T-Mobile violated WA data breach notification law, judge rules
A King County Superior Court judge ruled that T-Mobile violated Washington state's data breach notification law after a breach exposed sensitive personal information belonging to 40 million people, data that was subsequently sold on the dark web. Washington's attorney general brought the civil lawsuit against the company in January 2025.
Why this matters: Forty million people had their data stolen and sold, and T-Mobile did not tell them properly. That is the core of this case. Breach notification laws exist for one reason: people deserve to know when their information is compromised so they can act. When a company delays or skips that step, it is not a paperwork issue. It is people left exposed while the clock runs on identity theft and fraud. A court finding a major carrier liable for that failure matters. It says the notification requirement is real, not optional.
Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · General readers · Policy
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.