NOTE: The list of high-profile victims to which AT&T is being added now includes Advance Auto Parts, Pure Storage, Los Angeles Unified, Neiman Marcus, Ticketmaster, and Banco Santander.
Massive AT&T data breach exposes call logs of 109 million customersBy Bill Toulas
July 12, 2024 09:37 AM
AT&T is warning of a massive data breach where threat actors stole the call logs for approximately 109 million customers, or nearly all of its mobile customers, from an online database on the company's Snowflake account.
The company confirmed to Bleeping Computer that the data was stolen from the Snowflake account between April 14 and April 25, 2024.
In a Friday morning Form 8-K filling with the SEC, AT&T says that the stolen data contains the call and text records of nearly all AT&T mobile clients and customers of mobile virtual network operators (MVNOs) made from May 1 to October 31, 2022 and on January 2, 2023.
The stolen data includes:
- Telephone numbers of AT&T wireline customers and customers of other carriers.
- Telephone numbers with which AT&T or MVNO wireless numbers interacted.
- Count of interactions (e.g., the number of calls or texts).
- Aggregate call duration for a day or month.
- For a subset of records, one or more cell site identification numbers.
The exposed records did not contain the content of the calls or texts, customer names, or any other personal information such as Social Security numbers or dates of birth.
Although the accessed logs do not contain sensitive information that directly exposes customer identities, the communications metadata can be used to correlate them with publicly available information and easily derive identities in many cases.
Although the accessed logs do not contain sensitive information that directly exposes customer identities, the communications metadata can be used to correlate them with publicly available information and easily derive identities in many cases.
"The FBI prioritizes assistance to victims of cyber-attacks, encourages organizations to establish a relationship with their local FBI field office in advance of a cyber incident, and to contact the FBI early in the event of breach."
- AT&T is working with law enforcement to arrest those involved and states that they understand at least one person has already been apprehended.
- AT&T said it has implemented additional cybersecurity measures to block unauthorized access attempts in the future, and it promised to notify current and former customers impacted by this incident soon.
Meanwhile, AT&T customers can follow the links provided on this FAQ page to check if their phone number's data was exposed and to download the data associated with their number that was stolen.
- As of today, AT&T says it has no evidence the accessed data has been made publicly available and says the incident is not related to the 2021 data breach AT&T confirmed earlier this year impacted 51 million customers. . .
- AT&T is working with law enforcement to arrest those involved and states that they understand at least one person has already been apprehended.
- AT&T said it has implemented additional cybersecurity measures to block unauthorized access attempts in the future, and it promised to notify current and former customers impacted by this incident soon.
Meanwhile, AT&T customers can follow the links provided on this FAQ page to check if their phone number's data was exposed and to download the data associated with their number that was stolen.
- As of today, AT&T says it has no evidence the accessed data has been made publicly available and says the incident is not related to the 2021 data breach AT&T confirmed earlier this year impacted 51 million customers. . .
More details >
No comments:
Post a Comment