Connect with us

State News

Attorney General Miyares announces $15 million multistate settlements over 2015 Experian data breach

Published

on

Richmond, VA – Attorney General Jason Miyares announced today that Virginia will receive a total of $346,085.82 from two multistate settlements with Experian Information Solutions, Inc. (“Experian”) and T-Mobile USA, Inc. (“T-Mobile”) concerning a 2015 data breach. Experian’s breach compromised the personal information of more than 15 million individuals and 340,004 Virginians who submitted credit applications with cellular phone service provider T-Mobile. Under the settlements, the companies have agreed to improve their data security practices and to pay the states a combined amount of more than $15 million.

“The 2015 data breach affected hundreds of thousands of Virginians, putting their personal information at risk. Companies like T-Mobile and Experian have a responsibility to ensure the safety of consumers’ information, and when they fail, they have to be held accountable,” said Attorney General Miyares.

In September 2015, Experian, one of the big-three credit reporting bureaus, reported it had experienced a data breach in which an unauthorized actor gained access to part of Experian’s network storing personal information on behalf of its client, T-Mobile. The breach involved information associated with consumers who had applied for T-Mobile postpaid services and device financing between September 2013 and September 2015, including names, addresses, dates of birth, Social Security numbers, identification numbers (such as driver’s license and passport numbers), and related information used in T-Mobile’s own credit assessments. Neither Experian’s consumer credit database nor T-Mobile’s own systems were compromised in the breach.

The multistate coalition obtained separate settlements from Experian and T-Mobile in connection with the 2015 data breach. Under a $12.67 million settlement, Experian has agreed to strengthen its due diligence and data security practices going forward. Those include:

  • Prohibition against misrepresentations to its clients regarding the extent to which Experian protects the privacy and security of personal information;
  • Implementation of a comprehensive Information Security Program incorporating zero-trust principles, regular executive-level reporting, and enhanced employee training;
  • Due diligence provisions requiring the company to properly vet acquisitions and evaluate data security concerns prior to integration;
  • Data minimization and disposal requirements, including specific efforts aimed at reducing the use of Social Security numbers as identifiers; and
  • Specific security requirements include encryption, segmentation, patch management, intrusion detection, firewalls, access controls, logging and monitoring, penetration testing, and risk assessments.

The settlement also requires Experian to offer five years of free credit monitoring services to affected consumers and two free copies of their credit reports annually during that timeframe. This is in addition to the four years of credit monitoring services already offered to affected consumers— two of which were offered by Experian in the wake of the breach and two that were secured through a separate 2019 class action settlement. The deadlines to enroll in these prior offerings have since passed.

If you were a class member in the 2019 class action settlement, you are eligible to enroll in these extended credit monitoring services. Affected consumers can enroll in the five-year extended credit monitoring services and find more information on eligibility here or at www.tmobileapplicant2015eisdatabreachsettlement.com. The enrollment window will remain open for six months.

In a separate $2.43 million settlement, T-Mobile has agreed to detailed vendor management provisions designed to strengthen its vendor oversight going forward. Those include:

  • Implementation of a Vendor Risk Management Program;
  • Maintenance of a T-Mobile vendor contract inventory, including vendor criticality ratings based on the nature and type of information that the vendor receives or maintains;
  • Imposition of contractual data security requirements on T-Mobile’s vendors and sub-vendors, including related to segmentation, passwords, encryption keys, and patching;
  • Establishment of vendor assessment and monitoring mechanisms; and
  • Appropriate action in response to vendor non-compliance, up to contract termination.

The settlement with T-Mobile does not concern the unrelated, massive data breach announced by T-Mobile in August 2021, which is still under investigation by a multistate coalition of Attorneys General.

Attorney General Miyares’ Computer Crime Section and Consumer Protection Section handled this matter on behalf of Virginia.

Front Royal, VA
52°
Mostly Cloudy
6:16 am8:03 pm EDT
Feels like: 52°F
Wind: 1mph NNE
Humidity: 100%
Pressure: 29.93"Hg
UV index: 0
ThuFriSat
64°F / 43°F
64°F / 45°F
59°F / 41°F
Community Events5 hours ago

Samuels Public Library Adult Programming Events for May

Local News5 hours ago

Blue Ridge Wildlife Center Patient of the Week: Red Fox

report logo
Arrest Logs6 hours ago

POLICE: 7 Day FRPD Arrest Report 4/27/2026

Regional News9 hours ago

US Supreme Court Hears Arguments on Cancer Warning Labels for Roundup Weedkiller

Regional News9 hours ago

US Senate Spending Panel Hails Education Programs Trump Has Targeted for Cuts

Regional News9 hours ago

Ex-FBI Director James Comey, Targeted by Trump, Indicted for ’86 47′ Seashell Photo

Obituaries10 hours ago

Helen Virginia Smoot (1939 – 2026)

Local News17 hours ago

Front Royal Prepares to Welcome King and Queen During U.S. Visit

State News18 hours ago

Fairfax Tragedy Renews Debate on How Best to Intervene in Domestic Crises

State News19 hours ago

Spanberger Marks First 100 Days with Focus on Healthcare, Housing and Energy Affordability

Mature Living19 hours ago

Building Muscle After 50 Is a Win-Win

Local News20 hours ago

Rare, World-Class Masterworks from Picasso to Dalí Meet Contemporary Artists in Front Royal at Ichiuji Fine Arts Gallery

Business20 hours ago

Why Change Is So Hard — and How to Make It Stick

Home20 hours ago

Which Home Repairs Should Come First?

Legal Notices1 day ago

ORDER OF PUBLICATION: In the Circuit Court for Warren County, Virginia

State News1 day ago

Supreme Court of Virginia Weighs Challenge to Redistricting Amendment

Community Events1 day ago

South Warren Ruritan Club Prepares for Popular Spring Hanging Basket Sale

Obituaries1 day ago

Gerald W. “Jerry” Chilcote (1957 – 2026)

Obituaries2 days ago

Eleanor Showers Chadwell (1939 – 2026)

State News2 days ago

Virginia Cannabis Retail Plan in Limbo After Lawmakers Reject Spanberger Changes

State News2 days ago

Data Center Tax Exemption Changes Still Holding Up Virginia Budget

Health2 days ago

Colorectal Cancer Now Leading Cancer Killer Among Younger Adults

Interesting Things to Know2 days ago

Saying “Sorry” May Be a Key to Success, Survey Finds

Local News2 days ago

Warren County Fire and Rescue Launches “10-A-Day” Campaign to Improve Home Safety

Community Events2 days ago

Dance Club Shenandoah Celebrates 60 Years of Music and Movement