Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

11–20 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#11

And, honestly, how is this info (which I WOULD want to know) meaningfully actionable to customers. We get our information stolen from a myriad of sources everyday. These companies do comparatively nothing to make things right and the burden falls on customers to pick up the pieces if you're in a tranch that is sold and used.

Of course it's not meaningfully actionable to customers, big time lag in not disclosing since Apr 19. (Why does this not fall under SOX violation with the obligation to report timely to affected parties? It has affected AT&T's stock price -3% in early trading, so should it have also required SEC disclosure?)

Wondering what is the significance that most of the stolen records were from the period 5/1-10/31/2022? Does it mean that AT&T enabled 2FA on more recent records, or that more recent records were on a different cloud bucket (or that they mostly stopped using Snowflake since)?

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#16
post #8

Ongoing fallout from the Snowflake compromise; AT&T knew on Apr 19 but only disclosed now (Why does this not fall under SOX violation with the obligation to report timely to affected parties? It has affected AT&T's stock price -3% in early trading, so shouldn't it have also required SEC disclosure?) - Records downloaded from Snowflake cloud platform - AT&T will notify 110 million AT&T customers - Compromised data inc…

> Snowflake blamed the data thefts on its customers for not using multi-factor authentication to secure their Snowflake accounts, a security feature that the cloud data giant did not enforce or require its customers to use.

So AT&T put all our call information somewhere and hid it probably behind a weak password with no additional factors. IMO that's actionable negligence and I hope they get sued to oblivion.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#17
post #6

Including all location metadata associated to that?

The reports said celltower-level location data associated with calls and texts (but not datestamps). That would allow inferring their homes, job location, commute, family members, social graph.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#18
post #8

Ongoing fallout from the Snowflake compromise; AT&T knew on Apr 19 but only disclosed now (Why does this not fall under SOX violation with the obligation to report timely to affected parties? It has affected AT&T's stock price -3% in early trading, so shouldn't it have also required SEC disclosure?) - Records downloaded from Snowflake cloud platform - AT&T will notify 110 million AT&T customers - Compromised data inc…

> Snowflake blamed the data thefts on its customers for not using multi-factor authentication to secure their Snowflake accounts, a security feature that the cloud data giant did not enforce or require its customers to use. So AT&T put all our call information somewhere and hid it probably behind a weak password with no additional factors. IMO that's actionable negligence and I hope they get sued to oblivion.

I'm more stunned that AT&T knew back on Apr 19 [UPDATE: Mar 20] yet feels it had neither an SOX violation or SEC obligation (share price effect) to notify timely. Like, by Apr 22. Not three months later [UPDATE: 4 months later].

Remember the massive Yahoo 2014 hack which Yahoo management failed to notify its own users for 2 years?

If SOX violation only literally covers users' own passwords getting breached, but not 2FA or other passwords to access the same data, will Congress amend it urgently?

EDIT: apparently they're hiding behind the 3/20 disclosure [0] which is all they disclosed until [1],[2] today.

[0]: March 30, 2024 - "AT&T Addresses Recent Data Set Released on the Dark Web" https://about.att.com/story/2024/addressing-data-set-release...

> "AT&T has determined that AT&T data-specific fields were contained in a data set released on the dark web; source is still being assessed...

> "AT&T has launched a robust investigation supported by internal and external cybersecurity experts. Based on our preliminary analysis, the data set appears to be from 2019 or earlier [incorrect], impacting... approx 7.6m current and 65.4m former AT&T account holders"*

> "Currently, AT&T does not have evidence of unauthorized access to its systems resulting in exfiltration of the data set.... As of today, this incident has not had a material impact on AT&T’s operations."* [but did it have a material impact on the customers/ex-customers?!]

[1]: Jul 12, 2024 - "AT&T Addresses Recent Incidents Regarding Access to Data" https://about.att.com/pages/data-incident.html

[2]: Jul 12, 2024 - "AT&T Addresses Illegal Download of Customer Data" https://about.att.com/story/2024/addressing-illegal-download...

> "Based on our investigation, the compromised data includes files containing AT&T records of calls and texts of nearly all of customers of [AT&T’s cellular and (MVNOs) using AT&T’s wireless network], as well as AT&T’s landline customers who interacted with those cellular numbers between May 1, 2022 - October 31, 2022. The compromised data also includes records from January 2, 2023, for a very small number of customers. The records identify the telephone numbers an AT&T or MVNO cellular number interacted with during these periods. For a subset of records, one or more cell site identification number(s) associated with the interactions are also included."

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#19
So where/what is my compensation? (I know there is no recourse).

When no one is on the hook for secure practices, like enabling MFA on your effin data stores that contain massive amounts of customer PII, this is the result. Not even an apology, just report it and move on. woops! those gosh darned cyber criminals.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#20

How has Snowflake felt ANY recourse for being the source of all of these hacks?

The dark web and info stealing malware are the source of the hacks.

My worry is not only that consumers get numb to breaches, but they consume rampant misinformation and have no idea how to hold appropriate parties accountable.

How many times have you held AWS accountable for stolen access keys?

Was it AWS fault when rabbit leaked their own keys?

Is it snowflakes fault when you lose your creds to infostealing malware?

How should snowflake enforce mfa on machine service account credentials?

The answers are no, no, and they can not possibly. Not even hyperscalers have this magic.

Post reply on HN