Skip to main content
  1. Home
  2. Phones
  3. Android
  4. Apple
  5. Mobile
  6. News

T-Mobile website bug reportedly exposed private customer account details

Add as a preferred source on Google
t-mobile
Image used with permission by copyright holder

Due to a bug in T-Mobile’s website back in April, customers’ account information was left accessible for anyone to see, ZDnet reports. While the security flaw has since been fixed, personal information could have potentially been misused by anyone who knew where to look.

The subdomain — promotool.t-mobile.com — is a customer care portal for employees to access internal tools. But the bug allowed for it to be easily found through search engines and didn’t require a password to access the tools.

Recommended Videos

The flaw was due to a hidden API — it provided T-Mobile customer data by adding the customer’s cell phone number to the end of the web address. This data included a customer’s billing account number, postal address, and account information, such as the status of their bills, including if service for an account was suspended or a bill is past due. For some, customer account PINs and tax ID numbers were also accessible.

The API was pulled by T-Mobile a day after it was reported by security researcher Ryan Stevenson, who was also awarded a $1,000 bug bounty later. While it’s not clear how long the API was exposed, a spokesperson for T-Mobile told ZDnet that there’s no evidence any customer information was accessed.

This is isn’t the first time an issue like this has happened to T-Mobile. In October, a security flaw allowed hackers to gain access to similar information through a T-Mobile website. Hackers were able to obtain email addresses, account numbers, and more, simply by using the customer’s phone number.

The flaw was discovered by security researcher Karan Saini, and it allowed hackers to gain information that could then be used in a social engineering attack, as well as provided access to other personal information online. T-Mobile claimed the bug only affected a small amount of customers and that it was fixed within 24 hours of being discovered.

News of the most recent flaw comes a little less than a month after the merger with T-Mobile and Sprint was announced — which was also in April. While both carriers agreed on combining companies, we have yet to see whether the U.S. Justice Department will approve it.

Brenda Stolyar
Former Staff Writer, Mobile
Brenda became obsessed with technology after receiving her first Dell computer from her grandpa in the second grade. While…
Instagram could soon let you watch Reels while offline with automatic downloads
A new leak suggests Instagram is working on automatic downloads for Reels, which could let you continue your binge even without an internet connection.
Instagram and YouTube

Instagram could soon let users continue their Reels binge even when they're offline. A new leak suggests the app is working on automatic downloads for short-form videos, a move that would bring it closer to YouTube, which already allows offline viewing of Shorts.

What is Instagram working on?

Read more
Android 17 will let apps get the best out of your phone’s camera chops
A new vendor-defined extension system could bring advanced camera features like Super Resolution to your favorite third-party apps.
Android 17 logo.

Android 17 is shaping up to be quite an important update, especially if you care about camera quality across apps. Google is introducing a new way for phone makers to extend their custom camera features system-wide, which could finally close the gap between stock camera apps and third-party ones.

How is Android changing camera access for apps?

Read more
Google is preparing a priority charging feature for phones for rush scenarios
A hidden Android 17 feature appears built for quick top-ups, while keeping calls and texts flowing.
Electronics, Mobile Phone, Phone

Google is working on a priority charging feature designed for moments when you need power quickly. The option, uncovered in Android 17 beta code by Android Authority, focuses on boosting usable battery in a short window without shutting down core phone functions.

Instead of pushing higher charging speeds, the system shifts power toward the battery by dialing back background activity. Calls and texts still come through, but less critical processes pause so more energy goes into charging.

Read more