(Translated by https://www.hiragana.jp/)
AT&T says criminals stole phone records of 'nearly all' customers in new data breach | TechCrunch

Featured Article

AT&T says criminals stole phone records of ‘nearly all’ customers in new data breach

Stolen data includes millions of AT&T customer phone numbers, calling and text records, and location-related data

Comment

a shopper walks past an AT&T sign outside a store in PA.
Image Credits: Mark Makela / Getty Images

U.S. phone giant AT&T confirmed Friday it will begin notifying millions of consumers about a fresh data breach that allowed cybercriminals to steal the phone records of “nearly all” of its customers, a company spokesperson told TechCrunch.

In a statement, AT&T said that the stolen data contains phone numbers of both cellular and landline customers, as well as AT&T records of calls and text messages — such as who contacted who by phone or text — during a six-month period between May 1, 2022 and October 31, 2022. 

AT&T said some of the stolen data includes more recent records from January 2, 2023 for a smaller but unspecified number of customers.

The stolen data also includes call records of customers with phone service from other cell carriers that rely on AT&T’s network, the company said. 

AT&T said the stolen data “does not contain the content of calls or texts,” but does include calling and texting records that an AT&T phone number interacted with during the six-month period, as well as the total count of a customer’s calls and texts, and call durations — information that is often referred to as metadata. The stolen data does not include the time or date of calls or texts, AT&T said.

Some of the stolen records include cell site identification numbers associated with phone calls and text messages, information that can be used to determine the approximate location of where a call was made or text message sent.

In all, the phone giant said it will notify around 110 million AT&T customers of the data breach, company spokesperson Andrea Huguely told TechCrunch. 

AT&T published a website with information for customers about the data incident. AT&T also disclosed the data breach in a filing with regulators before the market opened on Friday.

Breach linked to Snowflake

AT&T said it learned of the data breach on April 19, and that it was unrelated to its earlier security incident in March. 

AT&T’s Huguely told TechCrunch that the most recent compromise of customer records were stolen from the cloud data giant Snowflake during a recent spate of data thefts targeting Snowflake’s customers.

Snowflake allows its corporate customers, like tech companies and telcos, to analyze huge amounts of customer data in the cloud. It’s not clear for what reason AT&T was storing customer data in Snowflake, and the spokesperson would not say.

AT&T is the latest company in recent weeks to confirm it had data stolen from Snowflake, following Ticketmaster and LendingTree subsidiary QuoteWizard, and others.

Snowflake blamed the data thefts on its customers for not using multi-factor authentication to secure their Snowflake accounts, a security feature that the cloud data giant did not enforce or require its customers to use. 

Cybersecurity incident response firm Mandiant, which Snowflake called in to help with notifying customers, later said about 165 Snowflake customers had a “significant volume of data” stolen from their customer accounts

Mandiant attributed the breach to an as-yet-uncategorized cybercriminal group tracked only as UNC5537. Mandiant’s researchers say the hackers are financially motivated and have members in North America and at least one member in Turkey. 

Some of the other corporate victims of the Snowflake account thefts had data subsequently published on known cybercrime forums. For AT&T’s part, the company said that it does not believe that the data is publicly available at this time.

AT&T’s statement said it was working with law enforcement to arrest the cybercriminals involved in the breach. AT&T said that “at least one person has been apprehended.” AT&T’s spokesperson said that the arrested individual was not an AT&T employee, but deferred questions about the alleged criminals to the FBI.

An FBI spokesperson confirmed to TechCrunch on Friday that after the phone giant contacted the agency to report the breach, AT&T, the FBI and the Department of Justice agreed to delay notifying the public and customers on two occasions, citing “potential risks to national security and/or public safety.”

“AT&T, FBI, and DOJ worked collaboratively through the first and second delay process, all while sharing key threat intelligence to bolster FBI investigative equities and to assist AT&T’s incident response work,” the FBI spokesperson said.

The FBI did not comment on the arrest of one of the alleged cybercriminals.

This is the second security incident AT&T has disclosed this year. AT&T was forced to reset the account passcodes of millions of its customers after a cache of customer account information — including encrypted passcodes for accessing AT&T customer accounts — was published on a cybercrime forum. A security researcher told TechCrunch at the time that the encrypted passcodes could be easily decrypted, prompting AT&T to take precautionary action to protect customer accounts.

Read more on TechCrunch:

Updated with comment from the FBI.

More TechCrunch

Note-taking apps typically aim to make you more efficient and productive. A lot of those apps concentrate on quickly jotting down your thoughts, organizing them better, or a mix of…

Napkin is a note-taking app that is not about making you more productive

Here are the startups from YC Demo Day 2 that we thought stood out from the flock.

9 startups that stood out on YC Demo Day 2

UAE-based Redwood has acquired a majority stake in the game streaming platform Loco as the Indian firm looks to expand focus to international markets, TechCrunch has learned and confirmed. Redwood,…

Indian game streaming startup Loco sells majority stake to Redwood

SpaceX’s Starlink satellite internet network is expected to hit a new customer milestone this week, company President Gwynne Shotwell told Texas legislators on Tuesday.  “This week, by the way, we…

Starlink hits 4 million subscribers

AI video generators need to believe that filmmakers will use their models in the production process. Otherwise why exist? To jump-start the new AI film ecosystem, Runway has set aside…

Runway earmarks $5M to fund up to 100 films using AI-generated video

Departures might be dominating the week’s OpenAI-related headlines. But comments on AI bias from Anna Makanju, the company’s VP of global affairs, also grabbed our attention. Makanju, speaking on a…

OpenAI’s VP of global affairs claims o1 is ‘virtually perfect’ at correcting bias, but the data doesn’t quite back that up

Lending startup Figure will be launching an AI tool powered by GPT-4 to help catch errors in lending documents. 

