Hello

Your subscription is almost coming to an end. Don’t miss out on the great content on Nation.Africa

Ready to continue your informative journey with us?

Hello

Your premium access has ended, but the best of Nation.Africa is still within reach. Renew now to unlock exclusive stories and in-depth features.

Reclaim your full access. Click below to renew.

Data from around 109m US customer accounts illegally downloaded, says AT&T

FILE PHOTO: The AT&T logo is seen in a store window, as airports around the country are awaiting for Verizon and AT&T to rollout their 5G technology, in the Manhattan borough of New York City, New York, U.S., January 19, 2022. PHOTO/REUTERS

What you need to know:

  • AT&T said it has taken additional cybersecurity measures including closing off the point of unlawful access.

AT&T T.N said Friday the company suffered a massive hacking incident as data from about 109 million customer accounts containing records of calls and texts from 2022 was illegally downloaded in April.

The U.S. telecom company said the FBI is investigating and at least one person has been arrested after AT&T call logs were copied from its workspace on a third-party cloud platform in a significant breach of consumer communication records.

AT&T said the compromised data includes files containing AT&T records of calls and texts of nearly all of AT&T's cellular and AT&T's landline customers interacting with those cellular numbers between May 2022 and October 2022 but does not contain the content of calls or texts or personal information such as social security numbers.

AT&T shares were down 2% in premarket trading.

The FBI and Federal Communications Commission did not immediately comment.

The compromised data also includes records from Jan. 2, 2023, for a very small number of customers.

AT&T said it first learned on April 19 that a hacker had claimed to have unlawfully accessed and copied AT&T call logs. The company said its investigation found hackers had between April 14 and April 25 unlawfully exfiltrated files containing AT&T records of customer call and text interactions. The records also include AT&T customers of mobile virtual network operators using AT&T's wireless network.

These records identify telephone numbers with which a wireless number interacted during these periods and aggregate call duration. A subset of records includes one or more cell site identification number.

AT&T said it has taken additional cybersecurity measures including closing off the point of unlawful access. It said it would notify customers of the incident and set up a website where they could determine if their data had been compromised.

AT&T is working with law enforcement and said it had delayed public notification based on a determination by the Justice Department. AT&T added it does not believe that the data is publicly available.

The company added the incident has not had a material impact on AT&T's operations.