AT&T says hackers stole call records of ‘nearly all’ wireless customers (2024)

Hackers stole records detailing the phone contacts of almost all AT&T Wireless customers in one of the most serious breaches of sensitive consumer data in recent years, the company disclosed in a securities filing Friday.

The cache includes the numbers called or texted by more than 100 million customers between May 1 and Oct. 31, 2022, as well as one day in January 2023. It contains the numbers themselves as well as the frequency and combined durations of the interactions, but not the customer names or the content of those communications, AT&T said.

Since most numbers can be tied to real names, such records illuminate who is close to whom. That would provide a road map for criminals who could impersonate a friend or relative to trick a victim. Texts from financial institutions could be mimicked to get an account holder to divulge passwords, and workplace relationships could reveal the identity of U.S. spies.

Advertisem*nt

“This data could be used by spies, scammers and other bad actors to target specific people or to improve the feasibility of scams by impersonating the numbers of people you regularly call,” said technologist Cooper Quintin of the Electronic Frontier Foundation.

The ability of U.S. intelligence to access similar calling records was one of the most alarming and impactful revelations by federal contractor Edward Snowden a decade ago. Now a large swath of it might be for sale to criminals and other governments.

GET CAUGHT UP

Stories to keep you informed

Dissenting Republican delegates sign protest of Trump platform SparkleSummary is AI-generated, newsroom-reviewed.
Family of teen who died after ‘One Chip Challenge’ sues snack companySparkleSummary is AI-generated, newsroom-reviewed.
La Niña is coming. Here’s how it could change the weather.SparkleSummary is AI-generated, newsroom-reviewed.
Do landlords have to provide AC? Here’s what renters should know.SparkleSummary is AI-generated, newsroom-reviewed.

AT&T said it had not detected the material being made public, and it said one person had been arrested. The company said it learned of the theft in April but delayed disclosing it — as required under recently adopted Securities and Exchange Commission regulations — at the request of law enforcement, for national security or public safety reasons, the first time such a delay has been disclosed.

Advertisem*nt

Justice Department spokesman Joshua Stueve confirmed that the FBI had invoked the legal provision allowing the delay, and said AT&T had aided the investigation. He did not say how the breach could have impacted national security. The Federal Communications Commission said it was also investigating.

While Social Security and credit card numbers were not included in the breach, the identity of cell towers for an undisclosed number of customers was, and those would point to their physical locations.

Even without that location data, hackers could work out relationship webs, experts warned. Someone targeting a criminal prosecutor or police officer might be able to identify a close relative and then use that number to find out where they live. Spurned romantic partners could do the same.

Because those in contact with AT&T users also have their numbers listed, “just about EVERYONE in the US who uses SMS or voice telephony is likely represented to some degree,” tech security expert Matt Blaze wrote on the social media platform Mastodon.

A major concern is that the data could be used to locate U.S. government workers employed abroad, or people communicating with the government, said David Berteau, president of the Professional Services Council, which represents contractors employing security-cleared workers.

“Given what we know now, there is clearly a risk to anybody who has a [security] clearance who might have called anybody who has an AT&T phone. Which is probably anybody with a clearance,” Berteau said.

AT&T said the attack began with illicit access to one of its accounts with a major but low-profile cloud data storage company, Snowflake. More than 100 of that company’s corporate customers have been compromised in the past few months. Snowflake says most if not all of the victims were not using multifactor authentication.

Advertisem*nt

“The incident was limited to an AT&T workspace on Snowflake’s cloud platform and did not impact AT&T’s network,” the phone company said. It said affected consumers would be notified and provided with resources to help protect their information.

“We sincerely regret this incident occurred,” AT&T said. It did not respond to questions about whether the relevant Snowflake account had two-factor authentication.

AT&T generates so much data, and uses it for so many things, that it is closely watched for the technology it picks. AT&T has boasted in Snowflake marketing material that it cut costs by 84 percent when it moved to Snowflake.

But Snowflake has come under heavy criticism from security experts for denying all responsibility for previous data breaches and being slow to aid customers. Related major breaches hit Ticketmaster and Advance Auto Parts.

Advertisem*nt

Snowflake told The Washington Post on Friday that it was still working on a process that would allow customers to require two-factor authentication.

Previous Snowflake customer data dumps have been offered for sale in online criminal forums, indicating that the hackers making the most of the security weakness have been motivated by money.

