
BY MICHELLE CHAPMAN
The data of nearly all customers of the telecommunications giant AT&T was downloaded to a third-party platform in a security breach, the company said Friday, as cyberattacks against businesses, schools and health systems continue to spread globally.
The breach, most of which took place over five months in 2022, hit customers of AT&T’s cellular customers, customers of mobile virtual network operators using AT&T’s wireless network, as well as its landline customers who interacted with those cellular numbers.
Approximately 109 million customer accounts were impacted, according to AT&T, which said that it currently doesn’t believe that the data is publicly available.
“The data does not contain the content of calls or texts, personal information such as Social Security numbers, dates of birth, or other personally identifiable information,” AT&T said Friday.
Cyber security experts concurred, saying that such data can be used to trace users.
“While the information that was exposed doesn’t directly have sensitive information, it can be used to piece together events and who may be calling who. This could impact people’s private lives as private calls and connections could be exposed,” Thomas Richards, principal consultant at Synopsys Software Integrity Group, said in an emailed statement. “The business phone numbers will be easy to identify and private numbers can be matched to names with public record searches.”
An internal investigation determined that compromised data includes AT&T records of calls and texts between May 1, 2022, and Oct. 31, 2022.
Cyber security experts say the sheer volume of data held by companies on cloud platforms can create its own perils.
“The AT&T data breach underscores the growing risks associated with the vast amounts of data companies now store on cloud and SaaS platforms,” said Roei Sherman, Field Chief Technology Officer at Mitiga, a threat detection and investigation company that focuses on cloud technology. “As organizations increasingly rely on these technologies, the complexity of detecting and investigating breaches has risen sharply.”
AT&T’s investigation is ongoing and it has engaged with cybersecurity experts to understand the nature and scope of the criminal breach. At least one person has been apprehended so far, according to the company.
Compromised data also includes records from Jan. 2, 2023, for a very small number of customers. The records identify the telephone numbers an AT&T or MVNO cellular number interacted with during these periods. For a subset of records, one or more cell site identification number(s) associated with the interactions are also included.
The Department of Justice said Friday that it became aware of the breach early this year, but that it met the security standard for a delayed filing by AT&T with the U.S. Securities & Exchange Commission, a filing that was made public Friday.
The DOJ said an earlier disclosure of the breach would “pose a substantial risk to national security and public safety.”
The Federal Communications Commission is also investigating.
The year has already been marked by several major data breaches, including an earlier attack on AT&T. In March AT&T said that a dataset found on the “dark web” contained information such as Social Security numbers for about 7.6 million current AT&T account holders and 65.4 million former account holders.
Alabama’s education superintendent said earlier this month that some data was “breached” during a hacking attempt at the Alabama State Department of Education.
Cybersecurity experts are warning that hospital systems around the country, which have already been targeted, are at risk for more attacks and that the U.S. government is doing too little to prevent breaches.
AT&T customers can visit att.com/DataIncident for more information.
Shares of AT&T Inc., based in Dallas, fell slightly on Friday.
Disclaimer
The information contained in South Florida Reporter is for general information purposes only.
The South Florida Reporter assumes no responsibility for errors or omissions in the contents of the Service.
In no event shall the South Florida Reporter be liable for any special, direct, indirect, consequential, or incidental damages or any damages whatsoever, whether in an action of contract, negligence or other tort, arising out of or in connection with the use of the Service or the contents of the Service. The Company reserves the right to make additions, deletions, or modifications to the contents of the Service at any time without prior notice.
The Company does not warrant that the Service is free of viruses or other harmful components