−Removed: Other than the updated risk factors below, there have been no material changes in our risk factors as previously disclosed in Part I, Item 1A of our Annual Report on Form 10-K for the year ended December 31, 2022.
−Removed: Risks Related to Our Business
−Removed: We have experienced criminal cyberattacks and could in the future be further harmed by disruption, data loss or other security breaches, whether directly or indirectly through third parties whose products and services we rely on in operating our business.
−Removed: Our business involves the receipt, storage, and transmission of confidential information about our customers, such as sensitive personal, account and payment card information, confidential information about our employees and suppliers, and other sensitive information about our Company, such as our business plans, transactions, financial information, and intellectual property (collectively, “Confidential Information”).
−Removed: Additionally, to offer services to our customers and operate our business, we utilize a number of products and services, such as IT networks and systems, including those we own and operate as well as others provided by third-party providers, such as cloud services (collectively, “Systems”).
−Removed: We are subject to persistent cyberattacks and threats to our business from a variety of bad actors, many of whom attempt to gain unauthorized access to and compromise Confidential Information and Systems.
−Removed: In some cases, the bad actors exploit bugs, errors, misconfigurations or other vulnerabilities in our Systems to obtain Confidential Information.
−Removed: In other cases, these bad actors may obtain unauthorized access to Confidential Information utilizing credentials taken from our customers, employees, or third-party providers through credential harvesting, social engineering or other means.
−Removed: Other bad actors aim to cause serious operational disruptions to our business and Systems through ransomware or distributed denial of services attacks.
−Removed: Cyberattacks against companies like ours have increased in frequency and potential harm over time, and the methods used to gain unauthorized access constantly evolve, making it increasingly difficult to anticipate, prevent, and/or detect incidents successfully in every instance.
−Removed: They are perpetrated by a variety of groups and persons, including state-sponsored parties, malicious actors, employees, contractors, or other unrelated third parties.
−Removed: Some of these persons reside in jurisdictions where law enforcement measures to address such attacks are ineffective or unavailable, and such attacks may even be perpetrated by or at the behest of foreign governments.
−Removed: In addition, we routinely rely upon third-party providers whose products and services are used in our business.
−Removed: These third-party providers have experienced in the past, and will continue to experience in the future, cyberattacks that involve attempts to obtain unauthorized access to our Confidential Information and/or to create operational disruptions that could adversely affect our business, and these providers also face other security challenges common to all parties that collect and process information.
−Removed: In August 2021, we disclosed that our systems were subject to a criminal cyberattack that compromised certain data of millions of our current customers, former customers, and prospective customers, including, in some instances, social security numbers,
−Removed: names, addresses, dates of birth and driver’s license/identification numbers.
−Removed: With the assistance of outside cybersecurity experts, we located and closed the unauthorized access to our systems and identified current, former, and prospective customers whose information was impacted and notified them, consistent with state and federal requirements.
−Removed: We have incurred certain cyberattack-related expenses, including costs to remediate the attack, provide additional customer support and enhance customer protection, and expect to incur additional expense in future periods resulting from the attack.
−Removed: For more information, see “Recent Cyberattacks” in the Overview section of our Management’s Discussion and Analysis of Financial Condition and Results of Operations.
−Removed: As a result of the August 2021 cyberattack, we are subject to numerous claims, lawsuits and regulatory inquiries, the ongoing costs of which may be material, and we may be subject to further regulatory inquiries and private litigation.
−Removed: For more information, see “– Contingencies and Litigation – Litigation and Regulatory Matters” in Note 13 – Commitments and Contingencies of the Notes to the Consolidated Financial Statements.
−Removed: In January 2023, we disclosed that a bad actor was obtaining data through a single Application Programming Interface (“API”) without authorization.
−Removed: Based on our investigation, the impacted API is only able to provide a limited set of customer account data, including name, billing address, email, phone number, date of birth, T-Mobile account number and information such as the number of lines on the account and plan features.
−Removed: The result from our investigation indicates that the bad actor(s) obtained data from this API for approximately 37 million current postpaid and prepaid customer accounts, though many of these accounts did not include the full data set.
−Removed: We believe that the bad actor first retrieved data through the impacted API starting on or around November 25, 2022.
−Removed: We have notified individuals whose information was impacted consistent with state and federal requirements.
−Removed: As a result of the August 2021 cyberattack and the January 2023 cyberattack, we have incurred and may continue to incur significant costs or experience other material financial impacts, which may not be covered by, or may exceed the coverage limits of, our cyber liability insurance, and such costs and impacts may have a material adverse effect on our business, reputation, financial condition, cash flows and operating results.
−Removed: In addition to the recent cyberattacks, we have experienced other unrelated immaterial incidents involving unauthorized access to certain Confidential Information.
