Featured Article

What the AT&T phone records data breach means for you

The giant U.S. telco lost the information of around 110 million customers. Here’s what you need to know.

Comment

An AT&T store in New York, US, on Monday, Jan. 22, 2024.
Image Credits: Jeenah Moon/Bloomberg / Getty Images

On Friday, AT&T said cybercriminals stole the phone records of “nearly all” of its customers, a data breach that will force the company to notify around 110 million people. 

AT&T said the stolen data included records like which phone numbers a certain customer called and texted, the total count of calls and texts, and call durations for a six-month period between May 1, 2022 and October 31, 2022. AT&T said the stolen data does not include any content of calls or texts, nor their time or date. 

For some of the affected customers, the cybercriminals were also able to steal cell site identification numbers linked to phone calls and text messages, according to AT&T. This means that — potentially — someone could use this information to figure out the approximate location of a customer when they made a certain call or sent a text, and perhaps infer sensitive information about their lives. 

“This can reveal where someone lives, works, spends their free time, who they communicate with in secret including affairs, any crime-based communication or typical private/sensitive conversations that require secrecy,” said Rachel Tobac, a social engineering expert and founder of cybersecurity firm SocialProof Security. “This is a big deal for anyone affected.” 

AT&T blamed the incident on a recent breach at cloud service provider Snowflake, which has affected dozens of companies, including Ticketmaster, Santander Bank and LendingTree subsidiary QuoteWizard. At this point, it’s unclear exactly who was behind the Snowflake breach. Mandiant, the cybersecurity firm hired by Snowflake to investigate, said a financially motivated cybercriminal group they identify as UNC5537 was responsible.

The type of data stolen in AT&T’s data breach is typically referred to as metadata because it doesn’t include the contents of calls or texts, but only information about those calls and texts. That, however, doesn’t mean there are no risks for the victims of this breach.

Tobac said that this type of data makes it easier for cybercriminals to impersonate people you trust, making it easier for them to craft more believable social engineering or phishing attacks against AT&T customers. 

Contact Us

Do you have more information about this AT&T incident? Or about the Snowflake breach? From a non-work device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram, Keybase and Wire @lorenzofb, or email. You also can contact TechCrunch via SecureDrop.

“The attackers know exactly who you’re likely to pick up a call from, who you’re likely to text back, how long you communicate with that person, and even potentially where you were located during that conversation due to the metadata that was stolen,” said Tobac.

Runa Sandvik, the founder of Granitt, a firm that helps journalists and activista be more secure, said that “even if you don’t do anything ‘important’ or ‘sensitive,’ who you talk to; when; and how often is still personal to you and should remain private to you as well.”

“I think everyone should be very angry about this and demand better from the telcos, it’s not enough to say ‘oh by the way your data was taken, we are sorry and are taking this very seriously’,” Sandvik told TechCrunch.

Sandvik said it’s more concerning for higher-risk individuals affected by the breach. “Some may consider changing their numbers and using a different provider, but it just really depends on the circumstances.” Higher-risk individuals can also include those who have a reason to shield their identity, such as survivors of domestic abuse. 

Sandvik also said that using encrypted chat apps — like Signal, which doesn’t hold the type of metadata AT&T just lost; and WhatsApp — could be better for security because these companies have a better track record of protecting user data. 

Jake Williams, a cybersecurity expert and former NSA hacker, told TechCrunch that the risk is greater for businesses and intelligence targets following the AT&T breach. 

“Threat actors can use this data to create patterns of life,” said Williams. “Call data records provide a wealth of value for intelligence analysts.”

Williams also said that it’s possible hackers can combine this data with that of data breaches, because “previous AT&T incidents mapped customer phone numbers to other identifying information, simplifying weaponization of the newly compromised data.”

Call and text metadata is traditionally information that can be valuable for intelligence agencies. Some of the documents leaked by former NSA contractor Edward Snowden more than a decade ago revealed that the U.S. National Security Agency was obtaining customer metadata from Verizon in bulk on an “ongoing, daily basis.” 

The U.S. government has long defended this practice as an essential tool to fight against terrorism, and for the last decade successive administrations have been reluctant to give up this capability. A former intelligence officer, who asked to remain anonymous because they were not authorized to speak to the press, told TechCrunch that there is “a reason telcos are so often targeted by foreign services,” citing efforts to identify potential intelligence sources and assets.

“In short, this data is a gold mine for understanding who talks to who, which can for instance be used for developing human sources,” said Williams.

More TechCrunch

A new study examines whether AI could be an automated helpmeet in creative tasks, with mixed results: it appeared to help less naturally creative people write more original stories —…

Experiment finds AI boosts creativity individually — but lowers it collectively

Featured Article

HeadSpin, whose founder is in prison for fraud, sold to PE firm for ‘cents on the dollar,’ sources say

In total, HeadSpin raised $117 million since its 2015 inception and was last valued at $1.1 billion in 2020.

HeadSpin, whose founder is in prison for fraud, sold to PE firm for ‘cents on the dollar,’ sources say

A bipartisan group of senators has introduced a new bill that seeks to protect artists, songwriters, and journalists from having their content used to train AI models or generate AI…

New Senate bill seeks to protect artists’ and journalists’ content from AI use

When Keith Rabois announced he was leaving Founders Fund to return to Khosla Ventures in January, it came as a shock to many in the venture capital ecosystem — and…

From Ethan Choi to Spencer Peterson, venture capitalists continue to play musical chairs

Archer Aviation and Southwest Airlines are teaming up to figure out what it will take to build out a network of electric air taxis at California airports. Southwest’s customer data…

Archer’s vision of an air taxi network could benefit from Southwest customer data

If you visited the Wikipedia website on mobile this week, you might have seen a pop-up indicating that dark mode is ready for prime time.

