Featured Article

What the AT&T phone records data breach means for you

The giant U.S. telco lost the information of around 110 million customers. Here’s what you need to know.

Comment

An AT&T store in New York, US, on Monday, Jan. 22, 2024.
Image Credits: Jeenah Moon/Bloomberg / Getty Images

On Friday, AT&T said cybercriminals stole the phone records of “nearly all” of its customers, a data breach that will force the company to notify around 110 million people. 

AT&T said the stolen data included records like which phone numbers a certain customer called and texted, the total count of calls and texts, and call durations for a six-month period between May 1, 2022 and October 31, 2022. AT&T said the stolen data does not include any content of calls or texts, nor their time or date. 

For some of the affected customers, the cybercriminals were also able to steal cell site identification numbers linked to phone calls and text messages, according to AT&T. This means that — potentially — someone could use this information to figure out the approximate location of a customer. 

“This can reveal where someone lives, works, spends their free time, who they communicate with in secret including affairs, any crime-based communication or typical private/sensitive conversations that require secrecy,” said Rachel Tobac, a social engineering expert and founder of cybersecurity firm SocialProof Security. “This is a big deal for anyone affected.” 

AT&T blamed the incident on a recent breach at cloud service provider Snowflake, which has affected dozens of companies, including Ticketmaster, Santander Bank and LendingTree subsidiary QuoteWizard. At this point, it’s unclear exactly who was behind the Snowflake breach. Mandiant, the cybersecurity firm hired by Snowflake to investigate, said a financially motivated cybercriminal group they identify as UNC5537 was responsible.

The type of data stolen in AT&T’s data breach is typically referred to as metadata because it doesn’t include the contents of calls or texts, but only information about those calls and texts. That, however, doesn’t mean there are no risks for the victims of this breach.

Tobac said that this type of data makes it easier for cybercriminals to impersonate people you trust, making it easier for them to craft more believable social engineering or phishing attacks against AT&T customers. 

Contact Us

Do you have more information about this AT&T incident? Or about the Snowflake breach? From a non-work device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram, Keybase and Wire @lorenzofb, or email. You also can contact TechCrunch via SecureDrop.

“The attackers know exactly who you’re likely to pick up a call from, who you’re likely to text back, how long you communicate with that person, and even potentially where you were located during that conversation due to the metadata that was stolen,” said Tobac.

Runa Sandvik, the founder of Granitt, a firm that helps journalists and activists be more secure, said that “even if you don’t do anything ‘important’ or ‘sensitive,’ who you talk to; when; and how often is still personal to you and should remain private to you as well.”

“I think everyone should be very angry about this and demand better from the telcos, it’s not enough to say ‘oh by the way your data was taken, we are sorry and are taking this very seriously’,” Sandvik told TechCrunch.

Sandvik said it’s more concerning for higher-risk individuals affected by the breach. “Some may consider changing their numbers and using a different provider, but it just really depends on the circumstances.” Higher-risk individuals can also include those who have a reason to shield their identity, such as survivors of domestic abuse. 

Sandvik also said that using encrypted chat apps — like Signal, which doesn’t hold the type of metadata AT&T just lost; and WhatsApp — could be better for security because these companies have a better track record of protecting user data. 

Jake Williams, a cybersecurity expert and former NSA hacker, told TechCrunch that the risk is greater for businesses and intelligence targets following the AT&T breach. 

“Threat actors can use this data to create patterns of life,” said Williams. “Call data records provide a wealth of value for intelligence analysts.”

Williams also said that it’s possible hackers can combine this data with that of data breaches, because “previous AT&T incidents mapped customer phone numbers to other identifying information, simplifying weaponization of the newly compromised data.”

Call and text metadata is traditionally information that can be valuable for intelligence agencies. Some of the documents leaked by former NSA contractor Edward Snowden more than a decade ago revealed that the U.S. National Security Agency was obtaining customer metadata from Verizon in bulk on an “ongoing, daily basis.” 

The U.S. government has long defended this practice as an essential tool to fight against terrorism, and for the last decade successive administrations have been reluctant to give up this capability. A former intelligence officer, who asked to remain anonymous because they were not authorized to speak to the press, told TechCrunch that there is “a reason telcos are so often targeted by foreign services,” citing efforts to identify potential intelligence sources and assets.

“In short, this data is a gold mine for understanding who talks to who, which can for instance be used for developing human sources,” said Williams.

More TechCrunch

Thomas Ingenlath is having perhaps a little too much fun in his Polestar 3, silently rocketing away from stop signs and swinging through tightening bends, grinning like a man far…

With the Polestar 3 now “weeks” away, its CEO looks to make company “self-sustaining”

Some parents have reservations about the South Korean government’s plans to bring tablets with AI-powered textbooks into classrooms, according to a report in The Financial Times. The tablets are scheduled…

South Korea’s AI textbook program faces skepticism from parents

Featured Article

How VC Pippa Lamb ended up on ‘Industry’ — one of the hottest shows on TV

Season 3 of “Industry” focuses on the fictional bank Pierpoint blends the worlds — and drama — of tech, media, government, and finance.

How VC Pippa Lamb ended up on ‘Industry’ — one of the hottest shows on TV

Featured Article

Selling a startup in an ‘acqui-hire’ is more lucrative than it seems, founders and VCs say

Selling under such circumstances is often not as poor of an outcome for founders and key staff as it initially seems. 

