AT&T says criminals stole phone records of 'nearly all' customers in new data breach | TechCrunch (2024)

U.S. phone giant AT&T confirmed Friday it will begin notifying millions of consumers about a fresh data breach that allowed cybercriminals to steal the phone records of “nearly all” of its customers, a company spokesperson told TechCrunch.

In a statement, AT&T said that the stolen data contains phone numbers of both cellular and landline customers, as well as AT&T records of calls and text messages — such as who contacted who by phone or text — during a six-month period between May 1, 2022 and October 31, 2022.

AT&T said some of the stolen data includes more recent records from January 2, 2023 for a smaller but unspecified number of customers.

The stolen data also includes call records of customers with phone service from other cell carriers that rely on AT&T’s network, the company said.

AT&T said the stolen data “does not contain the content of calls or texts,” but does include calling and texting records that an AT&T phone number interacted with during the six-month period, as well as the total count of a customer’s calls and texts, and call durations — information that is often referred to as metadata. The stolen data does not include the time or date of calls or texts, AT&T said.

Some of the stolen records include cell site identification numbers associated with phone calls and text messages, information that can be used to determine the approximate location of where a call was made or text message sent.

In all, the phone giant said it will notify around 110 million AT&T customers of the data breach, company spokesperson Andrea Huguely told TechCrunch.

AT&T published a website with information for customers about the data incident. AT&T also disclosed the data breach in a filing with regulators before the market opened on Friday.

Breach linked to Snowflake

AT&T said it learned of the data breach on April 19, and that it was unrelated to its earlier security incident in March.

AT&T’s Huguely told TechCrunch that the most recent compromise of customer records were stolen from the cloud data giant Snowflake during a recent spate of data thefts targeting Snowflake’s customers.

Snowflake allows its corporate customers, like tech companies and telcos, to analyze huge amounts of customer data in the cloud. It’s not clear for what reason AT&T was storing customer data in Snowflake, and the spokesperson would not say.

AT&T is the latest company in recent weeks to confirm it had data stolen from Snowflake, following Ticketmaster and LendingTree subsidiary QuoteWizard, and others.

Snowflake blamed the data thefts on its customers for not using multi-factor authentication to secure their Snowflake accounts, a security feature that the cloud data giant did not enforce or require its customers to use.

Cybersecurity incident response firm Mandiant, which Snowflake called in to help with notifying customers, later said about 165 Snowflake customers had a “significant volume of data” stolen from their customer accounts.

Mandiant attributed the breach to an as-yet-uncategorized cybercriminal group tracked only as UNC5537. Mandiant’s researchers say the hackers are financially motivated and have members in North America and at least one member in Turkey.

Some of the other corporate victims of the Snowflake account thefts had data subsequently published on known cybercrime forums. For AT&T’s part, the company said that it does not believe that the data is publicly available at this time.

AT&T’s statement said it was working with law enforcement to arrest the cybercriminals involved in the breach. AT&T said that “at least one person has been apprehended.” AT&T’s spokesperson said that the arrested individual was not an AT&T employee, but deferred questions about the alleged criminals to the FBI.

An FBI spokesperson confirmed to TechCrunch on Friday that after the phone giant contacted the agency to report the breach, AT&T, the FBI and the Department of Justice agreed to delay notifying the public and customers on two occasions, citing “potential risks to national security and/or public safety.”

“AT&T, FBI, and DOJ worked collaboratively through the first and second delay process, all while sharing key threat intelligence to bolster FBI investigative equities and to assist AT&T’s incident response work,” the FBI spokesperson said.

The FBI did not comment on the arrest of one of the alleged cybercriminals.

This is . AT&T was forced to reset the account passcodes of millions of its customers after a cache of customer account information — including encrypted passcodes for accessing AT&T customer accounts — was published on a cybercrime forum. A security researcher told TechCrunch at the time that the encrypted passcodes could be easily decrypted, prompting AT&T to take precautionary action to protect customer accounts.

Read more on TechCrunch:

  • Data breach exposes millions of mSpy spyware customers
  • Apple warns iPhone users in 98 countries of spyware attacks
  • Evolve Bank says ransomware gang stole personal data on millions of customers
  • OpenAI breach is a reminder that AI companies are treasure troves for hackers

Updated with comment from the FBI.

AT&T says criminals stole phone records of 'nearly all' customers in new data breach | TechCrunch (2024)

FAQs

AT&T says criminals stole phone records of 'nearly all' customers in new data breach | TechCrunch? ›

The stolen data contains phone numbers and AT&T records of calls and text messages during a six-month period in 2022, the company says. If you're an AT&T customer, here's what the breach could mean for you. Samsung is getting into the wearables game.

Are AT&T customers about data breach? ›

AT&T will contact you by text, email or U.S. mail if your account was affected by the cyberattack, the company said. But AT&T also said that “nearly all” customers had been affected by the breach. So if you were a customer from May 1, 2022, to Oct. 31, 2022, or on Jan. 2, 2023, your phone logs were most likely exposed.

