Nearly all AT&T cell customers’ call and text records exposed in a massive breach

DC_Dude

Rising Star
BGOL Investor

Nearly all AT&T cell customers’ call and text records exposed in a massive breach​

A visitor walks past an AT&T logo.

CNN — normal
The call and text message records from mid-to-late 2022 of tens of millions of AT&T cellphone customers and many non-AT&T customers were exposed in a massive data breach, the telecom company revealed Friday.

AT&T said the compromised data includes the telephone numbers of “nearly all” of its cellular customers and the customers of wireless providers that use its network between May 1, 2022 and October 31, 2022.

The stolen logs also contain a record of every number AT&T customers called or texted – including customers of other wireless networks – the number of times they interacted, and the call duration.

Importantly, AT&T said the stolen data did not include the contents of calls and text messages nor the time of those communications.

The records of a “very small number” of customers from January 2, 2023, were also implicated, AT&T said.

“We have an ongoing investigation into the AT&T breach and we’re coordinating with our law enforcement partners,” the FCC said on social media platform X.

The company blamed an “illegal download” on a third-party cloud platform that it learned about in April – just as the company was grappling with an unrelated major data leak.

AT&T says that the exposed data is not believed to be publicly available, however CNN was unable to independently verify that assertion.

AT&T spokesperson Alex Byers told CNN that this was an entirely new incident that had “no connection in any way” to another incident disclosed in March. At that time, AT&T said personal information such as Social Security numbers on 73 million current and former customers was released onto the dark web.

“We sincerely regret this incident occurred and remain committed to protecting the information in our care,” the company said in a statement about the latest breach.

AT&T listed approximately 110 million wireless subscribers as of the end of 2022. AT&T said international calls were not included in the stolen data, with the exception of calls to Canada.

The breach also included AT&T landline customers who interacted with those cell numbers.

AT&T said that contents of the calls or texts, personal information such as Social Security numbers, dates of birth, or customer names were not exposed in this incident, however the company acknowledged that publicly available tools can often link names with specific phone numbers.

Additionally, AT&T said that for an undisclosed subset of its records, one or more cell site identification numbers linked to the calls and texts were also exposed. Such data could reveal the broad geographic location of one or more of the parties.

AT&T promised to notify current and former customers whose information was involved and provide them resources to protect their information.

Usage details such as the time of calls and text messages were not compromised either. But AT&T spokesperson Byers told CNN that the number of calls and text messages, and total call durations for specific days or months were exposed.

That means the data would not identify precisely when one phone number called another but could reveal how often two parties called each other – and how long they spoke for – on specific days.

AT&T said it learned on April 19 that a “threat actor claimed to have unlawfully accessed and copied AT&T call logs.” The company said it “immediately” hired experts and a subsequent investigation determined hackers had exfiltrated files between April 14 and April 25.

Justice Department delays public disclosure​

The company said the US Department of Justice Department determined in May and in June that a delay in public disclosure was warranted. The FBI said AT&T reached out shortly after learning about the hack, but the agency wanted to review the data for potential national security risks.

“In assessing the nature of the breach, all parties discussed a potential delay to public reporting … due to potential risks to national security and/or public safety,” the FBI said in a statement. “AT&T, FBI, and DOJ worked collaboratively through the first and second delay process, all while sharing key threat intelligence to bolster FBI investigative equities and to assist AT&T’s incident response work.”

AT&T shares fell 1% on Friday following the news.

In the new incident, AT&T told CNN it learned in April that customer data was illegally downloaded from its workspace on Snowflake, a third-party cloud platform.

Brad Jones, chief information security officer at Snowflake, told CNN in a separate statement that the company has not found evidence this activity was “caused by a vulnerability, misconfiguration or breach of Snowflake’s platform.” Jones said this has been verified by investigations by third-party cybersecurity experts at Mandiant and CrowdStrike.

AT&T said it launched an investigation, hired cybersecurity experts and took steps to close the “illegal access point.”

The company said it’s cooperating with law enforcement’s efforts to apprehend those responsible and understands at least one person has already been arrested.

This story has been updated with additional context and developments.
 

tallblacknyc

Rising Star
Certified Pussy Poster
I've never used AT&T so...

It's only important to the famous and important people who might have something to hide.Other than that no one wants to listen or read most people's conversations about bullshit.
Lot of cheating and broads sending naked pics.. if you get a lot of action you probably got a lot of vids of chicks sucking your dick that you might send to another chick to show her how you like it done
 

playahaitian

Rising Star
Certified Pussy Poster
The publics' continued collective yawns about all these insanely huge data breeches...

With no real repercussions to these massive corporations

Is revealing as f**k

All these conspiracy theory anti corporations folk all cast a blind eye.
 

yaBoi

X-pert Professional
Platinum Member
I haven't had AT&T in over 20 years...

...but that doesn't mean Cingular (RIP to the GOAT) Verizon, Sprint and Xfinity are any safer.
Suncom was bought by Cingular was then bought by AT&T (which was Bellsouth mobility at the time)

i used to work there.. same shit they just changed the name on the building

all them shits are the same thing
 

yaBoi

X-pert Professional
Platinum Member
That was they SAY. It’s possible there’s some end-to-end encryption. Possible.
yeah the only thing that they got was phone numbers and who called who when....... (my understanding)

most text info now goes over imessage and google message which is encrypted
 

Kaotic

Dancing with the devil in the pale moon light...
Platinum Member
On another note... If you play the market... I'm thinking AT&T is about to take a nice dip once this news really hits the masses. I bet they they purposely waited until Friday to do the release.
 

BigDaddyBuk

still not dizzy.
Platinum Member
all them shits are the same thing
Disagree bruh!

Cingular had amazing customer service and reliable cellular service.

AS SOON as AT&T took over, my calls became spotty and started dropping. Folks at customer service didn't give ONE fuck.

I went to Verizon and their coverage was perfect. Their billing dept fucked me over.

Then I got grandfathered into my wife's ancient ass sprint account and that shit was like 13 bucks a month with unlimited service :lol:

Then Sprint discontinued it so I went with Xfinity and they been damn good.
 

ZuluSam

Rising Star
Platinum Member

Nearly all AT&T cell customers’ call and text records exposed in a maCNN — normal​



Importantly, AT&T said the stolen data did not include the contents of calls and text messages nor the time of those communications.



This story has been updated with additional context and developments.

Nearly all AT&T cell customers’ call and text records exposed in a maCNN — normal​



Importantly, AT&T said the stolen data did not include the contents of calls and text messages nor the time of those communications.



This story has been updated with additional context and developments.
 
Top