AT&T—AT&T disclosed mass breach affecting 'nearly all' wireless customers - call and text metadata stolen via Snowflake account
On July 12, 2024 AT&T disclosed that hackers had stolen call and text-message metadata for 'nearly all' of its approximately 110 million wireless customers between May 1 and October 31, 2022. The data was exfiltrated from a third-party cloud workspace hosted on Snowflake using stolen customer credentials. AT&T reportedly paid the threat actor approximately $370,000 in Bitcoin to delete the data. The DOJ allowed disclosure to be delayed twice on national-security grounds before the eventual filing.
Scoring Impact
| Topic | Direction | Relevance | Contribution |
|---|---|---|---|
| Corporate Transparency | -against | secondary | -0.50 |
| Data Security | -against | primary | -1.00 |
| User Privacy | -against | primary | -1.00 |
| Overall incident score = | -0.492 | ||
Score = avg(topic contributions) × significance (critical ×2) × confidence (0.59)× agency (negligent ×0.5)
Evidence (1 signal)
AT&T disclosed call/text metadata breach affecting nearly all wireless customers via Snowflake account
Reuters reported AT&T's July 12, 2024 SEC 8-K disclosure that call and text-message metadata for nearly all wireless customers had been stolen between May-October 2022 via a third-party cloud workspace hosted on Snowflake. AT&T reportedly paid the threat actor approximately $370,000 in Bitcoin to delete the data, with the DOJ permitting twice-delayed disclosure.