−Removed: Typically, these incidents have involved attempts to commit fraud by taking control of a customer’s phone line, often by using compromised credentials.
−Removed: In other cases, the incidents have involved unauthorized access to certain of our customers’ private information, including credit card information, financial data, social security numbers or passwords, and to certain of our intellectual property.
−Removed: Some of these incidents have occurred at third-party providers, including third parties who provide us with various Systems and others who sell our products and services through retail locations or take care of our customers.
−Removed: Our procedures and safeguards to prevent unauthorized access to Confidential Information and to defend against cyberattacks seeking to disrupt our operations must be continually evaluated and enhanced to address the ever-evolving threat landscape and changing cybersecurity regulations.
−Removed: These preventative actions require the investment of significant resources and management time and attention.
−Removed: Additionally, we do not have control of the cybersecurity systems, breach prevention, and response protocols of our third-party providers.
−Removed: While T-Mobile may have contractual rights to assess the effectiveness of many of our providers’ systems and protocols, we do not have the means to know or assess the effectiveness of all of our providers’ systems and controls at all times.
−Removed: We cannot provide any assurances that actions taken by us, or our third-party providers, will adequately repel a significant cyberattack or prevent or substantially mitigate the impacts of cybersecurity breaches or misuses of Confidential Information, unauthorized access to our networks or systems or exploits against third-party environments, or that we, or our third-party providers, will be able to effectively identify, investigate, and remediate such incidents in a timely manner or at all.
−Removed: We expect to continue to be the target of cyberattacks, given the nature of our business, and we expect the same with respect to our third-party providers.
−Removed: We also expect that threat actors will continue to gain sophistication including in the use of tools and techniques (such as artificial intelligence) that are specifically designed to circumvent security controls, evade detection, and obfuscate forensic evidence, making it more challenging for us to identify, investigate and recover from future cyberattacks in a timely and effective manner.
−Removed: If we fail to protect Confidential Information or to prevent operational disruptions from future cyberattacks, there may be a material adverse effect on our business, reputation, financial condition, cash flows, and operating results.
+Added: Other than the updated risk factor below, there have been no material changes in our risk factors as previously disclosed in Part I, Item 1A of our Annual Report on Form 10-K for the year ended December 31, 2023.
Our business may be adversely impacted if we are not able to successfully manage the ongoing arrangements entered into in connection with the Prepaid Transaction and known or unknown liabilities arising in connection therewith.
1 unchanged sentence
Pursuant to the MNSA, DISH will receive network services from the Company for a period of seven years.
−Removed: As set forth in the MNSA, the Company provides DISH, among other things, (a) legacy network services for certain Boost Mobile prepaid end users on the Sprint network, (b) T-Mobile network services for certain end users that have been migrated to the T-
−Removed: Mobile network or provisioned on the T-Mobile network by or on behalf of DISH and (c) infrastructure mobile network operator services to assist in the access and integration of the DISH network.
−Removed: Pursuant to the DISH License Purchase Agreement, DISH has agreed to purchase all of Sprint’s 800 MHz spectrum (approximately 13.5 MHz of nationwide spectrum) for a total of approximately $3.6 billion.
−Removed: Pursuant to an amendment to the DISH License Purchase Agreement (the “LPS Amendment”) executed by us and DISH and approved by the Court along with a proposed amendment to the Final Judgment on October 23, 2023, if DISH fails to purchase such spectrum on or prior to April 1, 2024, then DISH’s sole liability will be that we can retain a non-refundable extension fee of approximately $100 million.
−Removed: In such instance, T-Mobile may be required to conduct an auction sale of all of Sprint’s 800 MHz spectrum under the terms set forth in the Final Judgment, but would not be required to divest such spectrum for an amount less than $3.6 billion.
−Removed: Failure to successfully manage these ongoing arrangements entered into in connection with the Prepaid Transaction and liabilities arising in connection therewith may result in material unanticipated problems, including diversion of management time and energy, significant expenses and liabilities.
−Removed: There may also be other potential adverse consequences and unforeseen increased expenses or liabilities associated with the Prepaid Transaction, the occurrence of which could materially impact our business, financial condition, liquidity and operating results.
−Removed: In addition, there may be an increase in competition from DISH and other third parties that DISH may enter into commercial agreements with, who are significantly larger and with greater resources and scale advantages as compared to us.
+Added: As set forth in the MNSA, the Company provides DISH, among other things, (a) legacy network services for certain Boost Mobile prepaid end users on the Sprint network, (b) T-Mobile network services for certain end users that have been migrated to the T-Mobile network or provisioned on the T-Mobile network by or on behalf of DISH and (c) infrastructure mobile network operator services to assist in the access and integration of the DISH network.