In an earlier report, one of the security companies hired by Snowflake, Google Cloud’s Mandiant unit, said the hackers had used log-in credentials initially obtained by what are called infostealers — specialized malware that spirits away sensitive data from corporate or personal devices that have been compromised through other means.

Mandiant said that some of the infected devices had downloaded games or pirated software, a common vector for malware.

The hack marks the latest large-scale security incident for AT&T. In late March, the company disclosed that account information from 73 million current and former customers had been leaked to the dark web.

Advertisem*nt

The incidents underscore the massive reach of one of America’s largest wireless carriers and the vulnerability of calling data. Privacy advocates noted that smartphone apps are less likely to face similar breaches and that some, such as WhatsApp and Signal, offer full end-to-end encryption, meaning that no one can obtain contents of a message unless they have access to a device participating in the conversation.

They also urge consumers to use an app for authenticating themselves to a bank or other service provider, instead of text messages that can be intercepted.

AT&T said “nearly all” of its wireless customers had been affected. An employee speaking on the condition of anonymity for discussing private information said about 110 million wireless customers had data exposed.

Brad Jones, the chief information officer at Snowflake, said the company hasn’t seen evidence that Snowflake itself was breached, though it has confirmed a “targeted threat campaign” against some customers.

“We have not identified evidence suggesting this activity was caused by a vulnerability, misconfiguration, or breach of Snowflake’s platform,” Jones said, adding that this was confirmed by Mandiant and CrowdStrike.

AT&T said the hack wouldn’t be material to its operations or negatively impact its financial results.

AT&T says hackers stole call records of ‘nearly all’ wireless customers (2024)
Top Articles
Nikki Catsouras: A Tragic Tale Of Loss And Privacy Invasion
Nikki Catsouras: A Tragic Tale Behind The Death Photo
Elleypoint
Uca Cheerleading Nationals 2023
Tyson Employee Paperless
COLA Takes Effect With Sept. 30 Benefit Payment
Meer klaarheid bij toewijzing rechter
Google Jobs Denver
What happens if I deposit a bounced check?
What's Wrong with the Chevrolet Tahoe?
Scentsy Dashboard Log In
What Does Dwb Mean In Instagram
Palace Pizza Joplin
Costco Gas Foster City
How pharmacies can help
Curver wasmanden kopen? | Lage prijs
Pickswise Review 2024: Is Pickswise a Trusted Tipster?
18889183540
Babbychula
Highmark Wholecare Otc Store
Aol News Weather Entertainment Local Lifestyle
Morse Road Bmv Hours
Red Cedar Farms Goldendoodle
Shadbase Get Out Of Jail
T Mobile Rival Crossword Clue
Lines Ac And Rs Can Best Be Described As
Prey For The Devil Showtimes Near Ontario Luxe Reel Theatre
D2L Brightspace Clc
When His Eyes Opened Chapter 3123
Schooology Fcps
Craigslist Auburn Al
Best Restaurants Ventnor
Alima Becker
60 Second Burger Run Unblocked
Fox And Friends Mega Morning Deals July 2022
Leland Nc Craigslist
Kips Sunshine Kwik Lube
Dallas City Council Agenda
Pitchfork's Top 200 of the 2010s: 50-1 (clips)
3400 Grams In Pounds
Cranston Sewer Tax
Hireright Applicant Center Login
2007 Jaguar XK Low Miles for sale - Palm Desert, CA - craigslist
Blackwolf Run Pro Shop
Frequently Asked Questions
Dlnet Deltanet
Random Warzone 2 Loadout Generator
Rubmaps H
Campaign Blacksmith Bench
Wwba Baseball
Ark Silica Pearls Gfi
Craigslist Farm And Garden Missoula
Latest Posts
Article information

Author: Roderick King

Last Updated:

Views: 5417

Rating: 4 / 5 (71 voted)

Reviews: 94% of readers found this page helpful

Author information

Name: Roderick King

Birthday: 1997-10-09

Address: 3782 Madge Knoll, East Dudley, MA 63913

Phone: +2521695290067

Job: Customer Sales Coordinator

Hobby: Gunsmithing, Embroidery, Parkour, Kitesurfing, Rock climbing, Sand art, Beekeeping

Introduction: My name is Roderick King, I am a cute, splendid, excited, perfect, gentle, funny, vivacious person who loves writing and wants to share my knowledge and understanding with you.