So the customer got SMS spam from a third-party and there was no T-Mobile breach? The fuck up is the spammer makes spelling mistakes?
Typo URL in internal account memos + texts sent by the company to subscribers : http://metro-tmo.co/CustInfo
Actual legitimate URL they meant to put : http://metro-tmo.com/CustInfo