Data breach
Experian
- Records
- 110,191,498
- Breach date
- 16 September 2015Estimated
- Added
- 1 December 2024
What was exposed
32 types of data · 4 more reported
- Home addresses110,191,491
- Phone numbers110,191,248
- Names110,188,857
- Home multifamily108,543,183
- Employment104,225,254
- Ethnic country103,078,028
- Ethnic groups103,059,441
- Religion102,839,191
- Salaries102,187,899
- Net worth99,021,530
- Credit score96,950,779
- Home adults94,393,257
- Home generations88,944,946
- Home owner87,321,375
- Credit user84,424,052
- Children at home75,152,412
- Property type72,321,336
- Credit lines62,177,307
- Education history60,585,759
- Qualifications60,585,759
- Industries56,922,267
- Year built56,286,416
- Children46,949,886
- Credit ratings37,428,104
- Job titles26,991,802
- Home ac26,071,611
- Home fuel15,915,488
- Ethnic assimilation15,164,538
- Home sewer14,021,202
- Home water13,760,757
- Home veteran7,108,701
- Home pool6,314,247
- Social security numbersReported, not counted
- Driving licence numbersReported, not counted
- Passport numbersReported, not counted
- Dates of birthReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
Experian, one of the three major US credit bureaus, was hit by a data breach discovered on September 15, 2015, in which an attacker gained unauthorized access to a server holding personal information on consumers who had applied for T-Mobile services and device financing. According to a multi-state Attorneys General assurance, the incident affected roughly 15 million people. Separately, our investigation team has indexed a much larger dataset attributed to Experian, dated September 16, 2015, containing about 110 million records with extensive demographic and financial details. No hacking group has claimed that dataset, and its exact source remains inconclusive; some individuals have confirmed portions of their own data in it, but its origin has not been independently verified.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
September 15, 2015: Experian discovered unauthorized access to a server storing data on T-Mobile credit applicants, according to a settlement assurance filed with state Attorneys General.
October 1, 2015: Experian and T-Mobile publicly announced the breach, which affected applicants who required credit checks between September 1, 2013 and September 16, 2015.
What Information Was Compromised?
Our analysis found the following data types in this breach: name (about 110.2 million records), home address and phone number (about 110.2 million each), religion (about 102.8 million), job and job salary (about 102.2 million and 104.2 million respectively), net worth (about 99 million), credit score (about 96.9 million), ethnic group and ethnic country fields (about 103 million each), education level (about 60.6 million), number of children (about 46.9 million), and a wide range of household attributes such as home ownership, home type, year built, number of adults and children in the home, home value indicators, pool ownership, heating fuel, water and sewer type, and veteran status.
Experian's notice and T-Mobile's public letter also listed names, addresses, birth dates, and encrypted fields containing Social Security numbers and government ID numbers such as driver's license or passport numbers, and stated that the encryption may have been compromised.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The confirmed exposure of Social Security numbers and government ID numbers carries a serious risk of identity theft, since criminals can use that data to open accounts, file fraudulent tax returns, or impersonate victims. The demographic and financial fields add a second risk: detailed profiles covering religion, salary, net worth, credit standing, and family composition are well suited to convincing targeted phishing and social engineering, because scammers can reference plausible personal details to appear legitimate. Because this dataset surfaced without a verified source and has never been fully accounted for, it is difficult to know where copies may exist or who holds them today.
In the news
- Massachusetts Attorney General, Experian 2015 Data Breach Assurance of Discontinuancemass.gov (opens in a new tab)
- T-Mobile Newsroom, A Letter from CEO John Legere on Experian Data Breacht-mobile.com (opens in a new tab)
- CNBC, Experian reports data breach involving info for more than 15M T-Mobile customerscnbc.com (opens in a new tab)
- Tennessee Attorney General, Consumer Tips following Experian Data Breachtn.gov (opens in a new tab)
