Early access: the directory is still filling out, and every rating here is a reported experience.
NR Unrated
T-Mobile
T-Mobile Bugcrowd $0–$133,700
3 more reviews needed for a grade
Write a review Claim this company profile

Work at T-Mobile? Claim it to respond to reviews as the verified owner.

Found a vulnerability?

If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.

Ask BugRater to submit it

Private. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.

Reviews

0 published

No reviews yet.

Be the first to review

Program profile Bugcrowd · imported

Facts published by Bugcrowd on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 19 Sep 2026.

Program Purpose T-Mobile USA, Inc. ("T-Mobile") is committed to protecting our customers, our employees, our partners, and our brand. As part of this commitment, T-Mobile works with the security community to keep our customers and business safe. If you have identified a high-impact, reproducible security vulnerability in a T-Mobile property, application, or system, we encourage you to report it. We are especially interested in vulnerabilities that could materially affect: T-Mobile customers, employees, and owned brands or acquired businesses; customer accounts, billing, identity, authentication, and line-management systems; cellular, MSISDN, SIM/eSIM, DIGITS, messaging, location, and carrier-trust workflows; T-Mobile internal, cloud, administrative, and business operations. We evaluate reported vulnerabilities and promptly take appropriate action. Scope Boundary In this policy, T-Mobile means T-Mobile USA, Inc. and its affiliates. This program is limited to T-Mobile-owned or T-Mobile-controlled assets explicitly listed as in scope. T-Mobile does not own — and cannot remediate findings on — non-T-Mobile assets, including Deutsche Telekom assets and third-party vendors. Deutsche Telekom domains, applications, systems, networks, services, subsidiaries, infrastructure, employee accounts, customer data, and corporate environments are out of scope and not eligible for bounty — even where the asset references T-Mobile, shares branding, links to T-Mobile properties, or appears related to T-Mobile business operations. Any domain, property, product, protocol, or service not explicitly listed in scope is out of scope. Submissions against unlisted assets are welcome but not guaranteed a bounty. Eligibility The following are not eligible to participate. T-Mobile determines eligibility in its sole discretion, evaluated at submission and at payment. residents of countries or regions under applicable U.S. sanctions or export restrictions; persons on the U.S. Treasury SDN List or another applicable restricted-party list; current or former employees, contractors, consultants, interns, or vendor staff of T-Mobile or any T-Mobile affiliate, regardless of when the relationship ended; current or former employees of SoftBank Group Corp. or any of its affiliates; immediate family or household members of any person in the preceding two bullets; any person bound by a current or former NDA, confidentiality, or similar agreement with T-Mobile or any T-Mobile affiliate covering T-Mobile systems, security, source code, operations, or customer/employee data; any person who has had, at any time, non-public access to T-Mobile systems, source code, vulnerabilities, security testing, internal tools, credentials, or customer/employee data; any Bugcrowd staff member with access to the T-Mobile program, and their immediate family or household members; any person who learned of, identified, or developed the finding while in any role, agreement, or access above, regardless of current status; any other person prohibited by applicable law, regulation, contract, or program rule. T-Mobile affiliate means any parent, subsidiary, predecessor, successor, acquired entity, branded MVNO, joint venture, or otherwise controlled entity of T-Mobile USA, Inc. Immediate family means spouse, domestic partner, parent, child, sibling, and step/half/in-law equivalents. Household member means anyone sharing the researcher’s residence. Submitting on behalf of an ineligible person through a proxy, agent, alt account, or third party voids the submission. Researchers must promptly disclose any fact that could affect eligibility, and T-Mobile may require identity, employment, or tax documentation as a condition of triage or payment. Ineligible submissions are void. T-Mobile may withhold unpaid rewards and, where permitted, recover amounts already paid, close associated submissions, ban the researcher, and refer the matter to Bugcrowd, law enforcement, or regulators. Program Terms Participation in T-Mobile’s Bug Bounty Program is voluntary and subject to the terms and conditions of this policy. By submitting a vulnerability report to T-Mobile, researchers acknowledge that they have read and agree to comply with this policy. T-Mobile may modify this policy at any time. Continued participation in the program after a modification constitutes acceptance of the modified policy. Submission of a security report does not create a consumer, employment, contractor, partnership, or agency relationship between the researcher and T-Mobile. All communications regarding vulnerability findings, submissions, appeals, questions, or T-Mobile Bug Bounty Program policies must be conducted through the Bugcrowd platform. Researchers must not use any alternative channel unless expressly authorized in writing by T-Mobile or Bugcrowd. Prohibited channels include but are not limited to: direct contact with T-Mobile employees or executives by any means; social-media messages or posts directed at T-Mobile personnel; T-Mobile customer, enterprise, support, sales, PR, HR, or legal channels; physical visits to T-Mobile locations; any T-Mobile contact, regardless of how it was obtained. Intent (e.g., “just a heads-up”) does not create an exception. Failure to comply may result in removal from the program, reduced or forfeited bounty payments, ineligibility for future participation, and/or other punitive actions. T-Mobile may use the contents of submitted reports for any purpose related to validation, remediation, legal obligations, regulatory obligations, contractual obligations, security operations, or protection of T-Mobile, its customers, employees, partners, products, services, or systems. Information provided to T-Mobile will be handled according to T-Mobile’s Privacy Policy. Researchers must adhere to the Bugcrowd Community Code of Conduct and Bugcrowd Terms and Conditions. If this policy conflicts with Bugcrowd disclosure guidance or platform rules, this policy controls for the