+Added: Pursuant to the DISH License Purchase Agreement, DISH agreed to purchase all of Sprint’s 800 MHz spectrum (approximately 13.5 MHz of nationwide spectrum) for a total of $3.6 billion.
+Added: The DISH License Purchase Agreement terminated in accordance with its terms when DISH failed to purchase such spectrum on or prior to April 1, 2024, allowing the Company to retain a non-refundable extension fee of $100 million paid by DISH.
+Added: T-Mobile has commenced an auction sale of all of Sprint’s 800 MHz spectrum under the terms set forth in the Final Judgment, but is not required to divest such spectrum for an amount less than $3.6 billion.
+Added: Failure to successfully manage the MNSA and the spectrum auction may result in material unanticipated problems, including diversion of management time and energy, significant expenses and liabilities.
+Added: In addition, if the 800 MHz spectrum is sold at auction, there may be an increase in competition from the purchaser or purchasers of such spectrum and other third parties that such purchaser or purchasers may enter into commercial agreements with, who may be significantly larger and have greater resources and scale advantages as compared to us.
Such increased competition may result in our loss of customers and other business relationships.
−Removed: Risks Related to Legal and Regulatory Matters
−Removed: Unfavorable outcomes of legal proceedings may adversely affect our business, reputation, financial condition, cash flows and operating results.
−Removed: We and our affiliates are involved in various disputes, governmental and/or regulatory inspections, investigations and proceedings, mass arbitrations and litigation matters.
−Removed: Such legal proceedings can be complex, costly, and highly disruptive to our business operations by diverting the attention and energy of management and other key personnel.
−Removed: In connection with the Transactions, we became subject to a number of legal proceedings, including a putative shareholder class action and derivative lawsuit and a putative antitrust class action.
−Removed: For more information, see “– Contingencies and Litigation – Litigation and Regulatory Matters” in Note 13 – Commitments and Contingencies of the Notes to the Consolidated Financial Statements.
−Removed: It is possible that stockholders of T-Mobile and/or Sprint may file additional putative class action lawsuits or shareholder derivative actions against the Company and the legacy T-Mobile board of directors and/or the legacy Sprint board of directors.
−Removed: Among other remedies, these stockholders could seek damages.
−Removed: The outcome of any litigation is uncertain, and any such potential lawsuits could result in substantial costs and may be costly and distracting to management.
−Removed: Additionally, on April 1, 2020, in connection with the closing of the Merger, we assumed the contingencies and litigation matters of Sprint.
−Removed: Those matters include a wide variety of disputes, claims, government agency investigations and enforcement actions and other proceedings.
−Removed: Unfavorable resolution of these matters could require us to make additional reimbursements and pay additional fines and penalties.
−Removed: On February 28, 2020, we received a Notice of Apparent Liability for Forfeiture and Admonishment from the FCC, which proposed a penalty against us for allegedly violating Section 222 of the Communications Act and the FCC’s regulations governing the privacy of customer information.
−Removed: We recorded an accrual for an estimated payment amount as of March 31, 2020, which is included in Accounts payable and accrued liabilities on our Consolidated Balance Sheets.
−Removed: As a result of the August 2021 cyberattack, we are subject to numerous lawsuits, including consolidated class action lawsuits seeking unspecified monetary damages, mass consumer arbitrations, a shareholder derivative lawsuit and inquiries by various government agencies, law enforcement and other governmental authorities, and we may be subject to further regulatory inquiries and private litigation.
−Removed: We are cooperating fully with regulators and vigorously defending against the class actions and other lawsuits.
−Removed: On July 22, 2022, we entered into an agreement to settle the consolidated class action lawsuit.
−Removed: On June 29, 2023, the Court issued an order granting final approval of the settlement, which is subject to potential appeals.
−Removed: Under the terms of the settlement, we would pay an aggregate of $350 million to fund claims submitted by class members, the legal fees of plaintiffs’ counsel and the costs of administering the settlement.
−Removed: We would also commit to an aggregate incremental spend of $150 million for data security and related technology in 2022 and 2023.
−Removed: We previously paid $35 million for claims administration purposes.
−Removed: On July 31, 2023, a class member filed an appeal to the final approval order challenging the Court’s award of attorneys’ fees to class counsel.
−Removed: We expect the remaining portion of the $350 million settlement payment to fund claims to be made once that appeal is resolved.
−Removed: In connection with the class action settlement and other settlements of separate consumer claims that have been previously completed or are currently pending , we recorded a total pre-tax charge of approximately $400 million during
−Removed: the three months ended June 30, 2022.
