Nearly all AT&T cell customers’ call and text records exposed in a massive breach | CNN Business (2024)

Nearly all AT&T cell customers’ call and text records exposed in a massive breach | CNN Business (1)

A visitor walks past an AT&T logo.

CNN

The call and text message records from mid-to-late 2022 of tens of millions of AT&T cellphone customers and many non-AT&T customers were exposed in a massive data breach, the telecom company revealed Friday.

AT&T said the compromised data includes the telephone numbers of “nearly all” of its cellular customers and the customers of wireless providers that use its network between May 1, 2022 and October 31, 2022.

The stolen logs also contain a record of every number AT&T customers called or texted – including customers of other wireless networks – the number of times they interacted, and the call duration.

Importantly, AT&T said the stolen data did not include the contents of calls and text messages nor the time of those communications.

The records of a “very small number” of customers from January 2, 2023, were also implicated, AT&T said.

“We have an ongoing investigation into the AT&T breach and we’re coordinating with our law enforcement partners,” the FCC said on social media platform X.

The companyblamedan “illegal download” on a third-party cloud platform that it learned about in April – just as the company was grappling with anunrelated major data leak.

AT&T says that the exposed data is not believed to be publicly available, however CNN was unable to independently verify that assertion.

AT&T spokesperson Alex Byers told CNN that this was an entirely new incident that had “no connection in any way” to another incident disclosed in March. At that time, AT&T said personal information such as Social Security numbers on 73 million current and former customers was released onto the dark web.

“We sincerely regret this incident occurred and remain committed to protecting the information in our care,” the company said in a statement about the latest breach.

AT&T listed approximately 110 million wireless subscribers as of the end of 2022. AT&T said international calls were not included in the stolen data, with the exception of calls to Canada.

The breach also included AT&T landline customers who interacted with those cell numbers.

AT&T said that contents of the calls or texts, personal information such as Social Security numbers, dates of birth, or customer names were not exposed in this incident, however the company acknowledged that publicly available tools can often link names with specific phone numbers.

Additionally, AT&T said that for an undisclosed subset of its records, one or more cell site identification numbers linked to the calls and texts were also exposed. Such data could reveal the broad geographic location of one or more of the parties.

AT&T believes that at least one person involved in the cybercriminal incident is in custody, the company said in a filing with the Securities and Exchange Commission. The FBI declined to comment when asked about that statement.

AT&T promised to notify current and former customers whose information was involved and provide them resources to protect their information.

Usage details such as the time of calls and text messages were not compromised either. But AT&T spokesperson Byers told CNN that the number of calls and text messages, and total call durations for specific days or months were exposed.

That means the data would not identify precisely when one phone number called another but could reveal how often two parties called each other – and how long they spoke for – on specific days.

AT&T said it learned on April 19 that a “threat actor claimed to have unlawfully accessed and copied AT&T call logs.” The company said it “immediately” hired experts and a subsequent investigation determined hackers had exfiltrated files between April 14 and April 25.

Justice Department delays public disclosure

The company said the US Department of Justice Department determined in May and in June that a delay in public disclosure was warranted. The FBI said AT&T reached out shortly after learning about the hack, but the agency wanted to review the data for potential national security or public safety risks.

“In assessing the nature of the breach, all parties discussed a potential delay to public reporting… due to potential risks to national security and/or public safety,” the FBI said in a statement. “AT&T, FBI, and DOJ worked collaboratively through the first and second delay process, all while sharing key threat intelligence to bolster FBI investigative equities and to assist AT&T’s incident response work.”

This appears to be the first cyber incident in which the Justice Department has asked a company to delay filing a disclosure with the SEC because of potential national security or public safety concerns.

“This is very concerning. This information is very valuable to cyber criminals and to nation-states,” Sanaz Yashar, co-founder and CEO of cybersecurity firm Zafran, told CNN.

Yashar, previously an Israeli cyber spy, said threat actors can correlate the cell ID data with other information readily available to pinpoint where someone works – including at sensitive locations like the White House and Pentagon.

“You don’t need the timestamp. If someone is there everyday, you can understand they work there and their routine. This is very secret information and a way that spies do stuff.”

Justin Sherman, founder of Global Cyber Strategies, a consultancy, also put the potential threat in stark terms.

“Metadata about who’s communicating with who, at massive scale, enables someone to map connections between people — think journalists and sources, intelligence officers and their contacts, married people and those with whom they’re having an affair,” Sherman told CNN.

