T-Mobile allegedly tried to buy leaked data from a hacker forum for $200k
The stolen information was still up for sale long after payment, court papers suggest


Telecoms giant T-Mobile tried to pay hackers to limit the spread of stolen data, according to unsealed court documents.
However, the move backfired as the assailants went on to leak the information more widely, Vice reports.
T-Mobile confirmed that it had been breached last year, with hackers threatening to sell the personal data of 30 million customers for six bitcoin - said to be worth around $270,000 at the time. However, on Tuesday, an indictment unsealed by the Department of Justice revealed that the tech giant had employed a third-party firm that paid the hackers $200,000 for exclusive access to the stolen data so that it could prevent any further leaks.
The indictment was against Diofo Santos Coelho, who is alleged to have administrated the popular hacking site 'RaidForums'. He was arrested in the UK in March and extradited to the US to stand trial over a particular set of data found on RaidForums. In August 2021, an individual using the moniker "SubVirt" had posted an offer to sell data stolen from an organisation simply listed as "Company 3". Another post on the site confirms that the data belongs to a "major telecommunications company" that operates in the US.
The document goes on to say that the unnamed company "hired a third-party" to act as a buyer and purchase exclusive access to the databases to prevent them from being sold to "criminals". An employee of the third party is said to have used RaidForums' 'middleman service', which is operated by the administrator, to buy a sample of the data for $50,000 worth of bitcoin. It is claimed that the same employee then purchased the entire database for around $150,000, with a request that SubVirt would then delete their copy. However, it appears that the hackers continued to try and sell the database after the third-parties purchase, according to the court documents.
This is one of several reasons victim companies are discouraged from paying ransom demands to hackers. Third parties are often brought in to investigate breaches and advise on the best courses of action. Some may offer controversial services, such as revenge hacking, but it is generally held that paying ransom demands doesn't work.
In the UK, around 82% of businesses infected with ransomware ended up paying in 2021, according to research from Proofpoint.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Bobby Hellard is ITPro's Reviews Editor and has worked on CloudPro and ChannelPro since 2018. In his time at ITPro, Bobby has covered stories for all the major technology companies, such as Apple, Microsoft, Amazon and Facebook, and regularly attends industry-leading events such as AWS Re:Invent and Google Cloud Next.
Bobby mainly covers hardware reviews, but you will also recognize him as the face of many of our video reviews of laptops and smartphones.
-
BreachForums founder resentenced to three years in prison
News A US appeals court vacated his previous sentence and remanded the case for resentencing
-
Redefining the channel: Evolving partner models are unlocking innovation, value, and recurring revenue
Industry Insights Channel partners are evolving into consultants, driving AI innovation and recurring revenue growth
-
Prolific ransomware operator added to Europe’s Most Wanted list as US dangles $10 million reward
News The US Department of Justice is offering a reward of up to $10 million for information leading to the arrest of Volodymyr Viktorovych Tymoshchuk, an alleged ransomware criminal.
-
Jaguar Land Rover “did the right thing” shutting down systems to thwart cyber attack
News The attack on Jaguar Land Rover highlights the growing attractiveness of the automotive sector
-
Ransomware attack on IT supplier disrupts hundreds of Swedish municipalities
News The attack on IT systems supplier Miljödata has impacted public sector services across the country
-
A notorious hacker group is ramping up cloud-based ransomware attacks
News The Storm-0501 threat group is refining its tactics, according to Microsoft, shifting away from traditional endpoint-based attacks and toward cloud-based ransomware.
-
Security researchers have just identified what could be the first ‘AI-powered’ ransomware strain – and it uses OpenAI’s gpt-oss-20b model
News Using OpenAI's gpt-oss:20b model, ‘PromptLock’ generates malicious Lua scripts via the Ollama API.
-
Data I/O shuts down systems in wake of ransomware attack
News Regulatory filings by Data I/O suggest the costs of dealing with the attack could be significant
-
Average ransom payment doubles in a single quarter
News Targeted social engineering and data exfiltration have become the biggest tactics as three major ransomware groups dominate
-
BlackSuit ransomware gang taken down in latest law enforcement sting – but members have already formed a new group
News The notorious gang has seen its servers taken down and bitcoin seized, but may have morphed into a new group called Chaos