Or the service API that T-Mobile calls in to for the credit checks was left exposed in a way that granted access to the server that hosts it. Then the traffic from that server to the database that stores the data was also left open. It doesn’t have to be an inside job, it just has to be a bunch of people who don’t…