CFIUS Fines T-Mobile $60 Million Over Unauthorized Data Access and Breach Response
Time 2 Minute Read

On August 14, 2024, the Committee on Foreign Investment in the United States (“CFIUS”) disclosed that it had assessed a $60 million penalty against T-Mobile US, Inc. (“T-Mobile”) in connection with unauthorized data access incidents following T-Mobile’s 2020 merger (the “Merger”) with Sprint Corporation (“Sprint”). CFIUS is a U.S. government interagency body with regulatory authority over certain investments by foreign persons in U.S. businesses that may pose risks to U.S. national security. Among the various regulatory clearances sought in connection with the Merger, T-Mobile and Sprint sought approval from CFIUS. CFIUS approved the Merger subject to a national security agreement (“NSA”) to be entered into by T-Mobile and the U.S. government. In recent years, approximately 30% of transactions cleared by CFIUS required some kind of national security agreement to bind the transaction parties to certain actions and undertakings designed to mitigate the perceived national security risks.

In announcing the penalty, CFIUS disclosed that “between August 2020 and June 2021, in violation of a material provision of the NSA, T-Mobile failed to take appropriate measures to prevent unauthorized access to certain sensitive data and failed to report some incidents of unauthorized access promptly to CFIUS, delaying [CFIUS’s] efforts to investigate and mitigate any potential harm. CFIUS concluded that these violations resulted in harm to the national security equities of the United States.”

The penalty assessed by CFIUS against T-Mobile was (by far) the largest of any of the penalty actions that have been disclosed by CFIUS to date and the only penalty action where the target of the action was identified by name. The U.S. Treasury Department also just announced that it has unveiled a new CFIUS enforcement website to provide greater transparency regarding its enforcement actions and penalties.

You May Also Be Interested In

Time 2 Minute Read

On March 5, 2026, the California Privacy Protection Agency announced that the agency had reached a settlement with Ford Motor Company resolving an enforcement action against the company that alleged noncompliance with the California Consumer Privacy Act’s opt-out of sale/sharing rights.

Time 1 Minute Read

On January 26, 2026, the Brazilian data protection authority (“ANPD”) announced that Brazil and the European Union agreed to mutually recognize the adequacy of each other’s data protection networks.

Time 2 Minute Read

On December 16, 2025, the Federal Trade Commission announced an enforcement action against Illusory Systems Inc., a Utah-based company doing business as Nomad, following a major data breach in which hackers stole $186 million from consumers.

Time 3 Minute Read

On November 4, 2025, the European Data Protection Board adopted its opinion on the European Commission’s draft decision regarding the adequacy of Brazil’s personal data protection framework. Once finalized, this decision will enable the free flow of personal data from the European Union to Brazil.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page