From focused wiretaps to bulk surveillance dragnets, telephone firms have been at the middle of privateness considerations for many years—and their time in the limelight is not over but. On Friday, telecom big AT&T introduced that it not too long ago suffered an information breach impacting name and textual content messaging information of “almost all” its prospects. The firm is in the course of of notifying about 110 million those that they had been affected.
AT&T stated in a US Securities and Exchange Commission submitting that it realized about the knowledge breach on April 19. Attackers exfiltrated knowledge between April 14 and April 25. The firm stated in its SEC submission that the US Justice Department approved delayed disclosure of the breach on May 9 and once more on June 5, pending investigation. AT&T added that it’s “working with regulation enforcement in its efforts to arrest these concerned in the incident.” So far, “not less than one individual has been apprehended.”
“Yeah, that is actually unhealthy,” says Jake Williams, vp of analysis and improvement at the cybersecurity consultancy Hunter Strategy. “What the risk actors stole listed here are primarily name knowledge information. These are a gold mine in intelligence evaluation as a result of they permit somebody to grasp networks—who’s speaking to whom and when. And risk actors have knowledge from earlier compromises to map telephone numbers to identities. But even with out figuring out knowledge for a telephone quantity, closed networks—the place numbers solely talk with others in the identical community—are nearly at all times fascinating.”
The incident is important not solely as a result of of its sheer scale and attain however as a result of AT&T says it’s the newest in a staggering spate of knowledge thefts that resulted from attackers compromising organizations’ Snowflake cloud accounts. Snowflake is an information warehousing platform, and attackers collected its prospects’ account credentials in latest months to steal lots of of hundreds of thousands of information from about 165 Snowflake purchasers, together with Ticketmaster, Santander financial institution, and LendingTree’s QuoteWizard.
The AT&T knowledge is from each landline and mobile accounts and spans May 1, 2022, to October 31, 2022. A smaller, undisclosed quantity of folks additionally had information from January 2, 2023, stolen in the breach. The firm stated on Friday that the knowledge trove “doesn’t comprise the content material of calls or texts” and doesn’t embody the date and time of communications. But attackers did make off with telephone numbers and an enormous quantity of so-called “metadata” about calls and texts, together with who contacted whom, name durations, and tallies of a buyer’s whole calls and texts. The trove additionally contains some cell web site identification numbers—primarily cell tower knowledge that can be utilized to approximate a cellphone’s location when it made or acquired a name or textual content.
The knowledge contains some information of people who find themselves prospects of telephone carriers—often called “cellular digital community operators”—that contract with AT&T to make use of the bigger firm’s networks and infrastructure for his or her service. And, crucially, the stolen trove exposes individuals who don’t have any relationship with AT&T after they communicated with an AT&T buyer throughout the related time spans.



