Topics Tools Books & Guides Talk to Securafy

Knowledge Hub / IT Operations

IT Operations

Recent T-Mobile Data Breach Affects Google Fi Customers

Recent T-Mobile Data Breach Affects Google Fi Customers

Randy Hall By Randy Hall Updated Jul 2024 4 min read Share

Google Fi users have received emails regarding a recent data breach at T-Mobile. From November 2022 through January 2023, hackers were able to obtain unauthorized access to data for 37 million T-Mobile customers. Google Fi, a wireless plan, uses T-Mobile networks to provide wireless service to customers. Google Fi wireless plan users also had information stolen, a side effect of using T-Mobile’s 5G network.

What Information Was Leaked?

The hackers gained access to a limited amount of Google Fi customer data, including:

  • Phone numbers
  • SIM card serial numbers
  • Customer plan information
  • Serial number account status (active or inactive users)

While these details sound alarming, Google Fi had extra security measures around particular customer information to protect them from unauthorized eyes. The hackers were unable to access crucial customer data, including:

  • Name
  • Date of birth
  • Email address
  • PINs or passwords
  • Payment information
  • Financial account information
  • SMS messaging or phone call information
  • Government IDs (e.g., driver’s licenses)

How Did T-Mobile Handle the Data Breach?

T-Mobile reports that it has yet to discover the source of the data breach. In the meantime, T-Mobile has notified the U.S. Securities and Exchange Commission and law enforcement agencies. Besides letting T-Mobile customers know about the breach, T-Mobile has also informed other companies that utilize the T-Mobile wireless network.
Google sent an email to affected customers but has not yet named the number of compromised accounts.

What Does This Mean for Google Fi Users?

Google Fi users don’t need to do anything regarding this data breach. Wireless service will continue uninterrupted. Since hackers did not access the most private and personally identifiable information throughout the Google Fi data leak, customers can continue to use their wireless plans safely.

Google and T-Mobile announced they will place extra security measures to protect against future data leaks.

What Does This Mean for My Google Accounts?

According to Google’s email, the suspicious activity specifically targeted “a third-party system that contains a limited amount of Google Fi customer data.” Gmail, Google Drive, and other Google apps remained safe throughout the data breach, and the hackers did not break into any Google systems.

What Could Hackers Do with My Google Fi Information?
The data breach didn’t provide hackers with much private information, but they did take enough data to do some damage. If you were affected, hackers could use your phone number with your SIM card information, make and take phone calls, or use the number for two-factor authentication security measures.

Google Fi users should also use caution when accepting calls from unknown numbers, as scammers may have enough information to sound convincing. Scammers could use this information to talk you into paying a nonexistent bill.

Although a data breach sounds scary, the Google Fi data leak only provided hackers with specific phone or phone plan information. Your most important data, like passwords, PINs, and payment information, remains safe. Practice good judgment with unknown phone calls or emails, and you shouldn’t need to worry about your private information.

Join The Conversation

Have a question or perspective on this topic? Add it below.

Randy Hall

About The Author

Randy Hall · CEO & Founder

Randy Hall is the CEO and Founder of Securafy, with decades of experience helping organizations make smarter, safer decisions about technology.

A frequent speaker and instructor at national IT events, Randy has advised thousands of organizations, from startups and SMBs to large enterprises and U.S. government entities, on secure, practical technology adoption. He writes about the decisions business leaders are often expected to make without enough context, including cybersecurity, compliance, AI, cyber insurance, IT strategy, and business resilience.

Outside the office, you’ll often find Randy on Lake Erie enjoying time on his 38-foot Chris-Craft.

Writes about: Cybersecurity strategy, compliance, AI security, business resilience, cyber insurance, SMB risk, IT leadership

More From This Author →

Get Practical Cybersecurity Field Notes

Monthly cybersecurity, compliance, and IT strategy updates from Securafy, written for business owners who need clear next steps.

  • Practical security tips from our Cyber Security Drip series
  • The Securafy Times, our monthly roundup on compliance and IT strategy
  • Occasional updates on new tools, guides, and research
  • No spam — unsubscribe anytime