Item 1A. Risk Factors
Item 1A. Risk Factors
Other than the updated risk factor below, there have been no material changes in our risk factors as previously disclosed in Part I, Item 1A of our Annual Report on Form 10-K for the year ended December 31, 2025.
We have experienced cyberattacks and may experience disruptions, data loss and other security breaches, whether directly or indirectly through third parties whose products and services we rely on in operating our business.
Our business involves the receipt, storage, and transmission of confidential information about our customers, such as sensitive personal, account, and payment information, confidential information about our employees and suppliers, and other sensitive information about our Company, such as our business plans, transactions, financial information, and intellectual property (collectively, “Confidential Information”). Additionally, to offer services to our customers and operate our business, we utilize several applications and systems, including those we own and operate, such as our wireless network, as well as others provided to us by third parties, such as cloud service providers and SaaS companies (collectively, “Systems”).
We are subject to persistent cyberattacks and threats to our business from bad actors seeking to gain unauthorized access to Confidential Information and to compromise Systems. They are perpetrated by a variety of groups and persons, including nation state-sponsored parties, malicious actors, employees, contractors, and other third parties. Some of these bad actors reside in jurisdictions where law enforcement measures to address such attacks are ineffective or unavailable.
Cyberattacks against companies like ours are increasing in frequency and scope of potential harm over time, and the methods used to gain unauthorized access constantly evolve, making it increasingly difficult to anticipate, prevent, and detect incidents successfully in every instance. In some cases, these bad actors exploit bugs, errors, misconfigurations or other vulnerabilities in our Systems to obtain Confidential Information. In other cases, these bad actors obtain unauthorized access to Confidential Information by exploiting insider access or utilizing login credentials taken from our customers, employees, or third-party providers through credential harvesting, social engineering or other means. Other bad actors aim to cause serious operational disruptions to our business and Systems through ransomware or distributed denial of service attacks. Moreover, the amount and scope of insurance that we maintain against losses resulting from any such incidents or security breaches may not be sufficient to cover our losses or otherwise adequately compensate us for any disruptions to our business that may result.
Although we regularly work to identify, track, and remedy security vulnerabilities, given the complex nature of our Systems and the tools that are available to us, we may be unable to identify vulnerabilities in a timely manner, or to apply patches or compensating measures that address such vulnerabilities, before bad actors can exploit them. The exploitation of a security vulnerability before patches or measures are applied could materially compromise Confidential Information and Systems.
In addition, we routinely rely upon third-party providers whose products and services are used in our business. These third-party providers have experienced, and will continue to experience, cyberattacks that involve attempts to access our Confidential Information and/or to create operational risk that could materially and adversely affect our business, and these providers also face other security challenges common to all parties that collect and process information. Additionally, our Systems include components from third parties or fourth parties we do not control and may have compromises, defects, flaws, or design errors unknown to us.
As a result of the previously disclosed cyberattacks in August 2021 and January 2023, we incurred significant costs in connection with, among other things, responding to and resolving mass arbitration claims, multiple class action lawsuits, and an FCC investigation. For more information on the foregoing, see “– Contingencies and Litigation – Litigation and Regulatory Matters” in Note 1 3 – Commitments and Contingencies of the Notes to the Condensed Consolidated Financial Statements.
In addition to the August 2021 cyberattack and the January 2023 cyberattack, we have experienced unrelated, non-material incidents involving unauthorized access to certain Confidential Information and Systems. Typically, these incidents have involved attempts to commit fraud by taking control of a customer’s phone line, often by exploiting insider access or using compromised credentials. In other cases, the incidents have involved unauthorized access to certain of our customers’ private information, including payment information, financial data, Social Security numbers or passwords, and our intellectual
52
Table of Contents
property. Some of these incidents have occurred at third-party providers, including third parties who provide us with various Systems and others who sell our products and services through retail locations or take care of our customers.
Our procedures and safeguards to prevent unauthorized access to Confidential Information and to defend against cyberattacks seeking to disrupt our operations must be continually evaluated and enhanced to address the ever-evolving threat landscape and changing cybersecurity regulations, including while we adapt complex digital efforts. These preventative actions require the investment of significant resources and management time and attention. Additionally, we do not have control of the cybersecurity systems, breach prevention, and response protocols of our third-party providers, including through our cybersecurity programs or policies. While T-Mobile may have contractual rights to assess the effectiveness of many of our providers’ systems and protocols, we do not have the means to always know or assess the effectiveness of all of our providers’ systems and controls. We cannot provide any assurances that actions taken by us, or our third-party providers, including through our cybersecurity programs or policies, will adequately repel a significant cyberattack or prevent or substantially mitigate the impacts of cybersecurity breaches or misuses of Confidential Information, unauthorized access to our networks or Systems or exploits against third-party environments, or that we, or our third-party providers, will be able to effectively identify, investigate, and remediate such incidents in a timely manner or at all. We expect to continue to be the target of cyberattacks, given the nature of our business, and we expect the same with respect to our third-party providers. We expect threat actors to continue to increase in sophistication, including through the use of increasingly advanced AI tools, which may accelerate the identification and exploitation of vulnerabilities, enable evasion of security controls, and reduce the time between discovery and attempted exploitation. Although AI may also enhance defensive capabilities, the pace at which vulnerabilities can be identified and weaponized may outstrip our ability, and that of our third-party providers, to test and deploy patches or other mitigating measures across complex systems. Efforts to accelerate remediation may also increase the risk of operational disruptions or system instability, and the continued development and integration of AI may introduce new and evolving cybersecurity risks. These dynamics may heighten our exposure to cybersecurity incidents and related adverse impacts on our business, reputation, financial condition, and operating results. In addition, we have acquired and continue to acquire companies with cybersecurity vulnerabilities or unsophisticated security measures, which expose us to significant cybersecurity, operational, and financial risks. If we fail to protect Confidential Information or to prevent operational disruptions from future cyberattacks, there may be a material adverse effect on our business, reputation, financial condition, cash flows, and operating results.
Text extracted from the filing as submitted to EDGAR. Formatting, tables and exhibits are simplified for reading; the original document is authoritative for anything you rely on.