AT&T says criminals stole phone records of 'nearly all' customers in new data breach | TechCrunch (2024)

U.S. phone giant AT&T confirmed Friday it will begin notifying millions of consumers about a fresh data breach that allowed cybercriminals to steal the phone records of “nearly all” of its customers, a company spokesperson told TechCrunch.

In a statement, AT&T said that the stolen data contains phone numbers of both cellular and landline customers, as well as AT&T records of calls and text messages — such as who contacted who by phone or text — during a six-month period between May 1, 2022 and October 31, 2022.

AT&T said some of the stolen data includes more recent records from January 2, 2023 for a smaller but unspecified number of customers.

The stolen data also includes call records of customers with phone service from other cell carriers that rely on AT&T’s network, the company said.

AT&T said the stolen data “does not contain the content of calls or texts,” but does include calling and texting records that an AT&T phone number interacted with during the six-month period, as well as the total count of a customer’s calls and texts, and call durations — information that is often referred to as metadata. The stolen data does not include the time or date of calls or texts, AT&T said.

Some of the stolen records include cell site identification numbers associated with phone calls and text messages, information that can be used to determine the approximate location of where a call was made or text message sent.

In all, the phone giant said it will notify around 110 million AT&T customers of the data breach, company spokesperson Andrea Huguely told TechCrunch.

AT&T published a website with information for customers about the data incident. AT&T also disclosed the data breach in a filing with regulators before the market opened on Friday.

Breach linked to Snowflake

AT&T said it learned of the data breach on April 19, and that it was unrelated to its earlier security incident in March.

AT&T’s Huguely told TechCrunch that the most recent compromise of customer records were stolen from the cloud data giant Snowflake during a recent spate of data thefts targeting Snowflake’s customers.

Snowflake allows its corporate customers, like tech companies and telcos, to analyze huge amounts of customer data in the cloud. It’s not clear for what reason AT&T was storing customer data in Snowflake, and the spokesperson would not say.

AT&T is the latest company in recent weeks to confirm it had data stolen from Snowflake, following Ticketmaster and LendingTree subsidiary QuoteWizard, and others.

Snowflake blamed the data thefts on its customers for not using multi-factor authentication to secure their Snowflake accounts, a security feature that the cloud data giant did not enforce or require its customers to use.

Cybersecurity incident response firm Mandiant, which Snowflake called in to help with notifying customers, later said about 165 Snowflake customers had a “significant volume of data” stolen from their customer accounts.

Mandiant attributed the breach to an as-yet-uncategorized cybercriminal group tracked only as UNC5537. Mandiant’s researchers say the hackers are financially motivated and have members in North America and at least one member in Turkey.

Some of the other corporate victims of the Snowflake account thefts had data subsequently published on known cybercrime forums. For AT&T’s part, the company said that it does not believe that the data is publicly available at this time.

AT&T’s statement said it was working with law enforcement to arrest the cybercriminals involved in the breach. AT&T said that “at least one person has been apprehended.” AT&T’s spokesperson said that the arrested individual was not an AT&T employee, but deferred questions about the alleged criminals to the FBI.

An FBI spokesperson confirmed to TechCrunch on Friday that after the phone giant contacted the agency to report the breach, AT&T, the FBI and the Department of Justice agreed to delay notifying the public and customers on two occasions, citing “potential risks to national security and/or public safety.”

“AT&T, FBI, and DOJ worked collaboratively through the first and second delay process, all while sharing key threat intelligence to bolster FBI investigative equities and to assist AT&T’s incident response work,” the FBI spokesperson said.

The FBI did not comment on the arrest of one of the alleged cybercriminals.

This is . AT&T was forced to reset the account passcodes of millions of its customers after a cache of customer account information — including encrypted passcodes for accessing AT&T customer accounts — was published on a cybercrime forum. A security researcher told TechCrunch at the time that the encrypted passcodes could be easily decrypted, prompting AT&T to take precautionary action to protect customer accounts.

Read more on TechCrunch:

  • Data breach exposes millions of mSpy spyware customers
  • Apple warns iPhone users in 98 countries of spyware attacks
  • Evolve Bank says ransomware gang stole personal data on millions of customers
  • OpenAI breach is a reminder that AI companies are treasure troves for hackers

Updated with comment from the FBI.

AT&T says criminals stole phone records of 'nearly all' customers in new data breach | TechCrunch (2024)

FAQs

What data was stolen from AT&T? ›

That stolen data may have included customers' names, addresses, social security numbers, passcodes, email addresses, phone numbers, dates of birth and AT&T account numbers. According to the Texas attorney general's data breach report site, 7.6 million Texans were affected by the March breach.

