A King County Superior Court judge has determined that T-Mobile violated Washington state’s data breach notification law following a major T-Mobile data breach that exposed the sensitive personal information of 40 million individuals. The ruling, issued on Friday, found that the Bellevue-based telecommunications company failed to properly notify affected customers after their data was stolen and subsequently sold on the dark web.
The civil lawsuit was filed by the Washington attorney general’s office in January 2025, alleging that T-Mobile did not comply with state requirements for notifying customers whose personal information had been compromised in the security incident.
What Led to the Legal Action Against T-Mobile?
The lawsuit centered on T-Mobile’s handling of customer notifications following a significant data breach. According to the court proceedings, 40 million people had their sensitive personal information stolen by unauthorized parties. The compromised data was later discovered being sold on dark web marketplaces, indicating the severity of the security failure.
Washington state law requires companies to promptly notify individuals when their personal information has been breached. The attorney general’s office argued that T-Mobile’s notification practices fell short of these legal standards, prompting the legal challenge that has now resulted in a ruling against the company.
What Were the Court’s Findings?
The King County Superior Court judge sided with the Washington attorney general’s office, ruling that T-Mobile had indeed violated the state’s data breach notification law. The decision represents a significant legal setback for the telecommunications company, which operates its headquarters in Bellevue, Washington.
The court’s determination focused specifically on how T-Mobile communicated with affected customers following the discovery of the breach. The ruling suggests that the company’s notification procedures did not meet the legal requirements established under Washington state law to adequately inform customers about the compromise of their personal information.
What Are the Implications?
This ruling could have significant implications for how companies handle data breach notifications in Washington state. With 40 million individuals affected by this particular incident, the case highlights the importance of proper notification procedures when customer data is compromised and ends up in the hands of cybercriminals.
The decision serves as a reminder to organizations about their legal obligations to customers when security incidents occur, particularly regarding timely and adequate notification of data breaches.
Source: DataBreaches.net