When T-Mobile got hacked in 2021, the breach made headlines — 79 million people's data exposed, one of the largest telecom breaches in history. But the lawsuit that just produced a ruling wasn't about the hack itself. It was about what happened next.

In July, a judge ruled that T-Mobile violated Washington State's data breach notification law. Not because the breach happened. Because of how T-Mobile told people about it.

The details are instructive. According to the court, T-Mobile's notifications to affected customers were brief text messages that omitted information the law requires. In some cases, the messages understated how bad the breach was. And customers whose Social Security numbers were specifically exposed — the most sensitive data in the entire incident — weren't told that their information was included.

The Breach Isn't the Only Liability

Here's what makes this case important for every business owner: the legal obligation doesn't end when you discover the breach. In many ways, it begins.

Every state has its own data breach notification law. They differ on the details — how quickly you have to notify people, what information the notice has to include, who you have to notify besides your customers, and even what method of delivery is acceptable. Some states require notification within 30 days. Others give you 45 or 60. Some require you to notify the state attorney general's office above a certain threshold of affected residents. Colorado's law requires notification "in the most expedient time possible and without unreasonable delay."

What T-Mobile's case demonstrates is that doing the bare minimum — sending a vague text message that doesn't say what was actually taken — can be worse than sending nothing at all. A notification that omits required information, minimizes the impact, or fails to reach the right people isn't just a PR problem. It's a legal violation that can trigger separate enforcement action, separate penalties, and separate lawsuits on top of whatever the breach itself already costs.

What a Real Plan Looks Like

A breach response plan isn't complicated, but it needs to exist before you need it. At minimum, it should answer:

  • Who's in charge? One person who leads the response. Not a committee that has to schedule a meeting.
  • What do you say? Template notification language that includes what the law requires — what happened, what data was involved, what you're doing about it, and what affected people should do.
  • Who do you tell? Customers, yes. But also your attorney, your cyber insurance carrier, and potentially state regulators. Different states, different thresholds.
  • How fast? Know the deadlines for the states where your customers live before you're racing the clock.

The Real Cost of Winging It

T-Mobile had a $500 million class action settlement for the breach itself. The Washington State case is separate — it's about the notification failure alone. That's the lesson: a company with deep pockets and a legal team still got it wrong, and the notification became its own liability.

If you don't have a written breach response plan, you're not ready. Not because you expect to be breached — but because the cost of being unprepared isn't just the breach. It's everything that comes after.

Have a conversation with someone who understands breach response requirements across the states where you operate. Not a sales pitch — just an honest look at whether your plan would hold up if a judge came knocking.