AT&T admits massive 70m+ mid-March data dump is real, but claims it's years old
- Reference: 1711974890
- News link: https://www.theregister.co.uk/2024/04/01/att_admits_massive_70m_midmarch/
- Source link:
The telco giant said in a [1]press release that the data that [2]appeared in cybercrime forums last month was genuine, and included information on 7.6 million current AT&T customers as well as 65.4 million former users. The largest stolen data trove appears to be from 2019 or earlier based on initial investigations, AT&T said.
"It is not yet known whether the data in those fields originated from AT&T or one of its vendors," the company noted in its press release. "Currently, AT&T does not have evidence of unauthorized access to its systems resulting in exfiltration of the data set."
[3]
The information included in the dump varies per customer, AT&T said on a [4]support page for the incident, but may include full name, email and mailing address, phone number, SSN, birth date and AT&T account number and passcode, the latter being that four-digit identity verification number you always forget when talking to customer support.
[5]
[6]
While AT&T is withholding judgment on where the data came from, it appears to align with a massive set of AT&T customer data that was offered for sale on the dark web in 2021.
[7]AT&T blames marketing bods for exposing 9M accounts
[8]Americans wake to widespread AT&T cellular outages
[9]T-Mobile US exposes some customer data – but don't call it a breach
[10]US govt pays AT&T to let cops search Americans' phone records – 'usually' without a warrant
Cybercrime gang ShinyHunters claimed in mid-2021 to have data belonging to some 70 million AT&T customers that it was offering for sale for the tidy sum of $1m, [11]according to RestorePrivacy, which viewed the dataset. RestorePrivacy also spoke to members of ShinyHunters, who told them the data belonged to US-based AT&T customers, but wouldn't reveal how they obtained it.
AT&T denied that the data belonged to it in 2021, and it's not immediately clear whether both sets of data are the same. That said, there are plenty of similarities, both in the volume of records included and the items included in the set.
AT&T claimed in March that the dataset in question may have been "the same dataset that has been recycled several times" on the forum where it was uploaded, but it's not clear whether that's the case. If it's a different set of actual customer records then that just opens a whole other can of worms.
[12]
We've reached out to AT&T with questions and will update this story if we hear back. ®
Get our [13]Tech Resources
[1] https://www.prnewswire.com/news-releases/att-addresses-recent-data-set-released-on-the-dark-web-302103937.html
[2] https://theregister.com/2024/03/18/att_alleged_data_leak/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZgraHAXw1G5RinFS8PyjMQAAAI0&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://www.att.com/support/article/my-account/000101995
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZgraHAXw1G5RinFS8PyjMQAAAI0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZgraHAXw1G5RinFS8PyjMQAAAI0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2023/03/09/att_wireless_breach/
[8] https://www.theregister.com/2024/02/22/att_outage_usa/
[9] https://www.theregister.com/2023/09/25/tmobile_exposes_some_customer_data/
[10] https://www.theregister.com/2023/11/22/wyden_hemisphere_letter/
[11] https://restoreprivacy.com/att-data-breach-70-million-customers/
[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZgraHAXw1G5RinFS8PyjMQAAAI0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[13] https://whitepapers.theregister.com/
Re: reached out
they're AT&Useless. They want you to reach out and touch them.
I want to reach out and touch them with a sledgehammer.
Re: reached out
The "AT&T help" defaults to AI and is totally slow and hard to get working but once I demand, and managed to talk to a person at AT&T, then everything gets fixed. I'm not too worried about this data leakage because my old AT&T accounts are about 30 years ago, all with expired emails and other contact information that only existed years ago.
Personal data theft is a normal situation these days - it's a bit like the Flu environment, it happens all the time and we all need to get our "data vaccinated" but get used to recovering from minor "infections" every year or so - for example I recently called my credit card company and had all the card numbers "updated" to new numbers again.
AT&Useless strikes again
This is at least the third time that AT&Useless accounts have been hacked. The first two times it was because they had hired out their email to Yahoo, and 100% of Yahoo emails were grabbed, because Yahoo may have heard about security but has no idea what the word means.
I have been getting little text stating that my password for account ending
(Exact wording:
"AT&T Free Msg: Your Account passcode has been changed for acct # ending in
That particular account is the account for my AT&Useless cell phone. I have never, ever, had a separate login, or password, for that account, as it has been combined with my other AT&Useless accounts, for U-Verse, which has become AT&Useless Fibre (misspelled as Fiber, because AT&Useless) The text system has four of those texts. I suspect that whoever keeps changing the password is getting frustrated as they can't access anything. How sad. Too bad.
I went to the local AT&Useless corporate store (their franchise stores are even more bloody useless than AT&Useless normally is) yesterday and changed everything on the main account: login, password, PIN, and more. According to the corporate store, no-one has got into anything from the
The only reason why I don't just junk AT&Useless is that the only choice for internet/tv/landline around here is Comcast, who are even more useless than AT&Useless, difficult though that may be to believe, and there are only three main cellcos: AT&Useless, T-Mob, and Veriscum. I already have a cell on T-Mob and Veriscum are flat-out evil. I keep phones on different carriers because some carriers have problems in certain areas. (Veriscum signals drop to zero in certain locations. Guess how I know.)
It turns out that an ancient login for AT&Useless, which was, supposedly, deleted in 2007, still works Guess how I found out.
I have finally found a telco even more useless than Cable & Wireless.
Data ageism
It doesn't matter how many years old the data is. If it contains names, dates of birth and social security numbers , it will remain valuable for the lifetimes of the victims.
Thta's regardless of whether they remain AT&T customers or not.
reached out
I wish you wouldn't "reach out" with questions. Just ask them.