Breach report
TelecomAT&T
Crooks Steal Phone, SMS Records for Nearly All AT&T Customers
Hackers used stolen passwords to raid AT&T's Snowflake cloud workspace, taking months of call and text logs for nearly every AT&T wireless customer, and the carrier reportedly paid a ransom to have the data deleted.
Reported by Krebs on Security
Records exposed
110M
About 110 million customers (roughly 50 billion call and text records)
Scale vs. largest on file
- When
- 2024
- How they got in
- Stolen credentials for third-party cloud (Snowflake) account without multi-factor authentication
- Sector
- Telecom
On July 12, 2024, AT&T disclosed that hackers had downloaded records of calls and texts made by nearly all of its cellular customers, about 110 million people. The stolen logs covered a six-month stretch from May 1 to October 31, 2022, plus January 2, 2023. The company said it learned of the theft on April 19, 2024, but delayed public disclosure at the request of the FBI and Justice Department, which cited national security and public safety concerns.
The data was not taken from AT&T's core network. It came from a workspace AT&T maintained on Snowflake, a third-party cloud data platform. Beginning in April 2024, a hacking campaign used usernames and passwords stolen by information-stealing malware to log in to Snowflake accounts belonging to more than 160 organizations. Many of those accounts, including AT&T's, did not require multi-factor authentication, so a valid password was enough to get in and export data.
The records did not include the content of calls or messages, names, Social Security numbers or birth dates. They did include the phone numbers each customer interacted with, how often and for how long. A subset contained cell site identifiers, which can reveal a phone's approximate location. Security experts warned that this kind of metadata can map personal relationships and movements, making it valuable to criminals and intelligence services alike.
In November 2024, U.S. prosecutors unsealed charges against two men accused in the broader Snowflake campaign: Connor Moucka, arrested in Canada, and John Binns, arrested in Turkey. The indictment alleged they stole billions of records from multiple companies and extorted several victims, and media reports said AT&T paid about $370,000 to have its stolen data deleted. A U.S. Army soldier was separately charged with trying to sell AT&T call records. AT&T said the incident was not expected to have a material financial impact; in 2025 it agreed to a combined class-action settlement of about $177 million covering this breach and the earlier 73 million-record leak.
The breach became a defining example of how cloud platform credentials, rather than software flaws, can open the door to massive theft. It accelerated calls for mandatory multi-factor authentication on enterprise cloud services, and Snowflake subsequently moved to make it the default for customer accounts.