{"id":242928,"date":"2024-07-13T04:14:41","date_gmt":"2024-07-13T04:14:41","guid":{"rendered":"https:\/\/michigandigitalnews.com\/index.php\/2024\/07\/13\/massive-att-data-breach-impacted-nearly-every-single-customer\/"},"modified":"2025-06-25T17:14:48","modified_gmt":"2025-06-25T17:14:48","slug":"massive-att-data-breach-impacted-nearly-every-single-customer","status":"publish","type":"post","link":"https:\/\/michigandigitalnews.com\/index.php\/2024\/07\/13\/massive-att-data-breach-impacted-nearly-every-single-customer\/","title":{"rendered":"Massive AT&#038;T data breach impacted nearly every single customer"},"content":{"rendered":"<p> [ad_1]<br \/>\n<\/p>\n<div>\n<p>AT&amp;T just confirmed a massive data breach in 2022 that impacted \u201cnearly all\u201d of its customers, according to a <a data-i13n=\"cpos:1;pos:1\" href=\"https:\/\/techcrunch.com\/2024\/07\/12\/att-phone-records-stolen-data-breach\/\" data-ylk=\"slk:statement provided by TechCrunch;cpos:1;pos:1;elm:context_link;itc:0;sec:content-canvas\" class=\"link \"><em><\/em><\/a>. The company had over 110 million wireless subscribers in 2022 so, yeah, this is kind of a big deal.<\/p>\n<p>The data breach allowed hackers to steal phone numbers, text data and phone records from these people which, once again, comprises nearly the entire customer base, myself included. AT&amp;T says it will begin notifying consumers about the breach in the near future, committing to informing the 110 impacted million customers. The breach occurred during a six-month period from May 1, 2022 to October 31, 2022, though it looks like some data kept getting stolen up until January 2, 2023. This latter breach impacts a smaller, though unspecified, number of consumers.<\/p>\n<p>Now, before you start worrying about that embarrassing text you sent an ex back in 2022, AT&amp;T says the breach \u201cdoes not contain the content of calls or texts.\u201d However, it does include the phone numbers that an account interacted with, as well as a complete count of a customer\u2019s calls, texts and call durations, otherwise known as metadata. The time and date of the calls or texts were not included in the hack, according to AT&amp;T.<\/p>\n<p>However, the breach did include cell site identification numbers, which could \u201cpotentially allow for the triangulation of users&#8217; locations,\u201d wrote Javvad Malik, a representative from cybersecurity awareness firm <a data-i13n=\"cpos:2;pos:1\" href=\"https:\/\/www.knowbe4.com\/\" rel=\"nofollow noopener\" target=\"_blank\" data-ylk=\"slk:KnowBe4;cpos:2;pos:1;elm:context_link;itc:0;sec:content-canvas\" class=\"link \"><\/a>, in a statement to Engadget. Malik also painted a grim picture of what could be done with the stolen metadata, writing that it \u201ccan paint a detailed picture of an individual&#8217;s daily life, habits, and associations, making it a valuable asset for those with malicious intent.\u201d<\/p>\n<p>AT&amp;T has <a data-i13n=\"elm:affiliate_link;sellerN:AT&amp;T;elmt:;cpos:3;pos:1\" href=\"https:\/\/shopping.yahoo.com\/rdlw?merchantId=4ebb60ff-ff59-4606-b92b-d2b184542aa9&amp;siteId=us-engadget&amp;pageId=1p-autolink&amp;featureId=text-link&amp;merchantName=AT%26T&amp;custData=eyJzb3VyY2VOYW1lIjoiV2ViLURlc2t0b3AtVmVyaXpvbiIsImxhbmRpbmdVcmwiOiJodHRwczovL3d3dy5hdHQuY29tL3N1cHBvcnQvYXJ0aWNsZS9teS1hY2NvdW50LzAwMDEwMjk3OSIsImNvbnRlbnRVdWlkIjoiMDQ3MDkxMDAtZmJlOC00MDcxLWFiNDEtZDZhNzAwODExMDI0In0&amp;signature=AQAAAcsjRL9WaWtYYrHCkpUCo6tUIPGVS_cw7MQktn48vhmz&amp;gcReferrer=https%3A%2F%2Fwww.att.com%2Fsupport%2Farticle%2Fmy-account%2F000102979\" class=\"link  rapid-with-clickid etailiffa-link\" rel=\"nofollow noopener\" target=\"_blank\" data-ylk=\"slk:published a website;elm:affiliate_link;sellerN:AT&amp;T;elmt:;cpos:3;pos:1;itc:0;sec:content-canvas\"><\/a> with information for customers about the breach and has disclosed the hack <a