Item 1A. Risk Factors
Item 1A. Risk Factors
Other than the updated risk factor below, there have been no material changes in our risk factors as previously disclosed in Part I, Item 1A of our Annual Report on Form 10-K for the year ended December 31, 2021.
We have experienced criminal cyberattacks and could in the future be further harmed by disruption, data loss or other security breaches, whether directly or indirectly through third parties.
Our business involves the receipt, storage, and transmission of confidential information about our customers, such as sensitive personal, account and payment card information, confidential information about our employees and suppliers, and other sensitive information about our Company, such as our business plans, transactions, financial information, and intellectual property (collectively, “Confidential Information”). We are subject to persistent cyberattacks and threats to our networks, systems, and supply chain from a variety of bad actors, many of whom attempt to gain access to and compromise Confidential Information by exploiting bugs, errors, misconfigurations or other vulnerabilities in our networks and other systems (including purchased and third-party systems) or engaging in credential harvesting or social engineering. In some cases, these bad actors may obtain unauthorized access to Confidential Information utilizing credentials taken from our customers, employees, or third parties. Other bad actors aim to cause serious operational disruptions to our business or networks through other means, such as through ransomware or distributed denial of services attacks.
Cyberattacks against companies like ours have increased in frequency and potential harm over time, and the methods used to gain unauthorized access constantly evolve, making it increasingly difficult to anticipate, prevent, and/or detect incidents successfully in every instance. They are perpetrated by a variety of groups and persons, including state-sponsored parties, malicious actors, employees, contractors, or other unrelated third parties. Some of these persons reside in jurisdictions where law enforcement measures to address such attacks are ineffective or unavailable, and such attacks may even be perpetrated by or at the behest of foreign governments.
In addition, we routinely provide certain Confidential Information to third-party providers whose products and services are used in our business operations, including as part of our IT systems, such as cloud services. These third-party providers have experienced in the past, and will continue to experience in the future, cyberattacks that involve attempts to obtain unauthorized access to our Confidential Information and/or to create operational disruptions that could adversely affect our business, and these providers also face other security challenges common to all parties that collect and process information.
In August 2021, we disclosed that our systems were subject to a criminal cyberattack that compromised certain data of millions of our current customers, former customers, and prospective customers, including, in some instances, social security numbers, names, addresses, dates of birth and driver’s license/identification numbers. With the assistance of outside cybersecurity experts, we located and closed the unauthorized access to our systems and identified current, former, and prospective customers whose information was impacted and notified them, consistent with state and federal requirements. We have incurred certain cyberattack-related expenses, including costs to remediate the attack, provide additional customer support and enhance customer protection, and expect to incur additional expense in future periods resulting from the attack. For more information, see “Cyberattack” in the Overview section of MD&A. As a result of the August 2021 cyberattack, we are subject to numerous claims, lawsuits and regulatory inquiries, the ongoing costs of which may be material, and we may be subject to further regulatory inquiries and private litigation. For more information, see “– Contingencies and Litigation – Litigation and Regulatory Matters” in Note 11 – Commitments and Contingencies of the Notes to the Consolidated Financial Statements.” As a result of the August 2021 cyberattack, we may incur significant costs or experience other material financial impacts, which
42
Table of Contents
may not be covered by, or may exceed the coverage limits of, our cyber insurance, and such costs and impacts may have a material adverse effect on our business, reputation, financial condition, cash flows and operating results.
In addition to the August 2021 cyberattack, we have experienced other unrelated immaterial incidents involving unauthorized access to certain Confidential Information. Typically, these incidents have involved attempts to commit fraud by taking control of a customer’s phone line, often by using compromised credentials. In other cases, the incidents have involved unauthorized access to certain of our customers’ private information, including credit card information, financial data, social security numbers or passwords, and to certain of our intellectual property.
Our procedures and safeguards to prevent unauthorized access to Confidential Information and to defend against cyberattacks seeking to disrupt our operations must be continually evaluated and enhanced to address the ever-evolving threat landscape and changing cybersecurity regulations. These preventative actions require the investment of significant resources and management time and attention. Additionally, we do not have control of the cybersecurity systems, breach prevention, and response protocols of our third-party providers. While T-Mobile may have contractual rights to assess the effectiveness of many of our providers’ systems and protocols, we do not have the means to know or assess the effectiveness of all of our providers’ systems and controls at all times. We cannot provide any assurances that actions taken by us, or our third-party providers will adequately repel a significant cyberattack or prevent or substantially mitigate the impacts of cybersecurity breaches or misuses of Confidential Information, unauthorized access to our networks or systems or exploits against third-party environments, or that we or our third-party providers, will be able to effectively identify, investigate, and remediate such incidents in a timely manner or at all. We expect to continue to be the target of cyberattacks, given the nature of our business, and we expect the same with respect to our third-party providers. Our inability to protect Confidential Information or to prevent operational disruptions from future cyberattacks may have a material adverse effect on our business, reputation, financial condition, cash flows, and operating results.
Item 2. Unregistered Sales of Equity Securities and Use of Proceeds
None.
Item 3. Defaults Upon Senior Securities
None.
Item 4. Mine Safety Disclosures
Not applicable.