
[ad_1]
AT&T disclosed today that data of “nearly all” customers between May 1, 2022 and October 31, 2022, and January 2, 2023, was exposed to a third-party platform in April 2024. Customers whose data was exposed will be notified. AT&T said the access point where the cyberattack was carried out has been secured and the data is no longer accessible.
Threat actors access phone numbers and call duration
According to AT&T, the threat actors gained access to call and text message records, including phone numbers that customers interacted with and, in some cases, cell tower ID numbers. The breach included both cell and landline users.
An attacker could see “the number of calls or text messages made on a specific day or month, as well as the total length of calls,” AT&T said in a notice to customers:but not the content of those calls or text messages. Personally identifiable information such as Social Security numbers or dates of birth is also not included. However, the company noted that threat actors may be able to use phone numbers to find the names of people who use those phone numbers.
AT&T discovered the attack in April
AT&T first became aware of the attack on April 19, when “a threat actor claimed” to have accessed data, according to the report. AT&T’s filing with the U.S. Securities and Exchange Commission on the incident.
See also: July 4, another cyberattack Nearly 10 billion passwords For online accounts.
according to edgethe threat actors accessed data through Snowflake, a data warehouse platform also used Network attacks In June.
AT&T said in the notice that law enforcement has arrested a person in connection with the cyberattack.
AT&T uses the relatively new Form 8-KThe SEC implemented in December 2023, requiring public companies that experience a cyber incident to report the incident using this form if the incident is “significant.” As part of that disclosure, AT&T predicted that the April cyberattack is “unlikely to have a material impact on AT&T’s financial condition or results of operations.”
May 31, 2024 AT&T Disclosure 7.6 million customers’ passwords exposed in data breach. The two attacks do not appear to be related.
How to manually check if your data is affected
AT&T customers who manage business accounts can check if their data is affected. My AT&T or Premier Business Planning Portal. All customers (including corporate customers and former customers) can AT&T offers a variety of options on its support page.
What business leaders can learn from the AT&T hack
Such large-scale breaches serve as a reminder for companies to be aware of their Third-party suppliers and supply chain. Business leaders should also consider the following security tools: Endpoint Detection and Response or Security Information and Event Management And develop recovery and backup plans in case your data is stolen.
TechRepublic has reached out to AT&T for more information.
[ad_2]
Source link