data-i13n=\"cpos:4;pos:1\" href=\"https:\/\/www.sec.gov\/ix?doc=\/Archives\/edgar\/data\/0000732717\/000073271724000046\/t-20240506.htm\" rel=\"nofollow noopener\" target=\"_blank\" data-ylk=\"slk:in a regulatory filing;cpos:4;pos:1;elm:context_link;itc:0;sec:content-canvas\" class=\"link \"><\/a> issued before the market opened on Friday, July 12. The company says it learned of the issue on April 19 and that it has nothing to do with a <a data-i13n=\"cpos:5;pos:1\" href=\"https:\/\/www.engadget.com\/att-resets-millions-of-customers-passcodes-after-account-info-was-leaked-on-the-dark-web-160842651.html\" data-ylk=\"slk:previous security incident from March;cpos:5;pos:1;elm:context_link;itc:0;sec:content-canvas\" class=\"link \"><\/a>, in which customer data was published on the dark web.<\/p>\n<p>So how did this happen? AT&amp;T places the blame on its cloud data partner Snowflake, saying that the compromise occurred after hacks targeted its business customers. Snowflake allows corporate customers to store large amounts of customer data in the cloud for the purpose of analysis. AT&amp;T hasn\u2019t stated any reason as to why it would want to analyze massive amounts of customer data or why it would store this data with Snowflake. A company representative declined to provide further information to <em>TechCrunch<\/em>.<\/p>\n<p>One thing is certain. AT&amp;T isn\u2019t the only company recently burned by a Snowflake hack. Other impacted companies include Ticketmaster and QuoteWizard, among more than 160 others. Snowflake, for its part, has shifted the blame back to AT&amp;T and the others, saying that each organization didn\u2019t use multi-factor authentication to secure their accounts. So, all 160+ companies forgot to turn on multi-factor authentication? You\u2019d think something like that would be mandatory when dealing with massive amounts of customer data but, well, I guess not.<\/p>\n<p>The breach has been tracked back to an uncategorized cybercriminal group known only as UNC5537, according to <a data-i13n=\"cpos:6;pos:1\" href=\"https:\/\/duo.com\/decipher\/mandiant-165-snowflake-customers-potentially-exposed-in-wider-campaign\" rel=\"nofollow noopener\" target=\"_blank\" data-ylk=\"slk:cybersecurity incident response firm Mandiant;cpos:6;pos:1;elm:context_link;itc:0;sec:content-canvas\" class=\"link \"><\/a>. That company suggests financial motivations behind the hack.<\/p>\n<p>Despite the breach, AT&amp;T says that the stolen data isn\u2019t publicly available at this time. It\u2019s currently working with law enforcement and says that \u201cat least one person has been apprehended.\u201d<\/p>\n<p>This article contains affiliate links; if you click such a link and make a purchase, we may earn a commission.<\/p>\n<\/div>\n<p>[ad_2]<br \/>\n<br \/><a href=\"https:\/\/www.engadget.com\/massive-att-data-breach-impacted-nearly-every-single-customer-155346341.html?src=rss\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[ad_1] AT&amp;T just confirmed a massive data breach in 2022 that impacted \u201cnearly all\u201d of its customers, according to a . The company had over<\/p>\n","protected":false},"author":1,"featured_media":242929,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"footnotes":""},"categories":[159],"tags":[],"_links":{"self":[{"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/posts\/242928"}],"collection":[{"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/comments?post=242928"}],"version-history":[{"count":0,"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/posts\/242928\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/media\/242929"}],"wp:attachment":[{"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/media?parent=242928"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/categories?post=242928"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/michigandigitalnews.com\/index.php\/wp-json\/wp\/v2\/tags?post=242928"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}