AT&T Confirms Data Breach Affecting Nearly All Wireless Customers

Share:

American telecom service provider AT&T has confirmed that threat actors managed to access data belonging to “nearly all” of its wireless customers as well as customers of mobile virtual network operators (MVNOs) using AT&T’s wireless network.

“Threat actors unlawfully accessed an AT&T workspace on a third-party cloud platform and, between April 14 and April 25, 2024, exfiltrated files containing AT&T records of customer call and text interactions that occurred between approximately May 1 and October 31, 2022, as well as on January 2, 2023,” it said.

This comprises telephone numbers with which an AT&T or MVNO wireless number interacted – including telephone numbers of AT&T landline customers and customers of other carriers, counts of those interactions, and aggregate call duration for a day or month.

A subset of these records also contained one or more cell site identification numbers, potentially allowing the threat actors to triangulate the approximate location of a customer when a call was made or a text message was sent. AT&T said it will alert current and former customers if their information was involved.

Cybersecurity
“The threat actors have used data from previous compromises to map phone numbers to identities,” Jake Williams, former NSA hacker and faculty at IANS Research, said. “What the threat actors stole here are effectively call data records (CDR), which are a gold mine in intelligence analysis because they can be used to understand who is talking to who — and when.”

AT&T’s list of MVNOs includes Black Wireless, Boost Infinite, Consumer Cellular, Cricket Wireless, FreedomPop, FreeUp Mobile, Good2Go, H2O Wireless, PureTalk, Red Pocket, Straight Talk Wireless, TracFone Wireless, Unreal Mobile, and Wing.

The name of the third-party cloud provider was not disclosed by AT&T, but Snowflake has since confirmed that the breach was connected to the hack that’s impacted other customers, such as Ticketmaster, Santander, Neiman Marcus, and LendingTree, according to Bloomberg.

The company said it became aware of the incident on April 19, 2024, and immediately activated its response efforts. It further noted that it’s working with law enforcement in their efforts to arrest those involved, and that “at least one person has been apprehended.”

404 Media reported that a 24-year-old U.S. citizen named John Binns, who was previously arrested in Turkey in May 2024, is connected to the security event, citing three unnamed sources. He was also indicted in the U.S. for infiltrating T-Mobile in 2021 and selling its customer data.

However, AT&T emphasized that the accessed information does not include the content of calls or texts, personal information such as Social Security numbers, dates of birth, or other personally identifiable information.

“While the data does not include customer names, there are often ways, using publicly available online tools, to find the name associated with a specific telephone number,” it said in a Form 8-K filing with the U.S. Securities and Exchange Commission (SEC).

It’s also urging users to be on the lookout for phishing, smishing, and online fraud by only opening text messages from trusted senders. On top of that, customers can submit a request to get the phone numbers of their calls and texts in the illegally downloaded data.

Cybersecurity
The malicious cyber campaign targeting Snowflake has landed as many as 165 customers in the crosshairs, with Google-owned Mandiant attributing the activity to a financially motivated threat actor dubbed UNC5537 that encompasses “members based in North America, and collaborates with an additional member in Turkey.”

The criminals have demanded payments of between $300,000 and $5 million in return for the stolen data. The latest development shows that the fallout from the cybercrime spree is expanding in scope and has had a cascading effect.

WIRED revealed last month how the hackers behind the data thefts and extortion attacks procured’ stolen Snowflake credentials from dark web services that sell access to usernames, passwords, and authentication tokens that are captured by stealer malware. This included obtaining access through a third-party contractor named EPAM Systems.

For its part, Snowflake this week announced that administrators can now enforce mandatory multi-factor authentication (MFA) for all users to mitigate the risk of account takeovers. It also said it will soon require MFA for all users in newly created Snowflake accounts.

Update#
AT&T has reportedly paid the threat actors behind the breach $370,000 in cryptocurrency to delete what’s believed to be the “only copy” of the data and provide a video demonstrating proof of deletion, according to WIRED.

The ransom amount is believed to have been paid back in May, according to a member of the notorious ShinyHunters hacking group that has claimed responsibility for the incident by exploiting unsecured Snowflake storage accounts.

The U.S. Federal Communications Commission (FCC) said it has “an ongoing investigation into the AT&T breach and we’re coordinating with our law enforcement partners.”

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
7:53 am, Feb 1, 2025
weather icon 5°C
L: 4° | H: 5°
overcast clouds
Humidity: 89 %
Pressure: 1030 mb
Wind: 7 mph ESE
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 7:38 am
Sunset: 4:49 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
4° | 5°°C 0 mm 0% 6 mph 89 % 1030 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
2° | 7°°C 0 mm 0% 6 mph 84 % 1025 mb 0 mm/h
Mon Feb 03 9:00 pm
weather icon
2° | 9°°C 0 mm 0% 5 mph 85 % 1026 mb 0 mm/h
Tue Feb 04 9:00 pm
weather icon
4° | 9°°C 1 mm 100% 12 mph 93 % 1026 mb 0 mm/h
Wed Feb 05 9:00 pm
weather icon
4° | 8°°C 0.8 mm 80% 9 mph 91 % 1046 mb 0 mm/h
Today 9:00 am
weather icon
5° | 5°°C 0 mm 0% 4 mph 89 % 1030 mb 0 mm/h
Today 12:00 pm
weather icon
5° | 6°°C 0 mm 0% 6 mph 83 % 1030 mb 0 mm/h
Today 3:00 pm
weather icon
6° | 6°°C 0 mm 0% 6 mph 76 % 1029 mb 0 mm/h
Today 6:00 pm
weather icon
5° | 5°°C 0 mm 0% 6 mph 79 % 1027 mb 0 mm/h
Today 9:00 pm
weather icon
3° | 3°°C 0 mm 0% 4 mph 85 % 1026 mb 0 mm/h
Tomorrow 12:00 am
weather icon
3° | 3°°C 0 mm 0% 5 mph 84 % 1024 mb 0 mm/h
Tomorrow 3:00 am
weather icon
2° | 2°°C 0 mm 0% 4 mph 83 % 1023 mb 0 mm/h
Tomorrow 6:00 am
weather icon
2° | 2°°C 0 mm 0% 4 mph 82 % 1022 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€98,623.92
-1.85%
Ethereum(ETH)
€3,169.96
1.21%
XRP(XRP)
€2.93
-1.22%
Tether(USDT)
€0.97
-0.02%
Solana(SOL)
€222.32
-2.52%
USDC(USDC)
€0.97
-0.01%
Dogecoin(DOGE)
€0.315190
-0.44%
Shiba Inu(SHIB)
€0.000018
1.64%
Pepe(PEPE)
€0.000014
4.72%
Scroll to Top