AT&T late last week publicly disclosed that it was the victim of a cyberattack at a “third-party cloud platform” – believed to be Snowflake – that resulted in the theft of records of calls and texts for nearly all traffic running over its wireless network over a six-month period in mid-2022. The perpetrator has also been linked to a similar brazen cyberattack at AT&T rival T-Mobile US in 2021.
AT&T fessed up to the cyberattack in a Securities and Exchange Commission (SEC) filing that was initially filed in early May, but was not released until July 12. In it, the carrier states that on April 19 it learned of a “threat actor” that claimed to have hacked into a database at a third-party cloud platform used by the carrier where they accessed and copied AT&T call logs.
That information included records of “customer call and text interactions” that happened between May 1 and October 31 of 2022 and on Jan. 2, 2023. That data included records of calls and texts of “nearly all of AT&T’s wireless customers and customers of mobile virtual network operators (MVNOs) using AT&T’s wireless network.”
AT&T stated that the data identified the telephone numbers of the AT&T or mobile virtual network operator (mobile virtual network operator (MVNO)) customer and the telephone number that the AT&T or MVNO customer interacted with as part of the call or text session. For some of the records, it also included “one or more cell site identification numbers” that “using publicly available online tools” would provide the name associated with a specific telephone number.
The carrier did add that the accessed and copied data did not include Social Security numbers, dates of birth, or “other personally identifiable information.”
AT&T noted in the filing that it believes the attacker had access to the data beginning on April 14 and had access until April 25, which was six days after AT&T first learned of a potential attack. The carrier did notify the U.S. Department of Justice (DoJ) after it learned of the attack as required by law but was provided with two deferments on having to publicly release information that it was breached. The AT&T data was rumored to have been in circulation on the dark web before April 1.
AT&T added that it believes at least one person tied to the cybersecurity attack has been detained and “that it does not believe the data is publicly available.”
Was a ransom paid?
A detailed report from Wired indicates that belief is tied to the fact that AT&T paid a ransom to the attacker to have the stolen information deleted. That report links the AT&T case to a cyberattack earlier this year on a cloud database controlled by Snowflake, which had itself been tied to other prominent stolen data cases from the likes of Ticketmaster and Santander Bank.
Google’s Mandiant cybersecurity division has stated it received information in April that database records had been stolen and later determined those records were from Snowflake.
“Mandiant notified the victim, who then engaged Mandiant to investigate suspected data theft involving their Snowflake instance,” Mandiant wrote in a detailed autopsy of the cybersecurity attack. “During this investigation, Mandiant determined that the organization’s Snowflake instance had been compromised by a threat actor using credentials previously stolen via infostealer malware. The threat actor used these stolen credentials to access the customer’s Snowflake instance and ultimately exfiltrate valuable data. At the time of the compromise, the account did not have multi-factor authentication (MFA) enabled.”
Snowflake initially denied this data was stolen from its control, but indicated that “a threat actor obtained personal credentials to and accessed demo accounts belonging to a former Snowflake employee,” which did not contain sensitive data. It has since backed that stance by stating it was working more closely with customers on using “advanced security controls, like multi-factor authentication (MFA) or network policies.”
The Wired report indicated that AT&T paid approximately $370,000 in bitcoin to the attacker and in return was passed a video of the attacker deleting the stolen information.
AT&T declined to provide a response to SDxCentral on that accusation.
AT&T cyberattack tied to T-Mobile US breach
The Wired report also stated that the Snowflake attacker was the same person that breached T-Mobile US servers in mid-2021. That attack garnered personal data on more than 100 million of the carrier’s customers in what one analyst said might have been “the largest carrier breach on record.”
T-Mobile US eventually agreed to pay $350 million to compensate consumers hit by that cybersecurity breach and said it would spend $150 million on data security over the next 18 months. T-Mobile US customer data has been accessed and stolen several more times since, with the carrier recently unveiling a cybersecurity “Trust Center” it claims will provide a clearer picture of the carrier’s cybersecurity posture.
Comments