Managed to steal very similar information, but also included drivers license numbers and some people's passport numbers. Interestingly, for a while there was a post that allowed us to query the suspected API once authentication with our own accounts, which pulled down our drivers license numbers.
It's prompted a major investigation into identity legislation and data security. Our government bodies started allowing people to change their driver's license online. Furthermore the breached Telco started providing free credit monitoring services.
I wonder if the success from that hack has prompted attackers to pay more attention to unsecured API's. Not that it wouldn't have been a topic before.