Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

1–10 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#2
This is huge; also AT&T knew on Apr 19 but only disclosed now; ongoing fallout from the Snowflake compromise:

- Records downloaded from Snowflake cloud platform

- "AT&T will notify 110 million AT&T customers"

- Compromised data includes customer phone numbers ("for 77m customers"), metadata (but not actual content or timestamp of calls and messages), and location-related data. Not SSNs or DOBs. Mostly during a six-month period 5/1-10/31/2022, but more recent records from 1/2/2023 for a smaller but unspecified number of customers. TechCrunch [1] has more details including Mandiant's response, the name and suspects location of the cybercriminal group

[1]: https://techcrunch.com/2024/07/12/att-phone-records-stolen-d...

I wonder if Congress manages to summon TikTok-like levels of anger on regulating this one.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#3
And, honestly, how is this info (which I WOULD want to know) meaningfully actionable to customers. We get our information stolen from a myriad of sources everyday. These companies do comparatively nothing to make things right and the burden falls on customers to pick up the pieces if you're in a tranch that is sold and used.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#7
The real problem is that data needs to be deleted over time. There is not much of a use case for customers for go back last year and see who called them and obviously there are use cases like criminal investigations or spying. But customer has no power or ability to dictate how long their records are store and how they are used. Companies should provide tools and features to their customers empowering them with their data.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#8
Ongoing fallout from the Snowflake compromise; AT&T knew on Apr 19 but only disclosed now (Why does this not fall under SOX violation with the obligation to report timely to affected parties? It has affected AT&T's stock price -3% in early trading, so shouldn't it have also required SEC disclosure?)

- Records downloaded from Snowflake cloud platform

- AT&T will notify 110 million AT&T customers

- Compromised data includes customer phone numbers, metadata (but not actual content or timestamp of calls and messages), and location-related data. Not SSNs or DOBs. Mostly during a six-month period 5/1-10/31/2022, but more recent records from 1/2/2023 for a smaller but unspecified number of customers. TechCrunch report has more details including Mandiant's response, the name and suspects location of the cybercriminal group

I wonder if Congress manages to summon TikTok-like levels of anger on regulating this one.

Post reply on HN