How do I know if my AT&T data was breached? ›

"When customers log in, they can see if their data was affected. They can also request a report that provides a more user-friendly version of technical information that was compromised," an AT&T spokesperson told CBS MoneyWatch.

What data was stolen from AT&T? ›

A 2022 security breach compromised the data of "nearly all" AT&T cellular network customers, with hackers stealing six months worth of call and text message records, the company said Friday. The breach also impacts AT&T landline customers that interacted with affected cellular numbers, the company said.

Was AT&T hacked recently? ›

The company said in an SEC filing that it learned from an internal investigation that in April, hackers "unlawfully accessed and copied AT&T call logs" that were saved on a third-party cloud platform. The data contains records of calls and texts between approximately May 1 and Oct. 31, 2022, and on Jan. 2, 2023.

Why am I getting a data warning from AT&T? ›

AT&T 4GB plan

You'll get an alert when you use 75% and 100% of your data allowance. If you go over your data limit, we'll automatically add 2GB of additional data for $10. You'll get an alert when you reach 75% and 100% of the new total data limit.

How do I know if I have been data breached? ›

Check for suspicious logins into your accounts and activate notifications for them if the service you use provides them. Be on the lookout for misleading password retrieval emails and messages and only change your credentials by logging into the account from the official website.

What does AT&T do about stolen phones? ›

Report the claim within 60 days of the date of loss. If your device was lost or stolen, please contact AT&T Customer Care at 866. MOBILITY to temporarily suspend service and prevent unauthorized use. A non-refundable deductible will be charged to your wireless bill following each approved claim.

Can AT&T see what you do on your phone? ›

Web browsing and app information.

We automatically collect a variety of information which may include time spent on websites or apps, website and IP addresses and advertising IDs. It also can include links and ads seen, videos watched, search terms entered and items placed in online AT&T shopping carts.

What are my rights if my data has been breached? ›

Under data protection law, you are entitled to take your case to court to: enforce your rights under data protection law if you believe they have been breached. claim compensation for any damage caused by any organisation if they have broken data protection law, including any distress you may have suffered, or.

Can AT&T delete phone records? ›

With AT&T Phone, you can view a list of your most recent calls by date and time. You can sort your calls by missed, answered, or outgoing calls. Note: You can't manually delete your call history. Calls are automatically deleted after 60 days or after reaching the 100 call maximum.

Does AT&T keep phone records? ›

AT&T said the stolen data included records like what phone numbers a certain customer called and texted, the total count of calls and texts, and call durations for a six-month period between May 1, 2022 and October 31, 2022.

What to do about att hack? ›

What should AT&T customers do?
  1. Suspicious text activity: Do not reply. Forward the text to AT&T so they can assist you. ...
  2. You are a target of fraud on your AT&T wireless number: Report it to AT&T's fraud team. If you suspect fraud on another account, call the customer service number on your bill for help.
4 days ago

How serious is an AT&T data breach? ›

At that time, AT&T said personal information such as Social Security numbers on 73 million current and former customers was released onto the dark web. “We sincerely regret this incident occurred and remain committed to protecting the information in our care,” the company said in a statement about the latest breach.

How to find out if you were affected by an AT&T data breach? ›

AT&T data breach: Was I affected? AT&T said it will alert customers who were impacted via text, email or U.S. mail. It also said people could log into their account, where they'll be able to see if their data was affected.

What are signs my phone is hacked? ›

Here are the most common signs of phone hacking:
  • Pop-ups. If you're seeing a lot of pop-up ads, your phone could have an adware infection. ...
  • Unrecognized texts or calls. ...
  • High data usage. ...
  • High battery drain. ...
  • Hot phone. ...
  • Reduced performance. ...
  • Websites look strange. ...
  • Unexpected charges on your phone bill.
Jan 24, 2024

What are AT&T common complaints? ›

Customers report a wide variety of problems with their monthly bills including: Price increases without notification. Refusal to pro-rate fees when a customer cancels their service. Customers that cancel in the middle of a billing period will be charged the full amount, even though they no longer had service.

Is AT&T a secure network? ›

We use a centralized control function that incorporates user-defined application and routing policies, to provide highly secure, dynamic, and application-aware network traffic management.

Does AT&T share your information? ›

We may share information with affiliates and other companies to deliver our ads and marketing or to assess their effectiveness. (Learn more about our ad programs and see your choices.) Non-AT&T companies providing a service.

References

Top Articles
Latest Posts
Article information

Author: Domingo Moore

Last Updated:

Views: 5705

Rating: 4.2 / 5 (53 voted)

Reviews: 92% of readers found this page helpful

Author information

Name: Domingo Moore

Birthday: 1997-05-20

Address: 6485 Kohler Route, Antonioton, VT 77375-0299

Phone: +3213869077934

Job: Sales Analyst

Hobby: Kayaking, Roller skating, Cabaret, Rugby, Homebrewing, Creative writing, amateur radio

Introduction: My name is Domingo Moore, I am a attractive, gorgeous, funny, jolly, spotless, nice, fantastic person who loves writing and wants to share my knowledge and understanding with you.