Work at T-Mobile? Claim it to respond to reviews as the verified owner.
Found a vulnerability?
If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.
Ask BugRater to submit itPrivate. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.
Reviews
0 publishedNo reviews yet.
Facts published by Bugcrowd on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 19 Sep 2026.
Program Purpose T-Mobile USA, Inc. ("T-Mobile") is committed to protecting our customers, our employees, our partners, and our brand. As part of this commitment, T-Mobile works with the security community to keep our customers and business safe. If you have identified a high-impact, reproducible security vulnerability in a T-Mobile property, application, or system, we encourage you to report it. We are especially interested in vulnerabilities that could materially affect: T-Mobile customers, employees, and owned brands or acquired businesses; customer accounts, billing, identity, authentication, and line-management systems; cellular, MSISDN, SIM/eSIM, DIGITS, messaging, location, and carrier-trust workflows; T-Mobile internal, cloud, administrative, and business operations. We evaluate reported vulnerabilities and promptly take appropriate action. Scope Boundary In this policy, T-Mobile means T-Mobile USA, Inc. and its affiliates. This program is limited to T-Mobile-owned or T-Mobile-controlled assets explicitly listed as in scope. T-Mobile does not own — and cannot remediate findings on — non-T-Mobile assets, including Deutsche Telekom assets and third-party vendors. Deutsche Telekom domains, applications, systems, networks, services, subsidiaries, infrastructure, employee accounts, customer data, and corporate environments are out of scope and not eligible for bounty — even where the asset references T-Mobile, shares branding, links to T-Mobile properties, or appears related to T-Mobile business operations. Any domain, property, product, protocol, or service not explicitly listed in scope is out of scope. Submissions against unlisted assets are welcome but not guaranteed a bounty. Eligibility The following are not eligible to participate. T-Mobile determines eligibility in its sole discretion, evaluated at submission and at payment. residents of countries or regions under applicable U.S. sanctions or export restrictions; persons on the U.S. Treasury SDN List or another applicable restricted-party list; current or former employees, contractors, consultants, interns, or vendor staff of T-Mobile or any T-Mobile affiliate, regardless of when the relationship ended; current or former employees of SoftBank Group Corp. or any of its affiliates; immediate family or household members of any person in the preceding two bullets; any person bound by a current or former NDA, confidentiality, or similar agreement with T-Mobile or any T-Mobile affiliate covering T-Mobile systems, security, source code, operations, or customer/employee data; any person who has had, at any time, non-public access to T-Mobile systems, source code, vulnerabilities, security testing, internal tools, credentials, or customer/employee data; any Bugcrowd staff member with access to the T-Mobile program, and their immediate family or household members; any person who learned of, identified, or developed the finding while in any role, agreement, or access above, regardless of current status; any other person prohibited by applicable law, regulation, contract, or program rule. T-Mobile affiliate means any parent, subsidiary, predecessor, successor, acquired entity, branded MVNO, joint venture, or otherwise controlled entity of T-Mobile USA, Inc. Immediate family means spouse, domestic partner, parent, child, sibling, and step/half/in-law equivalents. Household member means anyone sharing the researcher’s residence. Submitting on behalf of an ineligible person through a proxy, agent, alt account, or third party voids the submission. Researchers must promptly disclose any fact that could affect eligibility, and T-Mobile may require identity, employment, or tax documentation as a condition of triage or payment. Ineligible submissions are void. T-Mobile may withhold unpaid rewards and, where permitted, recover amounts already paid, close associated submissions, ban the researcher, and refer the matter to Bugcrowd, law enforcement, or regulators. Program Terms Participation in T-Mobile’s Bug Bounty Program is voluntary and subject to the terms and conditions of this policy. By submitting a vulnerability report to T-Mobile, researchers acknowledge that they have read and agree to comply with this policy. T-Mobile may modify this policy at any time. Continued participation in the program after a modification constitutes acceptance of the modified policy. Submission of a security report does not create a consumer, employment, contractor, partnership, or agency relationship between the researcher and T-Mobile. All communications regarding vulnerability findings, submissions, appeals, questions, or T-Mobile Bug Bounty Program policies must be conducted through the Bugcrowd platform. Researchers must not use any alternative channel unless expressly authorized in writing by T-Mobile or Bugcrowd. Prohibited channels include but are not limited to: direct contact with T-Mobile employees or executives by any means; social-media messages or posts directed at T-Mobile personnel; T-Mobile customer, enterprise, support, sales, PR, HR, or legal channels; physical visits to T-Mobile locations; any T-Mobile contact, regardless of how it was obtained. Intent (e.g., “just a heads-up”) does not create an exception. Failure to comply may result in removal from the program, reduced or forfeited bounty payments, ineligibility for future participation, and/or other punitive actions. T-Mobile may use the contents of submitted reports for any purpose related to validation, remediation, legal obligations, regulatory obligations, contractual obligations, security operations, or protection of T-Mobile, its customers, employees, partners, products, services, or systems. Information provided to T-Mobile will be handled according to T-Mobile’s Privacy Policy. Researchers must adhere to the Bugcrowd Community Code of Conduct and Bugcrowd Terms and Conditions. If this policy conflicts with Bugcrowd disclosure guidance or platform rules, this policy controls for the