Wikipedia’s mobile website finally gets a dark mode — here’s how to turn it on

Featured Article

What the AT&T phone records data breach means for you

The giant U.S. telco lost the information of around 110 million customers. Here’s what you need to know.

What the AT&T phone records data breach means for you
Image Credits: Jeenah Moon/Bloomberg / Getty Images

The error brings to a close SpaceX’s incredible streak of 335 flawless launches across the company’s Falcon family of rockets, which also includes the more powerful Falcon Heavy.

SpaceX Falcon 9 suffers rare failure on orbit during Starlink deployment

The AI chatbot has been trained on Amazon’s product catalog, customer reviews, community Q&As, and other public information found around the web.

Amazon AI chatbot Rufus is now live for all US customers

If X continues to violate Europe’s data protection rules, the company is on the hook for fines of up to €4,000 per day.

More bad news for Elon Musk after X user’s legal challenge to shadowban prevails

HERO Software has closed a €40 million Series B financing round, and plans to expand across Europe. 

A startup set out to fight climate change — it did it by helping plumbers

Fusion power may still be a few years away, but one startup is laying the groundwork for what it hopes will become a bustling sector of the economy.

Fusion pioneer Commonwealth Fusion Systems is selling core magnet tech to the University of Wisconsin

For months, rumors persisted that Google, and perhaps others, were interested in buying HubSpot, a Boston-based CRM and marketing software company. HubSpot’s market cap ballooned as the rumors persisted, eventually…

Boston VCs are pleased that HubSpot will remain an independent company

ByteDance’s video editing app CapCut will stop offering free cloud storage to host creative assets starting August 5. In the past few days, users have received notifications about CapCut changing…

CapCut will stop offering free cloud storage from August 5

The platform formerly known as Twitter has earned the dubious honor of being the first very large online platform (VLOP) to face a preliminary finding of breaching the European Union’s…

Europe confirms first clutch of DSA grievances on Elon Musk’s X

Featured Article

AT&T says criminals stole phone records of ‘nearly all’ customers in new data breach

The stolen data includes 110 million AT&T customer phone numbers, calling and text records, and some location-related data.

AT&T says criminals stole phone records of ‘nearly all’ customers in new data breach

The full and final text of the EU AI Act, the European Union’s landmark risk-based regulation for applications of artificial intelligence, has been published in the bloc’s Official Journal. In…

EU’s AI Act gets published in bloc’s Official Journal, starting clock on legal deadlines

A Castro Valley resident was charged Thursday for allegedly slashing the tires of 17 Waymo robotaxis in San Francisco between June 24 and June 26, according to the city’s district…

Waymo cameras capture footage of person charged in alleged robotaxi tire slashings

Featured Article

SoftBank acquires UK AI chipmaker Graphcore

While the figure of $500 million has been bandied around in various reports for months, in a press briefing early Thursday morning, Graphcore co-founder and CEO Nigel Toon remained coy on the details.

SoftBank acquires UK AI chipmaker Graphcore

Elon Musk’s X, formerly Twitter, is continuing to develop a downvoting feature that will be used to improve how replies are ranked. Although the company has not yet officially announced…

X is building a ‘dislike’ button for downvoting replies

Featured Article

Data breach exposes millions of mSpy spyware customers

A huge batch of mSpy customer service emails dating back to 2014 were stolen in a May data breach.

Data breach exposes millions of mSpy spyware customers

Kudos founder says her company makes a disposable diaper lined with 100% cotton, unlike the major competitors.

Shark Tank-backed Kudos raises another $3M for healthier, cotton-based disposable diapers

Astra CEO Chris Kemp is already pulling out of a parking spot when he warns the person in the passenger seat that he doesn’t have a valid driver’s license. “And…

‘Wild Wild Space’ doc captures the risks and rivalries of the new space race

Although these companies’ claims are artfully couched, it’s clear that they want to express that the model sees in some sense of the word.

‘Visual’ AI models might not see anything at all

Welcome back to TechCrunch Mobility — your central hub for news and insights on the future of transportation. Sign up here for free — just click TechCrunch Mobility! Did you…

Lucid revs up sales, Fisker makes a deal and Uber reignites an old fight

Retro CEO Nathan Sharp isn’t worrying just yet about Google’s plan to copy his app’s experience, despite the numerous similarities.

Photo-sharing startup Retro spots Google Photos copying its idea and design

Tesla had internally planned to build the dedicated robotaxi and the $25,000 car, often referred to as the Model 2, on the same platform.

Tesla reportedly delays ‘robotaxi’ event to October

Here’s a look at what’s going to change with Siri, and what the introduction of Apple Intelligence will allow you to do with the digital assistant. 

How Apple Intelligence is changing the way you use Siri on your iPhone 

The new YouTube features include those that will automatically transform longer videos into Shorts, among others.

YouTube tempts creators with a half dozen new features for Shorts

The capital will be used to expand in Europe, the U.S. and Asia.

Exein raised $15M Series B to stop robotic arms going haywire