in January 2025. The ruling establishes that T-Mobile's notification practices did not meet the state's legal requirements.
Why it matters: Practitioners at telecommunications and large-scale data custodian organizations need to review their breach notification procedures against Washington state law and similar state requirements, as courts are now enforcing strict compliance standards with potential liability for inadequate customer notification.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
breaches incidents
T-Mobile violated WA data breach notification law, judge rules
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
breaches incidents
T-Mobile violated WA data breach notification law, judge rules
A King County Superior Court judge ruled that T‑Mobile violated Washington state data‑breach notification law by failing to properly inform customers after a breach exposed the personal data of approximately 40 million individuals, which was later offered for sale on the dark web. The Washington Attorney General’s office had filed a civil lawsuit against the Bellevue‑based carrier in January 2025, alleging delayed and inadequate breach notifications. The court’s decision upholds the state’s requirement that affected individuals receive timely notice of compromised information.
Why it matters: T‑Mobile customers, particularly those in Washington, are affected because their personal data may remain exposed on illicit markets and they should monitor accounts for fraud and consider placing a credit freeze or fraud alert.
- Source published
- First seen by Cybersecurity Tracker