Last Member Drive of 2025!

Your year-end tax-deductible gift powers our local newsroom. Help raise $1 million in essential funding for LAist by December 31.
$700,442 of $1,000,000 goal
A row of graphics payment types: Visa, MasterCard, Apple Pay and PayPal, and  below a lock with Secure Payment text to the right
Audience-funded nonprofit news
radio tower icon laist logo
Next Up:
0:00
0:00
Subscribe
  • Listen Now Playing Listen
NPR News

AT&T says hackers stole 2022 call and text data from 'nearly all' cell customers

 AT&T announced Friday that hackers stole 2022 data of “nearly all” of its cellular customers off the company's workspace on a third-party cloud platform.
AT&T announced Friday that hackers stole 2022 data of “nearly all” of its cellular customers off the company's workspace on a third-party cloud platform.
(
Pau Barrena
/
AFP via Getty Images
)

Truth matters. Community matters. Your support makes both possible. LAist is one of the few places where news remains independent and free from political and corporate influence. Stand up for truth and for LAist. Make your year-end tax-deductible gift now.

AT&T says hackers stole 2022 data of “nearly all” of its cellular customers from the company's workspace on a third-party cloud platform.

The Dallas-based telecommunications company announced the massive data breach in a regulatory filing and press release on Friday morning, which said it believes the data is no longer publicly available.

“AT&T has taken additional cybersecurity measures in response to this incident including closing off the point of unlawful access,” it added.

The company wrote that it first learned of the incident in April, but the U.S. Justice Department determined in May and again in June that “a delay in providing public disclosure was warranted” until now.

AT&T’s investigation found that an unspecified number of “threat actors” exfiltrated files in April containing the records of phone calls and text messages of “nearly all AT&T cellular customers” between May and October 2022, as well as a smaller number of customers on Jan. 2, 2023.

An AT&T spokesperson described the information taken as “aggregated metadata,” holding information about the calls and texts but not their contents.

The records identify other telephone numbers with which affected customers interacted, including AT&T landline numbers, as well as counts of those calls and texts and the total call durations for specific days or months.

Sponsored message

“For a subset of the records, one or more cell site ID numbers associated with the interactions are also included,” it adds.

AT&T says the data does not include the substance or time stamps of those calls and texts, nor birthdays, social security numbers or other “personally identifiable information.” Though there is a catch.

“While the data does not include customer names, there are often ways, using publicly available online tools, to find the name associated with a specific telephone number,” it cautions.

AT&T says it is working with law enforcement to arrest the perpetrators, and “understands that at least one person has been apprehended” so far.

The company says it will notify impacted users by text, email or U.S. mail, and has also set up a webpage where current and former customers can check to see if their information was involved.

Those affected can follow an online process to obtain the phone numbers of their calls and texts in the downloaded data. AT&T says the option to request that information will be in place through the end of this year.

And for those concerned about potential phishing and online fraud, it offers some evergreen advice, including not replying to a text from an unknown sender with personal details and making sure websites are secure by looking for the “s” after “http” in the address.

Sponsored message

It adds that customers who suspect suspicious text activity should forward the message to AT&T, and report any suspected fraud on their AT&T wireless account to its team.

This is not the first data breach that AT&T has reported this year.

It said in March that it had reset the passcodes of about 7.6 million users after it discovered a dataset on the “dark web” containing Social Security numbers and other personal information of some 70 million current and former account holders.

Separately, AT&T gave $5 to certain customers affected by a nearly 12-hour nationwide outage back in February.

Verizon, Ticketmaster, Dell and Bank of America are among the other companies that have reported major data breaches this year, affecting millions of people altogether.

Copyright 2024 NPR. To see more, visit npr.org.

Corrected July 12, 2024 at 7:18 AM PDT

This story has been updated to reflect that hackers downloaded the customer data from a third-party platform.

Corrected July 12, 2024 at 7:18 AM PDT

This story has been updated to reflect that hackers downloaded the customer data from a third-party platform.

You come to LAist because you want independent reporting and trustworthy local information. Our newsroom doesn’t answer to shareholders looking to turn a profit. Instead, we answer to you and our connected community. We are free to tell the full truth, to hold power to account without fear or favor, and to follow facts wherever they lead. Our only loyalty is to our audiences and our mission: to inform, engage, and strengthen our community.

Right now, LAist has lost $1.7M in annual funding due to Congress clawing back money already approved. The support we receive before year-end will determine how fully our newsroom can continue informing, serving, and strengthening Southern California.

If this story helped you today, please become a monthly member today to help sustain this mission. It just takes 1 minute to donate below.

Your tax-deductible donation keeps LAist independent and accessible to everyone.
Senior Vice President News, Editor in Chief

Make your tax-deductible year-end gift today

A row of graphics payment types: Visa, MasterCard, Apple Pay and PayPal, and  below a lock with Secure Payment text to the right