{
  "type": "bundle",
  "id": "bundle--0662094e-c3cc-5f8d-822f-bda6e431a92d",
  "objects": [
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--8a1fd826-8994-513d-8744-39629658a3da",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "org:31f0a471-c4bc-5a5e-a3fd-668565b494f4",
      "name": "T-Mobile",
      "identity_class": "organization"
    },
    {
      "type": "incident",
      "spec_version": "2.1",
      "id": "incident--3b228575-0921-595d-88e5-42bbabd3c303",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "brh:882d4b7e-3175-5f28-bf72-9f9d84e11afb",
      "name": "T-Mobile security incident"
    },
    {
      "type": "incident",
      "spec_version": "2.1",
      "id": "incident--9a3a3992-aeed-54ee-82fa-82387a3b9a1c",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "inc:9f6bc3ab-9b9f-5b96-8226-8ddab3e58cc5",
      "name": "T-Mobile security incident"
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--8052fa9c-6bb5-5e8a-88b1-2b9d5914a069",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "clm:c678379b-376e-53f2-a386-785a4e690dc1",
      "relationship_type": "affected-organization",
      "source_ref": "incident--9a3a3992-aeed-54ee-82fa-82387a3b9a1c",
      "target_ref": "identity--8a1fd826-8994-513d-8744-39629658a3da",
      "confidence": 100,
      "external_references": [
        {
          "source_name": "U.S. Securities and Exchange Commission",
          "url": "https://www.sec.gov/Archives/edgar/data/1283699/000119312523010949/d641142d8k.htm",
          "external_id": "cit:5eb25de9-36b7-5099-8fac-eb32d22f16eb",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:154317cdf95ec9a796f23f432e9ea8d7429e9170d4a587dbc5aea016cdbc10b3"
        }
      ]
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--645ba741-fa0f-55c6-891b-43e630a8dc6f",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "clm:dbc42976-ee3f-5107-a1df-c69149a9f850",
      "confidence": 100,
      "external_references": [
        {
          "source_name": "U.S. Securities and Exchange Commission",
          "url": "https://www.sec.gov/Archives/edgar/data/1283699/000119312523010949/d641142d8k.htm",
          "external_id": "cit:0e47818c-305e-5c0b-bd5f-4c25f13fd8f4",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:154317cdf95ec9a796f23f432e9ea8d7429e9170d4a587dbc5aea016cdbc10b3"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "The reviewed source documents the t-mobile security incident involving T-Mobile."
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--85db475f-8ae6-5b14-8082-e93a3da9f71d",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "clm:33a40d66-c4a3-507f-b7c4-0daed2546e68",
      "confidence": 88,
      "external_references": [
        {
          "source_name": "U.S. Securities and Exchange Commission",
          "url": "https://www.sec.gov/Archives/edgar/data/1283699/000119312523010949/d641142d8k.htm",
          "external_id": "cit:a0d70e57-2d90-577c-b26b-4f9e5cee37be",
          "description": "The preliminary result from our investigation indicates that the bad actor(s) obtained data from this API for approximately 37 million current postpaid and prepaid customer accounts, though many of these accounts did not include the full data set.",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:154317cdf95ec9a796f23f432e9ea8d7429e9170d4a587dbc5aea016cdbc10b3"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "37M customer accounts' basic data exposed."
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--b15b141c-ad16-50c1-802c-e410c672a208",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "clm:6d72a2b7-8f5c-52d8-b8f3-d66c2eba1f45",
      "confidence": 90,
      "external_references": [
        {
          "source_name": "U.S. Securities and Exchange Commission",
          "url": "https://www.sec.gov/Archives/edgar/data/1283699/000119312523010949/d641142d8k.htm",
          "external_id": "cit:cfd1b177-d8c6-5c12-90e1-176a2ca6b9d1",
          "description": "In addition, we have notified certain federal agencies about the incident, and we are concurrently working with law enforcement.",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:154317cdf95ec9a796f23f432e9ea8d7429e9170d4a587dbc5aea016cdbc10b3"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "The retained source reports coordination with law enforcement as part of the incident response."
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--b66483a9-48dd-5746-88c4-fefd8c02fb86",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "clm:56dcec5b-bd40-5bad-a777-05adc4330471",
      "confidence": 90,
      "external_references": [
        {
          "source_name": "U.S. Securities and Exchange Commission",
          "url": "https://www.sec.gov/Archives/edgar/data/1283699/000119312523010949/d641142d8k.htm",
          "external_id": "cit:23a75e1a-d71e-5590-bca0-ca7fa0e04ebc",
          "description": "Our investigation is still ongoing, but the malicious activity appears to be fully contained at this time, and there is currently no evidence that the bad actor was able to breach or compromise our systems or our network.",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:154317cdf95ec9a796f23f432e9ea8d7429e9170d4a587dbc5aea016cdbc10b3"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "The retained source describes containment action intended to limit further access or disruption."
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--d7579f03-7032-5724-87b3-cec7d357d49e",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "clm:3352eb8a-1aac-5104-8842-48825f292e0f",
      "confidence": 88,
      "external_references": [
        {
          "source_name": "U.S. Securities and Exchange Commission",
          "url": "https://www.sec.gov/Archives/edgar/data/1283699/000119312523010949/d641142d8k.htm",
          "external_id": "cit:547f2b76-4801-5d85-9e87-59105165402e",
          "description": "The API abused by the bad actor does not provide access to any customer payment card information (PCI), social security numbers/tax IDs, driver’s license or other government ID numbers, passwords/PINs or other financial account information, so none of this information was exposed.",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:154317cdf95ec9a796f23f432e9ea8d7429e9170d4a587dbc5aea016cdbc10b3"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "API abuse requiring no login."
      }
    }
  ]
}
