AT&T discloses theft of call and text records for nearly all wireless customers

Organization
AT&T
Exploit
Credential Compromise
Industry
Telecommunications

AT&T disclosed in a Form 8-K filed with the U.S. Securities and Exchange Commission on 12 July 2024 that attackers had downloaded call and text message records belonging to nearly all of its wireless customers, a group reported at roughly 109 to 110 million people. The records came from AT&T's workspace on Snowflake, a third-party cloud data platform, in an intrusion the company dated to 14 to 25 April 2024. AT&T said it learned of the problem on 19 April.

The stolen files were metadata rather than content. They recorded which phone numbers a customer interacted with, how often and for how long in aggregate, and for a subset of records they included cell site identification numbers that can indicate approximate location. The data covered 1 May to 31 October 2022, plus a smaller set from 2 January 2023. AT&T said call and message content, names and Social Security numbers were not involved.

The breach was part of a wider campaign against Snowflake customer accounts. Mandiant attributed it to credentials harvested by infostealer malware on systems outside Snowflake, noting that the affected accounts were not protected by multifactor authentication.

AT&T said it closed the unauthorized access point, engaged outside investigators and worked with the FBI and Justice Department, which granted disclosure delays on 9 May and 5 June citing national security and public safety risks. At least one person had been apprehended. WIRED and Bloomberg later reported that AT&T paid about $370,000 in bitcoin in May to have the stolen data deleted, a payment the company declined to comment on.

Sources