Experian says 15M have info stolen in hack of T-Mobile data

FILE - In this Sept. 12, 2012 file photo, a man uses a cellphone as he passes a T-Mobile store in New York. Credit reporting agency Experian on Thursday, Oct. 1, 2015 said that hackers accessed the social security numbers, birthdates and other personal information belonging to about 15 million T-Mobile wireless customers. T-Mobile uses Experian to check the credit of its customers. (AP Photo/Mark Lennihan, File)
FILE - In this Sept. 12, 2012 file photo, a man uses a cellphone as he passes a T-Mobile store in New York. Credit reporting agency Experian on Thursday, Oct. 1, 2015 said that hackers accessed the social security numbers, birthdates and other personal information belonging to about 15 million T-Mobile wireless customers. T-Mobile uses Experian to check the credit of its customers. (AP Photo/Mark Lennihan, File)

NEW YORK (AP) – Hackers have stolen personal information belonging to about 15 million T-Mobile wireless customers and potential customers in the U.S., including Social Security numbers, home addresses, birthdates and other personal information.

In the latest high-profile breach, the hackers got the information from credit reporting agency Experian, which T-Mobile uses to check the credit of consumers applying for phone plans and financing for devices. Experian said T-Mobile customers who applied between Sept. 1, 2013 and Sept. 16, 2015 may have had their information stolen.

Experian said it immediately notified law enforcement authorities after discovering the hack and that “there is no evidence to date that the data has been used inappropriately.”

T-Mobile customers can sign up for two free years of credit monitoring services at http://www.protectmyID.com/securityincident , a service owned by Experian.

That arrangement prompted sarcastic responses on Twitter. T-Mobile CEO John Legere, who is active on Twitter, responded to many tweeters unhappy with the resolution offered.

“I hear you re: Experian as service protection option. I am moving as fast as possible to get an alternate option in place by tomorrow,” Legere wrote Thursday evening.

Earlier in a statement, Legere had said that he was “incredibly angry” about the breach and that the company would review its relationship with Experian.

“Customers will be cynical” about using credit monitoring from Experian, said Gartner security analyst Avivah Litan. “Why would you trust someone with your accounts that’s been breached.”

Still, she said that customers can still use the service. But as an alternative, they could check their credit reports for free at http://www.annualcreditreport.com. The site lets consumers check each of their credit reports from the three credit rating agencies-  Equifax, Experian and TransUnion – once a year.

The hack happened on Experian’s server and is still being investigated, said Annie Garrigan, a spokeswoman for Bellevue, Washington-based T-Mobile.

Experian said in a statement on its website that it doesn’t know who was behind the hack and that it is taking “necessary steps” to prevent further breaches.

The company said that affected customers should “remain vigilant” against identity theft and watch for phishing email scams that ask for sensitive information such as bank account and Social Security numbers.

The companies said that payment card and banking information was not affected, but consumers shouldn’t downplay the theft of Social Security numbers, said Eva Velasquez, the CEO of the nonprofit Identity Theft Resource Center.

“There are many more steps you have to take to minimize your risk when your Social Security number is compromised versus payment card data,” she said.

Payment cards can be canceled, ending the harm. But thieves can use someone’s Social Security number to open new financial accounts and take out new loans for big-ticket items like cars and they can file a false tax return in your name.

Velasquez said that affected consumers should review their credit reports and sign up for a credit monitoring service and think about putting fraud alerts on their credit reports. They should also file tax returns as soon as they can, to beat a potential thief.

There have been a string of high-profile hacks of businesses and other organizations in recent years affecting millions of people, including adultery website Ashley Madison, Sony Pictures, the insurer Anthem, retailers such as Home Depot and Target, eBay and the U.S. Office of Personnel Management.

Nearly 800 data breaches were reported last year by U.S. organizations, according to the Identity Theft Resource Center.

T-Mobile is now the No. 3 wireless carrier in the U.S., having surpassed Sprint this year. The company refers to itself as an “Un-carrier” because it changed some of the wireless industry’s practices, like replacing the two-year service contract with monthly installment plans. Verizon and AT&T are the country’s largest wireless carriers.

(Copyright 2015 The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.)

WKBN 27 First News provides commenting to allow for constructive discussion on the stories we cover. In order to comment here, you acknowledge you have read and agreed to our Terms of Service. Commenters who violate these terms, including use of vulgar language or racial slurs, will be banned. No links will be permitted. Please be respectful of the opinions of others. If you see an inappropriate comment, please flag it for our moderators to review.

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s