AT&T has disclosed a massive breach which has compromised records of over 100 million cellular customers’ calls and texts. The breach was caused by an illegal download from a cloud partner, Snowflake, a platform that allows corporate customers to store large amounts of customer data in the cloud for the purpose of analysis.
A hacker stole records of calls and texts from nearly all of the telecom company's wireless customers. TWILIO's 33 Million accounts, two-step verification, APIs and 2FA keys were stolen too. The breach has been traced back to an uncategorized cybercriminal group known only as UNC5537 with possible financial motivations, according to cybersecurity incident response firm Mandiant.
The stolen data isn’t publicly available at this time, according to AT&T. The company is currently working with law enforcement and says that “at least one person has been apprehended.”
The hack occurred mainly from May 1, 2022 to October 31, 2022, and continued in some form up until January 2, 2023. Hackers in April 14-25, 2024, also accessed and copied customer call logs from Snowflake.
The breach included cell site identification numbers, which could potentially allow for the triangulation of users' locations, according to cybersecurity experts. This can paint a detailed picture of an individual's daily life, habits, and associations, making it a valuable asset for those with malicious intent.”
The Snowflake hack impacted more than 160 other companies, including Ticketmaster and QuoteWizard.
Snowflake, for its part, blames AT&T and the others, saying that each organization didn’t use multi-factor authentication to secure their accounts.
AT&T disclosed the hack in a regulatory filing issued before the market opened on Friday, July 12. The company has published a website with information for customers about the breach; and says it learned of the issue on April 19. The latest breach has nothing to do with a previous security incident from March, in which customer data was published on the dark web, according to the company.