Was AT&T hacked in 2024? ›

On Friday July 12, AT&T disclosed that the phone records of almost all current and former AT&T customers were stolen by hackers in April 2024 (AT&T notified the SEC at that time, at which point the US Department of Justice determined a delay in making the breach public was warranted).

What information is stolen in a data breach? ›

A data breach occurs when confidential and sensitive information is stolen by an unauthorized group or individual. Data breaches are one of the end goals of many cyberattacks.

What does AT&T do about stolen phones? ›

Report the claim within 60 days of the date of loss. If your device was lost or stolen, please contact AT&T Customer Care at 866. MOBILITY to temporarily suspend service and prevent unauthorized use. A non-refundable deductible will be charged to your wireless bill following each approved claim.

How do I know if my info was in a data breach? ›

2. Check data breach websites. One of the best ways to check if you have been hacked is to enter your email into a number of data breach websites that track breaches and verify them as genuine. The websites will tell you if your email and associated passwords were part of any known data breaches.

Is AT&T getting hacked? ›

The company announced Friday that nearly all of its mobile phone customers' information was exposed over the course of months in 2022. The data stolen includes “records of calls and texts of nearly all of AT&T's cellular customers,” AT&T said in a statement.

What is the major data breach in 2024? ›

Records Breached: 49 million

In May 2024, Dell was hit with a massive cyberattack that could affect their 49 million customers. Menelik, the threat actor behind the attack, openly revealed to TechCrunch that he extracted large amounts of data by setting up partner accounts within Dell's company portal.

How do I file a claim with AT&T settlement? ›

Consumers can contact the claims administrator by calling 1-877-654-1982 or emailing info@ATTDataThrottling.com if they have questions or if they would like to request a claim form.

Can someone steal your phone data? ›

Phone hacking can range from stealing personal details to listening in on phone conversations. There are several ways someone can hack a phone, including using phishing attacks, tracking software, and unsecured Wi-Fi networks.

What information do hackers need to steal your identity? ›

Identity theft is the act of stealing a victim's Personal Identifying Information (PII), which could include name, address, Social Security number, or other identifying numbers such as medical insurance or credit card accounts.

What are my rights if my data has been breached? ›

To address any harm you endured, the law gives you the right to seek financial compensation following a data breach. You can and should seek legal recourse from a company that exposed your data, and you can file a lawsuit to obtain payment for your losses.

Should you change your phone number after a data breach? ›

If you've experienced identity theft — or had your phone stolen — you should probably change your phone number. It's a massive inconvenience, but the pros will outweigh the cons. Let's understand why. Most people upgrade their smartphone every two years — especially if they're on a contract plan.

Should I be worried about a data breach? ›

A data breach affects you in several ways. It increases your chances of becoming a victim of identity or financial theft. Hackers can use a leaked password to access other accounts that have the same password. It can take some effort to recover from getting hacked online.

Who do I contact if my data has been breached? ›

If you find that someone is using your information to commit fraud, identitytheft.gov can help you report that, too. Find out how to recover from a data breach at identitytheft.gov/databreach.

Why am I getting a data warning from AT&T? ›

Our internet plans

All plans come with a data allowance for each bill period. You'll get an email alert when you use 65%, 90%, and 100% of your monthly data allowance.

What data does AT&T collect? ›

The Personal Information We Collect and Purpose for Collection
CategoriesExamplesCollected or created
IdentifiersName, postal address, email address, account name, Social Security number, driver's license number, passport number, taxpayer identification number, IP address, device IDsCollected
9 more rows

Does AT&T track data history? ›

We automatically collect a variety of information which may include time spent on websites or apps, website and IP addresses and advertising IDs. It also can include links and ads seen, videos watched, search terms entered and items placed in online AT&T shopping carts.

What was AT&T broken up into? ›

The breakup of the Bell System resulted in the creation of seven independent companies that were formed from the original twenty-two AT&T-controlled members of the System. On January 1, 1984, these companies were NYNEX, Pacific Telesis, Ameritech, Bell Atlantic, Southwestern Bell Corporation, BellSouth, and US West.

Top Articles
Latest Posts
Article information

Author: Rueben Jacobs

Last Updated:

Views: 6183

Rating: 4.7 / 5 (77 voted)

Reviews: 92% of readers found this page helpful

Author information

Name: Rueben Jacobs

Birthday: 1999-03-14

Address: 951 Caterina Walk, Schambergerside, CA 67667-0896

Phone: +6881806848632

Job: Internal Education Planner

Hobby: Candle making, Cabaret, Poi, Gambling, Rock climbing, Wood carving, Computer programming

Introduction: My name is Rueben Jacobs, I am a cooperative, beautiful, kind, comfortable, glamorous, open, magnificent person who loves writing and wants to share my knowledge and understanding with you.