−Removed: In light of the inherent uncertainties involved in such matters and based on the information currently available to us, we believe it is reasonably possible that we could incur additional losses associated with these proceedings and inquiries, and we will continue to evaluate information as it becomes known and will record an estimate for losses at the time or times when it is both probable that a loss has been incurred and the amount of the loss is reasonably estimable.
−Removed: In addition, in connection with the January 2023 cyberattack, we have received notices of consumer class actions and regulatory inquires, to which we will continue to respond in due course.
−Removed: Ongoing legal and other costs related to these proceedings and inquiries, as well as any potential future proceedings and inquiries related to the August 2021 cyberattack and the January 2023 cyberattack, may be substantial, and losses associated with any adverse judgments, settlements, penalties or other resolutions of such proceedings and inquiries could be significant and have a material adverse impact on our business, reputation, financial condition, cash flows and operating results.
−Removed: We, along with equipment manufacturers and other carriers, are subject to current and potential future lawsuits alleging adverse health effects arising from the use of wireless handsets or from wireless transmission equipment such as cell towers.
−Removed: In addition, the FCC has from time to time gathered data regarding wireless device emissions, and its assessment of the risks associated with using wireless devices may evolve based on its findings.
−Removed: Any of these allegations or changes in risk assessments could result in customers purchasing fewer devices and wireless services, could result in significant legal and regulatory liability, and could have a material adverse effect on our business, reputation, financial condition, cash flows and operating results.
−Removed: The assessment of the outcome of legal proceedings, including our potential liability, if any, is a highly subjective process that requires judgments about future events that are not within our control.
−Removed: The amounts ultimately received or paid upon settlement or pursuant to final judgment, order or decree may differ materially from amounts accrued in our financial statements.
−Removed: In addition, litigation or similar proceedings could impose restraints on our current or future manner of doing business.
−Removed: Such potential outcomes including judgments, awards, settlements or orders could have a material adverse effect on our business, reputation, financial condition, cash flows and operating results.
−Removed: Risks Related to Ownership of Our Common Stock
−Removed: We cannot guarantee that our 2023-2024 Stockholder Return Program will be fully utilized, and our share repurchases and dividend payments pursuant thereto may fail to have the desired impact on stockholder value.
−Removed: Our Board of Directors has authorized the 2023-2024 Stockholder Return Program for up to $19.0 billion that will run through December 31, 2024.
−Removed: The 2023-2024 Stockholder Return Program is expected to consist of additional repurchases of shares of our common stock and payment of cash dividends.
−Removed: The existence of the 2023-2024 Stockholder Return Program could cause our stock price, in certain cases, to be higher or lower than it otherwise would be and could potentially reduce the market liquidity or have other unintended consequences for our stock.
−Removed: In addition to the approximately $750 million dividend we declared on September 25, 2023, which is payable on December 15, 2023 to stockholders of record as of the close of business on December 1, 2023, we intend to declare and pay approximately $3.0 billion in total additional dividends in 2024, with payments occurring each quarter during the year.
−Removed: The dividend amount paid per share is expected to grow by around 10% annually, however, the declaration and payment of future dividends is subject to the discretion of our Board of Directors and will depend on financial and legal requirements and other considerations.
−Removed: The amount available under the 2023-2024 Stockholder Return Program for share repurchases will be reduced by the amount of any cash dividends declared by the Company.
−Removed: Under the 2023-2024 Stockholder Return Program, share repurchases can be made from time to time using a variety of methods, which may include open market purchases, Rule 10b5-1 plans, accelerated share repurchases, privately negotiated transactions or otherwise, all in accordance with the rules of the Securities and Exchange Commission and other applicable legal requirements.
−Removed: The specific timing and amount of any share repurchases, and the specific timing and amount of any dividend payments, under the 2023-2024 Stockholder Return Program will depend on prevailing share prices, general economic and market conditions, Company performance and other considerations.
−Removed: In addition, the specific timing and amount of any dividend payments are subject to declaration on future dates by the Board in its sole discretion.
−Removed: The 2023-2024 Stockholder Return Program does not obligate the Company to acquire any particular amount of common stock or to declare and pay any particular amount of dividends, and the 2023-2024 Stockholder Return Program may be suspended or discontinued at any time at the Company’s discretion.
−Removed: In addition, the threshold price that would trigger the issuance of additional shares of T-Mobile common stock to SoftBank under the Letter Agreement is subject to downward adjustment by the per share amount of any cash dividends or other cash distributions declared or paid on the Company’s common stock during the measurement period set forth in the Letter Agreement.
−Removed: As a result, any declaration of cash dividends could potentially result in the issuance of shares of T-Mobile
−Removed: common stock to SoftBank under the Letter Agreement based on the lower threshold price that would not otherwise occur without the cash dividends, which would cause the interests of our stockholders to be diluted.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.