AT&T notifies about 9 million customers after marketing vendor breach

Organization
AT&T
Exploit
Third-Party Data Breach
Industry
Telecommunications

AT&T began notifying roughly 9 million wireless customers in March 2023 that some of their account information had been exposed when a marketing vendor was hacked in January 2023. The carrier did not identify the vendor, which it said handled personalized video content such as billing and marketing videos.

The exposed records fell under Customer Proprietary Network Information, a category of subscriber data that US carriers are required to protect under Federal Communications Commission rules. AT&T said the affected fields included customer first names, wireless account numbers, wireless phone numbers and email addresses. A smaller group of customers also had rate plan names, past due amounts, monthly payment amounts, various charges and minutes used exposed.

The company said credit card numbers, Social Security numbers, account passwords and other sensitive personal data were not involved, and that its own systems were not compromised. AT&T described the affected information as several years old and said the unauthorized access had been shut off.

AT&T notified federal law enforcement as required by FCC rules and told affected customers they could submit a CPNI restriction request to limit how their data is shared with third-party vendors in future. According to SecurityWeek, the 9 million accounts represented a small share of AT&T's roughly 200 million customers.

Updates

  1. The FCC announced a 13 million dollar settlement with AT&T over this vendor breach. The consent decree also requires AT&T to strengthen its data governance and supply chain controls and to ensure vendors return or destroy customer data as contracted.

Sources