Jason Hogg, a former FBI special agent who is now executive-in-residence at Great Hill Partners, said the cell site data is “quite significant because it could allow bad actors to determine certain consumers’ geolocation, which could be used to make the social engineering attacks more believable.”

AT&T shares fell 1% on Friday following the news.

In the new incident, AT&T told CNN it learned in April that customer data was illegally downloaded from its workspace on Snowflake, a third-party cloud platform.

AT&T is only the latest major company to have data stolen via access to their Snowflake platform. Ticketmaster and Santander Bank have also recently disclosed massive data breaches linked to Snowflake. Mandiant, a Google-owned cybersecurity firm, has notified at least 165 organizations that they may have been affected by the hacking spree. Mandiant analysts said they have “moderate confidence” that the hackers are based in North America and that they collaborate with an additional person in Turkey.

Brad Jones, chief information security officer at Snowflake, told CNN in a separate statement that the company has not found evidence this activity was “caused by a vulnerability, misconfiguration or breach of Snowflake’s platform.” Jones said this has been verified by investigations by third-party cybersecurity experts at Mandiant and CrowdStrike.

AT&T said it launched an investigation, hired cybersecurity experts and took steps to close the “illegal access point.”

This story has been updated with additional context and developments.

Nearly all AT&T cell customers’ call and text records exposed in a massive breach | CNN Business (2024)

FAQs

Nearly all AT&T cell customers’ call and text records exposed in a massive breach | CNN Business? ›

The call and text message records of tens of millions of AT&T cellphone customers and many non-AT&T customers in mid-to-late 2022 were exposed in a massive data breach, the telecom company revealed Friday. AT&T said the hacked data did not include the content of calls and text messages.

Did AT&T hacker steal call text records of nearly all customers? ›

Hackers stole six months' worth of call and text message records of nearly every AT&T cellular network customer, the company said Friday, a breach that has the potential to reveal sensitive information about millions of Americans.

What was exposed to the AT&T data breach? ›

AT&T announced a cybersecurity breach on July 12th that exposed call records and text data for a significant portion of its customer base. This includes customers on mobile virtual network operators (MVNOs) that use AT&T's network, like Cricket, Boost Mobile, and Consumer Cellular.

Is AT&T customer service having a data breach? ›

Almost everyone with AT&T mobile service -- nearly 110 million customers -- has been affected by this breach. AT&T said it would notify affected customers by mail, text or email. However, customers with AT&T mobile service between May 1, 2022, and Oct. 31, 2022, along with a select few accounts active on Jan.

Did AT&T say hacker stole data on nearly all of its wireless customers? ›

Hackers steal call records of 'nearly all' AT&T customers

Hackers stole call and text records data from "nearly all" of 109 million AT&T Wireless customers, the telecommunications company disclosed on Friday.

What happened with the AT&T hack? ›

Recently, AT&T said that “nearly all” of its cell phone customers were affected by an attack that exposed call and text logs to hackers. The actual content of those calls and texts is said to be safe, and AT&T doesn't believe the hacked data has been made public.

Can AT&T see your text messages? ›

Data usage displays the amount of cellular data used. Hotspot usage shows the amount of cellular data used for hotspot. FYI: The content of text or video messages isn't visible or accessible to anyone on the account.

Why am I getting a data warning from AT&T? ›

We'll send a text alert when you use 37.5GB of data. This is 75% of your 50GB data threshold. You'll get an alert when you use 75% and 100% of your data allowance.

Did AT&T have a data breach in 2024? ›

On Friday July 12, AT&T disclosed that the phone records of almost all current and former AT&T customers were stolen by hackers in April 2024 (AT&T notified the SEC at that time, at which point the US Department of Justice determined a delay in making the breach public was warranted).

How do I know if my AT&T data was breached? ›

If your account was included AT&T said they would contact you by text, email, or U.S. mail. You can also check if their data was compromised – including texts and phone numbers included in the download - by logging onto their accounts.

What is the AT&T text message data breach? ›

AT&T says calls and text message records for tens of millions of the phone service provider's customers were exposed in a massive data breach two years ago. The company announced Friday that nearly all of its mobile phone customers' information was exposed over the course of months in 2022.

