The aforementioned security researcher, known by his online name Reddington, had been contacted in mid-April by another hacker (not the one who was paid by AT&T) who told him that he had millions of call and texting logs from AT&T which were obtained through a poorly secured cloud storage account hosted by Snowflake.
AT&T customers had some of their personal data stolen. | Image credit-AT&T
The data stolen from AT&T included metadata for calls and text messages; this information did not include the content of calls and messages and the names of the phone owners according to AT&T’s SEC filing. However, Reddington was shown by the hacker he was talking to how he could use a reverse look-up that could identify the owners of the stolen numbers as well as family members, colleagues, and others connected to the phone numbers.
AT&T’s SEC filing also indicated that the stolen data included phone numbers of “nearly all” of the carrier’s cellular customers, and the phone numbers of those using other wireless providers who exchanged calls and messages with AT&T customers during certain dates. The time period of the hacked data includes calls and messages made between May 1, 2022, and October 31, 2022, and January 2, 2023. Phone numbers of calls made to AT&T customers using a landline were included along with the date of the communication and the duration of each call.
Even with the deletion of the data, there is some fear that some AT&T customers and the people who communicated with them are still at risk since some might have samples of the data that were not deleted.