Scope
87 assets| Asset | Type | Eligibility | Max severity |
|---|---|---|---|
| *.api.t-mobile.com | api | ✓ bounty | not set |
| *.assurancewireless.com | website | ✓ bounty | not set |
| *.metrobyt-mobile.com | website | ✓ bounty | not set |
| *.sprint.com | website | ✓ bounty | not set |
| *.t-mobile.com | website | ✓ bounty | not set |
Show all 87 assets
| Asset | Type | Eligibility | Max severity |
|---|---|---|---|
| *.uscc.com | website | ✓ bounty | not set |
| *.uscc.net | website | ✓ bounty | not set |
| *.uscellular.com | website | ✓ bounty | not set |
| account.business.t-mobile.com | website | ✓ bounty | not set |
| account.t-mobile.com | website | ✓ bounty | not set |
| api.vistarmedia.com | website | ✓ bounty | not set |
| api.vistarmedia.eu | website | ✓ bounty | not set |
| assets-cdn.vistarmedia.com | website | ✓ bounty | not set |
| assets.development.amazon-tacticalplanner.com | website | ✓ bounty | not set |
| assets.platform.blis.com | website | ✓ bounty | not set |
| assets.platform.development.blis.com | website | ✓ bounty | not set |
| assets.platform.rc.blis.com | website | ✓ bounty | not set |
| assurancewireless.com | website | ✓ bounty | not set |
| audience-builder.vistarmedia.com | website | ✓ bounty | not set |
| audiencelogos.blis.com | website | ✓ bounty | not set |
| blis.com | website | ✓ bounty | not set |
| Cellular Network Auth Bypass via Web App/T-Life (404-200-7239) | network | ✓ bounty | not set |
| clients.adstruc.com | website | ✓ bounty | not set |
| creative.infinity.blismedia.com | website | ✓ bounty | not set |
| creatives.vistarmedia.com | website | ✓ bounty | not set |
| dashboard-101.moengage.com | website | ✓ bounty | not set |
| demo.adstruc.com | website | ✓ bounty | not set |
| devedge.t-mobile.com | website | ✓ bounty | not set |
| development.wmaudience.com | website | ✓ bounty | not set |
| DIGITS - Web, Desktop, Mobile | website | ✓ bounty | not set |
| docker-staging.adstruc.com | website | ✓ bounty | not set |
| docsite.vistarmedia.com | website | ✓ bounty | not set |
| imply-pivot.blis.com | website | ✓ bounty | not set |
| imply-pivot.test.blis.com | website | ✓ bounty | not set |
| imply.blis.com | website | ✓ bounty | not set |
| imply.internal.platform.blis.com | website | ✓ bounty | not set |
| imply.platform.blis.com | website | ✓ bounty | not set |
| imply.platform.development.blis.com | website | ✓ bounty | not set |
| imply.platform.rc.blis.com | website | ✓ bounty | not set |
| imply.test.blis.com | website | ✓ bounty | not set |
| imply.wmaudience.com | website | ✓ bounty | not set |
| internal.platform.blis.com | website | ✓ bounty | not set |
| jenkins-github.gcp.blis.com | website | ✓ bounty | not set |
| job-svc-b.vistarmedia.com | website | ✓ bounty | not set |
| maps.vistarmedia.com | website | ✓ bounty | not set |
| metrobyt-mobile.com | website | ✓ bounty | not set |
| packages.cortexpowered.com | website | ✓ bounty | not set |
| platform.blis.com | website | ✓ bounty | not set |
| platform.blismedia.com | website | ✓ bounty | not set |
| platform.development.blis.com | website | ✓ bounty | not set |
| platform.development2.blis.com | website | ✓ bounty | not set |
| platform.rc.blis.com | website | ✓ bounty | not set |
| privacy.blismedia.com | website | ✓ bounty | not set |
| production-delivery-metrics-svc.vistarmedia.com | website | ✓ bounty | not set |
| production-dynam-creative.vistarmedia.com | website | ✓ bounty | not set |
| rc.wmaudience.com | website | ✓ bounty | not set |
| Self-Register Account on T-Mobile Microsoft Entra ID | other | ✓ bounty | not set |
| sfleet.cortexpowered.com | website | ✓ bounty | not set |
| sflower.cortexpowered.com | website | ✓ bounty | not set |
| signature.blis.com | website | ✓ bounty | not set |
| sitepixel.blis.com | website | ✓ bounty | not set |
| sitepixel.dev.blis.com | website | ✓ bounty | not set |
| sprint.com | website | ✓ bounty | not set |
| staging-login.vistarmedia.com | website | ✓ bounty | not set |
| staging-trafficking.vistarmedia.com | website | ✓ bounty | not set |
| storybook.vistarmedia.com | website | ✓ bounty | not set |
| t-mobile.com | website | ✓ bounty | not set |
| T&P Servers | network | ✓ bounty | not set |
| T&P Servers (Temporarily Out of Scope) | network | ✓ bounty | not set |
| tess.service-now.com | website | ✓ bounty | not set |
| tfb.t-mobile.com | website | ✓ bounty | not set |
| transcodes-cdn.vistarmedia.com | website | ✓ bounty | not set |
| wiki.atom-lens.com | website | ✓ bounty | not set |
| wmaudience.com | website | ✓ bounty | not set |
| *.mobile.uscc.com | website | out | not set |
| *.mobile.uscc.net | website | out | not set |
| *.moengage.com | website | out | not set |
| *.sprint.net | website | out | not set |
| /self-service-* | website | out | not set |
| Any domain, property, product, protocol, or service of the app/hardware/software version not explicitly listed in the In-Scope section is out of scope; submissions are welcome but not guaranteed for the bounty/bonus. | other | out | not set |
| appointments.uscellular.com | website | out | not set |
| http://10.62.252.214/flag.txt | network | out | not set |
| http://10.72.218.66/flag.txt | network | out | not set |
| Leaked Credentials | other | submit only | not set |
| Subdomain Takeover | other | submit only | not set |
| T-Mobile - Android | android | submit only | not set |
| T-Mobile - iOS | ios | submit only | not set |