Currency
USD
Submissions
Open
Scope entries
86 Bugcrowd’s count

Scope

87 assets
AssetTypeEligibilityMax severity
*.api.t-mobile.com api ✓ bounty not set
*.assurancewireless.com website ✓ bounty not set
*.metrobyt-mobile.com website ✓ bounty not set
*.sprint.com website ✓ bounty not set
*.t-mobile.com website ✓ bounty not set
Show all 87 assets
AssetTypeEligibilityMax severity
*.uscc.com website ✓ bounty not set
*.uscc.net website ✓ bounty not set
*.uscellular.com website ✓ bounty not set
account.business.t-mobile.com website ✓ bounty not set
account.t-mobile.com website ✓ bounty not set
api.vistarmedia.com website ✓ bounty not set
api.vistarmedia.eu website ✓ bounty not set
assets-cdn.vistarmedia.com website ✓ bounty not set
assets.development.amazon-tacticalplanner.com website ✓ bounty not set
assets.platform.blis.com website ✓ bounty not set
assets.platform.development.blis.com website ✓ bounty not set
assets.platform.rc.blis.com website ✓ bounty not set
assurancewireless.com website ✓ bounty not set
audience-builder.vistarmedia.com website ✓ bounty not set
audiencelogos.blis.com website ✓ bounty not set
blis.com website ✓ bounty not set
Cellular Network Auth Bypass via Web App/T-Life (404-200-7239) network ✓ bounty not set
clients.adstruc.com website ✓ bounty not set
creative.infinity.blismedia.com website ✓ bounty not set
creatives.vistarmedia.com website ✓ bounty not set
dashboard-101.moengage.com website ✓ bounty not set
demo.adstruc.com website ✓ bounty not set
devedge.t-mobile.com website ✓ bounty not set
development.wmaudience.com website ✓ bounty not set
DIGITS - Web, Desktop, Mobile website ✓ bounty not set
docker-staging.adstruc.com website ✓ bounty not set
docsite.vistarmedia.com website ✓ bounty not set
imply-pivot.blis.com website ✓ bounty not set
imply-pivot.test.blis.com website ✓ bounty not set
imply.blis.com website ✓ bounty not set
imply.internal.platform.blis.com website ✓ bounty not set
imply.platform.blis.com website ✓ bounty not set
imply.platform.development.blis.com website ✓ bounty not set
imply.platform.rc.blis.com website ✓ bounty not set
imply.test.blis.com website ✓ bounty not set
imply.wmaudience.com website ✓ bounty not set
internal.platform.blis.com website ✓ bounty not set
jenkins-github.gcp.blis.com website ✓ bounty not set
job-svc-b.vistarmedia.com website ✓ bounty not set
maps.vistarmedia.com website ✓ bounty not set
metrobyt-mobile.com website ✓ bounty not set
packages.cortexpowered.com website ✓ bounty not set
platform.blis.com website ✓ bounty not set
platform.blismedia.com website ✓ bounty not set
platform.development.blis.com website ✓ bounty not set
platform.development2.blis.com website ✓ bounty not set
platform.rc.blis.com website ✓ bounty not set
privacy.blismedia.com website ✓ bounty not set
production-delivery-metrics-svc.vistarmedia.com website ✓ bounty not set
production-dynam-creative.vistarmedia.com website ✓ bounty not set
rc.wmaudience.com website ✓ bounty not set
Self-Register Account on T-Mobile Microsoft Entra ID other ✓ bounty not set
sfleet.cortexpowered.com website ✓ bounty not set
sflower.cortexpowered.com website ✓ bounty not set
signature.blis.com website ✓ bounty not set
sitepixel.blis.com website ✓ bounty not set
sitepixel.dev.blis.com website ✓ bounty not set
sprint.com website ✓ bounty not set
staging-login.vistarmedia.com website ✓ bounty not set
staging-trafficking.vistarmedia.com website ✓ bounty not set
storybook.vistarmedia.com website ✓ bounty not set
t-mobile.com website ✓ bounty not set
T&P Servers network ✓ bounty not set
T&P Servers (Temporarily Out of Scope) network ✓ bounty not set
tess.service-now.com website ✓ bounty not set
tfb.t-mobile.com website ✓ bounty not set
transcodes-cdn.vistarmedia.com website ✓ bounty not set
wiki.atom-lens.com website ✓ bounty not set
wmaudience.com website ✓ bounty not set
*.mobile.uscc.com website out not set
*.mobile.uscc.net website out not set
*.moengage.com website out not set
*.sprint.net website out not set
/self-service-* website out not set
Any domain, property, product, protocol, or service of the app/hardware/software version not explicitly listed in the In-Scope section is out of scope; submissions are welcome but not guaranteed for the bounty/bonus. other out not set
appointments.uscellular.com website out not set
http://10.62.252.214/flag.txt network out not set
http://10.72.218.66/flag.txt network out not set
Leaked Credentials other submit only not set
Subdomain Takeover other submit only not set
T-Mobile - Android android submit only not set
T-Mobile - iOS ios submit only not set