They have poor security practices like storing passwords in plaintext [2], and they had a large data breach (probably about 100M customers affected) last year. [3]
A̶n̶d̶ ̶n̶o̶w̶,̶ ̶i̶t̶ ̶s̶e̶e̶m̶s̶ ̶t̶h̶e̶y̶ ̶a̶r̶e̶ ̶t̶h̶r̶o̶w̶i̶n̶g̶ ̶i̶n̶ ̶s̶o̶m̶e̶ ̶p̶r̶o̶t̶o̶c̶o̶l̶ ̶b̶l̶o̶c̶k̶i̶n̶g̶ ̶t̶o̶o̶.̶
PS: This isn't protocol blocking at the packet/port level, so I may have used "protocol blocking" a bit inappropriately. Apparently Apple allows the carriers to prevent people from enabling iCloud Private Relay, and T-Mobile is doing that. Apple is probably doing so due to the pressure by the carriers. In August, four carriers (Vodafone, Telefonica, Orange and T-Mobile ) signed a letter urging the European Commission to stop Apple from providing Private Relay. (According to a report by The Telegraph: https://archive.fo/BRUS4#selection-915.74-925.194) This, of course, still quite preposterous.
[1]: https://news.ycombinator.com/item?id=29744347
[2]: https://news.ycombinator.com/item?id=16776347
[3]: https://news.ycombinator.com/item?id=28192423 (The first comment by @jonathanmayer has a list of other recent T-Mobile security incidents)