Former Brex COO who now heads unicorn fintech Figure says GPT is already upending the mortgage industry

Drata, a security compliance automation platform that helps companies adhere to frameworks such as SOC 2 and GDPR, has laid off 9% of its workforce, amounting to 40 people. Founded in 2020, Drata integrates…

Security compliance unicorn Drata lays off 9% of its workforce

As OpenAI boasts about its o1 model’s increased thoughtfulness, small, self-funded startup Nomi AI is building the same kind of technology. Unlike the broad generalist ChatGPT, which slows down to…

Nomi’s companion chatbots will now remember things like the colleague you don’t get along with

The company recently closed a $130 million round, according to an SEC filing, bringing the total to $327 million.

Zap Energy investors in recent $130M round included Soros Fund and Laurene Powell Jobs’ Emerson Collective

Welcome back to TechCrunch Mobility — your central hub for news and insights on the future of transportation. Sign up here for free — just click TechCrunch Mobility! I’ve been…

Uber snags another robotaxi deal, aviation startups land VC bucks, and where Rivian Foundation money is going

That lack of user interaction — or request for consent — is what confused and concerned some former Kaspersky customers.

Kaspersky defends force-replacing its security software without users’ explicit consent

The world of WordPress, one of the most popular technologies for creating and hosting websites, is going through a very heated controversy. The core issue is the fight between WordPress…

The WordPress vs. WP Engine drama, explained

Featured Article

Tesla Superchargers: GM, Ford, Rivian, and other EV brands with access

EV owners of GM vehicles like the Chevrolet Silverado EV and Cadillac Lyriq will now officially have access to Tesla’s Superchargers.

Tesla Superchargers: GM, Ford, Rivian, and other EV brands with access

Despite hydrogen’s challenges, BMW thinks the only way to actually achieve a shift to zero-emissions transportation is through a mix of BEVs and hydrogen vehicles.

BMW says we need both battery and hydrogen EVs for a zero-emissions future

Google’s NotebookLM has been updated with YouTube and audio files as new source types and sharable links for Audio Overviews.

Google’s NotebookLM enhances AI note-taking with YouTube, audio file sources, sharable audio discussions

EVA, the platform that connects event bookers with local performers, has secured $2 million in funding as the popularity of in-person events comes back in full force. The round, which…

EVA, an entertainment booking platform for events, raises $2M as it expands to more cities 

The idea here is to bring a subscription-based app in-house to serve as a testing ground for RevenueCat’s new features.

Subscription management platform RevenueCat acquires a ‘spicy’ audiobooks app (??!!)

We’re thrilled to announce that the agenda for our dedicated AI Stage presented by Google Cloud to TechCrunch Disrupt 2024 is complete and ready to go! It joins fintech, SaaS,…

Announcing the final agenda for the AI Stage at TechCrunch Disrupt 2024

Meta Connect 2024 is a developer-centric event featuring a keynote from CEO Mark Zuckerberg. He showcased new hardware and software to support two of Meta’s big ambitions: AI and the…

Meta Connect 2024: Orion glasses, Quest 3S headset, Meta AI upgrades, Ray-Ban Meta real-time video, and more

The health insurance giant is investigating an incident that allegedly leaked sensitive customer medical data.

India’s Star Health says it’s investigating after hacker posts stolen medical data

We’re in the final stretch of Ticket Reboot Week with just 48 hours remaining! You can still save up to $600 on individual ticket types to TechCrunch Disrupt 2024. Don’t…

2 days left to save up to $600 on TechCrunch Disrupt 2024 tickets

A new female-founded dating app called After is launching in Austin, Texas, on Thursday with the mission of tackling ghosting and holding people accountable.  What sets the app apart from…

After is a new dating app that tries to tackle ghosting

The Tor Project is merging operations with Tails, a portable Linux-based operating system focused on preserving user privacy and anonymity.

The Tor Project merges with Tails, a Linux-based portable OS focused on privacy

A company that claims its tech can “revolutionize” emergency calls has raised $27 million in a Series B round led by Andreessen Horowitz. The company, Prepared, enables 911 dispatchers to…

Prepared, which wants to ‘revolutionize’ emergency 911 calls, raises $27M

A new Dealroom report shows that VC investment in defense-related tech is outpacing any other type of investment across NATO member states and allies. 

As war rages in Ukraine, investment in European defense and dual-use tech skyrockets

Peak XV Partners, the largest India-focused venture fund, has realized about $1.2 billion in exits since it separated from Sequoia last year.

Peak XV has reaped $1.2B in the year since it split from Sequoia

WordPress drama went up another notch on Wednesday after WordPress.org banned hosting provider WP Engine from accessing its resources.

WordPress.org bans WP Engine, blocks it from accessing its resources

Marvel Fusion is one of several companies pursuing what’s known as inertial confinement fusion.

Marvel Fusion lands $70M for laser-powered fusion bet

OpenAI’s chief research officer, Bob McGrew, and a research VP, Barret Zoph, left the company on Wednesday, hours after OpenAI CTO Mira Murati announced she would be departing. CEO Sam…

OpenAI’s chief research officer has left following CTO Mira Murati’s exit