Frontier Communications disclosed April 2024 breach of its IT environment
- Organization
- Frontier Communications Parent, Inc.
- Exploit
- Hacking
- Industry
- Telecommunications
Frontier Communications Parent, Inc. reported in a Form 8-K filed with the U.S. Securities and Exchange Commission on April 18, 2024 that it had detected a third party with unauthorized access to portions of its information technology environment four days earlier, on April 14.
The company said it activated its established incident response protocols and took containment steps that included shutting down certain systems. Those shutdowns, it told the SEC, "resulted in an operational disruption that could be considered material." Customers reported service problems while the systems were offline.
Frontier said its investigation indicated the intruder was "likely a cybercrime group, which gained access to, among other information, personally identifiable information." It did not say at the time how many people were affected or which data elements were involved. As of the filing date the company believed the incident was contained, said it had restored its core IT environment and was returning to normal business operations, and said it had engaged cybersecurity experts and notified law enforcement. It did not expect a material effect on its financial condition or results.
The scale became clearer later. SecurityWeek reported in June 2024 that the RansomHub group claimed the attack and said it held 5GB of data on more than two million customers, including names, addresses, dates of birth, phone numbers, email addresses, Social Security numbers and credit scores. Frontier did not confirm those figures.