Did AT&T say criminals stole phone records? ›

In a filing with the Securities and Exchange Commission (SEC), AT&T said: “On April 19, 2024, AT&T Inc. (“AT&T”) learned that a threat actor claimed to have unlawfully accessed and copied AT&T call logs.” AT&T says the customer data was illegally downloaded from its workspace on a third-party cloud platform.

Did hackers get your cell phone number from AT&T? ›

AT&T said Friday that hackers who have hit other companies also swiped at least six months of 2022 phone records for almost everyone who had AT&T mobile service — that's roughly 110 million customer accounts.

Can hackers get into your phone by text messages? ›

Yes, it's possible. Avoid clicking any links in texts or emails from unknown senders. However, hackers can also steal your information without you clicking a link.

Does AT&T keep record of text message content? ›

AT&T currently stores Your sent and received Messages for up to 90 days. Messages older than 90 days will be deleted from Your Messages cloud storage.

Can AT&T pull up call history? ›

Select the (+) on the My Digital Phone menu. Select Check or manage voicemail & features from the MyVoicemail & Phone Features menu. Select the Call History tab and go to your AT&T Phone Call Logs page. You can sort your call history by name, length of call, or search for a call.

Can someone steal your information if you answer a phone call? ›

Although cybercriminals cannot steal your information just by you answering a spam call, you should still avoid answering them to prevent them from targeting you more and falling for their scams.

Top Articles
Keto Chocolate Bars (Award Winning Recipe!) - The Big Man's World ®
Better Than Anything Toffee Recipe
Katie Nickolaou Leaving
Localfedex.com
Craigslist Mexico Cancun
Noaa Weather Philadelphia
Apnetv.con
Www Thechristhospital Billpay
Www.paystubportal.com/7-11 Login
Our Facility
Washington, D.C. - Capital, Founding, Monumental
Simon Montefiore artikelen kopen? Alle artikelen online
Jinx Chapter 24: Release Date, Spoilers & Where To Read - OtakuKart
10-Day Weather Forecast for Santa Cruz, CA - The Weather Channel | weather.com
Aldine Isd Pay Scale 23-24
Nevermore: What Doesn't Kill
Allybearloves
Dragonvale Valor Dragon
Sister Souljah Net Worth
New Stores Coming To Canton Ohio 2022
WRMJ.COM
My Dog Ate A 5Mg Flexeril
Does Circle K Sell Elf Bars
Fedex Walgreens Pickup Times
Kltv Com Big Red Box
Sun-Tattler from Hollywood, Florida
What Time Does Walmart Auto Center Open
1400 Kg To Lb
Car Crash On 5 Freeway Today
Afspraak inzien
Mcgiftcardmall.con
Miracle Shoes Ff6
Hometown Pizza Sheridan Menu
2020 Can-Am DS 90 X Vs 2020 Honda TRX90X: By the Numbers
Craigslist Pa Altoona
Thelemagick Library - The New Comment to Liber AL vel Legis
Umiami Sorority Rankings
Bekah Birdsall Measurements
The Attleboro Sun Chronicle Obituaries
Satucket Lectionary
Powerboat P1 Unveils 2024 P1 Offshore And Class 1 Race Calendar
Here's Everything You Need to Know About Baby Ariel
'The Night Agent' Star Luciane Buchanan's Dating Life Is a Mystery
Craigslist Minneapolis Com
Sechrest Davis Funeral Home High Point Nc
Csgold Uva
Yourcuteelena
American Bully Puppies for Sale | Lancaster Puppies
Call2Recycle Sites At The Home Depot
Roller Znen ZN50QT-E
Diesel Technician/Mechanic III - Entry Level - transportation - job employment - craigslist
4015 Ballinger Rd Martinsville In 46151
Latest Posts
Article information

Author: Tyson Zemlak

Last Updated:

Views: 6475

Rating: 4.2 / 5 (63 voted)

Reviews: 94% of readers found this page helpful

Author information

Name: Tyson Zemlak

Birthday: 1992-03-17

Address: Apt. 662 96191 Quigley Dam, Kubview, MA 42013

Phone: +441678032891

Job: Community-Services Orchestrator

Hobby: Coffee roasting, Calligraphy, Metalworking, Fashion, Vehicle restoration, Shopping, Photography

Introduction: My name is Tyson Zemlak, I am a excited, light, sparkling, super, open, fair, magnificent person who loves writing and wants to share my knowledge and understanding with you.