T-MOBILE US INC
TMUS
Communication Services
1
exclusion reason
1 theme
This page is part of our public exclusion list — a transparency tool that shows which companies we screen out and why. It is not investment advice, and it is not an accusation. But it is subject to change as our understanding of the facts evolves.
T-Mobile has a documented pattern of massive data breaches spanning 2021-2023, demonstrating systemic failures in data security governance. In August 2021, attackers stole records of 47.8 million customers including SSNs, driver's license numbers, and dates of birth, resulting in a $350 million class action settlement (approved June 2023) plus $150 million in mandatory security investments. In 2022, another breach via SIM-swapping and phishing compromised internal systems. In January 2023, a misconfigured API exposed personal data for 37 million current customers. The FCC settled in September 2024 for $31.5 million ($15.75M penalty + $15.75M security investment) covering all three breaches, finding the attacks were "varied in their nature, exploitations, and apparent methods of attack" — indicating not isolated incidents but recurring governance failures. Washington State AG filed a separate lawsuit over the 2021 breach. T-Mobile was required to adopt zero trust architecture and phishing-resistant MFA, confirming the company's prior security posture was materially deficient.
Research Sources
4 organizations
Related Exclusions
Wondering what we do invest in?
The Naughty List
A digest of changes to our exclusion list — new additions, removals, and the evidence behind them. We review the list continuously as new evidence surfaces.
Companies appear on our exclusion list based on our investment judgment — not because they've done anything illegal. This is a difference of values and opinion, not an accusation of wrongdoing. Exclusion does not constitute a recommendation against investing in any company, and absence from the list does not constitute a recommendation to invest.
This information is provided for educational and transparency purposes only and should not be relied upon as investment advice. Data is drawn from independent watchdogs, NGOs, government registries, and Ethical Capital's ongoing research — see Research Sources for the full list.
Ethical Capital LLC is a state-registered investment adviser in Utah (CRD #316032). Registration does not imply a certain level of skill or training.