Selling a startup in an ‘acqui-hire’ is more lucrative than it seems, founders and VCs say

While the rapid pace of funding has slowed, many fintechs are continuing to see growth and expand their teams.

These  fintech companies are hiring, despite a rough market in 2024

This is just one area of leadership where Parker Conrad takes a contrarian approach. He also said he doesn’t believe in top-down management.

Rippling’s Parker Conrad says founders should ‘go all the way to the ground’ to run their companies

Congresswoman Nancy Pelosi issued a statement late yesterday laying out her opposition to SB 1047, a California bill that seeks to regulate AI. “The view of many of us in…

Nancy Pelosi criticizes California AI bill as ‘ill-informed’

Data analytics company Palantir has faced criticism and even protests over its work with the military, police, and U.S. Immigration and Customs Enforcement, but co-founder and CEO Alex Karp isn’t…

Palantir CEO Alex Karp is ‘not going to apologize’ for military work

Timo Resch is basking in the sun. That’s literally true, as we speak on a gloriously clear California day at the Quail, one of Monterey Car Week’s most prestigious events.…

Why Porsche NA CEO Timo Resch is betting on ‘choice’ to survive the turbulent EV market

Made by Google was this week, featuring a full range of reveals from Google’s biggest hardware event. Google unveiled its new lineup of Pixel 9 phones, including the $1,799 Pixel…

Google takes on OpenAI with Gemini Live

I’ve been playing around with OpenAI’s Advanced Voice Mode for the last week, and it’s the most convincing taste I’ve had of an AI-powered future yet. This week, my phone…

OpenAI’s new voice mode let me talk with my phone, not to it

X, the social media platform formerly known as Twitter, said today that it’s ending operations in Brazil, although the service will remain available to users in the country. The announcement…

X says it’s closing operations in Brazil

One of the biggest questions looming over the drone space is how to best use the tech. Inspection has become a key driver, as the autonomous copters are deployed to…

Ikea expands its inventory drone fleet

Brands can use Keychain to look up different products and see who actually manufactures them.

Keychain aims to unlock a new approach to manufacturing consumer goods

In this post, we explain the many Microsoft Copilots available and what they do, and highlight the key differences between each.

Microsoft Copilot: Everything you need to know about Microsoft’s AI

A hack on UnitedHealth-owned tech giant Change Healthcare likely stands as one of the biggest data breaches of U.S. medical data in history.

How the ransomware attack at Change Healthcare went down: A timeline

Gogoro has deferred its India plans over delay in government incentives, but the Taiwanese company has partnered with Rapido for a bike-taxi pilot.

Gogoro delays India plans due to policy uncertainty, launches bike-taxi pilot with Rapido

On Friday, the venture firm Andreessen Horowitz tweeted out a link to its guide on how to “build your social media presence” which features advice for founders.

A16z offers social media tips after its founder’s ‘attack’ tweet goes viral

OpenAI has banned a cluster of ChatGPT accounts linked to an Iranian influence operation that was generating content about the U.S. presidential election, according to a blog post on Friday.…

OpenAI shuts down election influence operation that used ChatGPT

Apple is reportedly shifting into the world of home robots after the wheels came off its electric car. According to a new report from Bloomberg, a team of several hundred…

Apple reportedly has ‘several hundred’ working on a robot arm with attached iPad

Welcome to Startups Weekly — your weekly recap of everything you can’t miss from the world of startups. I’m Anna Heim from TechCrunch’s international team, and I’ll be writing this newsletter…

Another week in the circle of startup life

MIT this week showcased tiny batteries designed specifically for the purpose of power these systems to execute varied tasks.

Researchers develop hair-thin battery to power tiny robots

Rimac revealed Friday during The Quail, a Motorsports Gathering at Monterey Car Week the Nevera R, an all-electric hypercar that’s meant to push the performance bounds of its predecessor.

The Nevera R all-new electric hypercar can hit a top speed of 217 mph, and it only starts at $2.5 million

While the ethics of AI-generated porn are still under debate, using the technology to create nonconsensual sexual imagery of people is, I think we can all agree, reprehensible. One such…

A hellish new AI threat: ‘Undressing’ sites targeted by SF authorities

Almost two weeks ago, TechCrunch reported that African e-commerce giant Jumia was planning to sell 20 million American depositary shares (ADSs) and raise more than $100 million, given its share…

African e-commerce company Jumia completes sale of secondary shares at $99.6M

We’re entering the final week of discounted rates for TechCrunch Disrupt 2024. Save up to $600 on select individual ticket types until August 23. Join a dynamic crowd of over…

Only 7 days left to save on TechCrunch Disrupt 2024 tickets

Epic Games, the maker of Fortnite, announced on Friday that it has officially launched its rival iOS app store in the European Union. The Epic Games Store is also launching…

‘Fortnite’ maker Epic Games launches its app store on iOS in the EU, worldwide on Android

After bringing AI overviews to the U.S., Google is expanding the AI-powered search summaries to six more countries: India, Brazil, Japan, the U.K., Indonesia and Mexico. These markets will also…

Google is bringing AI overviews to India, Brazil, Japan, UK, Indonesia and Mexico

The Commission is seeking more information from Meta following its decision to deprecate its CrowdTangle transparency tool. The latest EU request for information (RFI) on Meta has been made under…

Meta draws fresh questions from EU over its CrowdTangle shut-down

Twitter alternatives — new and old — have found audiences willing to try out a newer social networks since Elon Musk took over the company in 2022. Mastodon, Bluesky, Spill…

What is Instagram’s Threads app? All your questions answered