Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

461–470 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#461
When are we going to see the technical report of what happened? Since this data has a specific time frame, it makes sense to me that a backup was stolen. But, we'll see.

My guess is that the tech leaders a AT&T are going to have sore wrists for a few minutes because of this.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#462
Joining the dots on the facts so far, people don't seem to have grasped the apparent huge significance:

- guessing it was some GenAI startup looking into consumer tracking, alternate credit scoring, surveillance or other national-security use-case.

- Very unusually, the DOJ ordered two ~month-long "delay periods" in disclosure: ("The Justice Department determined on May 9 and again on June 5 that a delay in providing public disclosure was warranted"). Yet this didn't happen for Ticketmaster or MOVEit breaches revealed around the same time. "Cybersecurity delay period requests" is a new power quietly authorized by the DOJ+SEC+FBI, 18 Dec 2023 [0]. Note that [1] emphasizes this as "Corporate Alert - guidance for delay requests [on SEC 8-K]". Might Congress already have known/suspected, when it authorized the cybersecurity delay request powers, of the Snowflake/AT&T breach? Either way, whoever is involved seems to have very powerful friends. Also, the big FISA renewal vote was Apr 19 2024 [2].

- Seems the cloud instance was set up the same time GPT-4 was released (March 2023), also when Snowflake set up a Telco business unit [3] ("Location data... Alternate credit scoring, hyper-targeted marketing and more... an emerging trend of companies building partnerships with telecoms to power use cases across multiple industries"). This product is not aimed at the telcos' use-cases, but at new revenue streams. (Who might the unnamed Snowflake AI partner(s) be?)

- They set up the Snowflake instance with AT&T/MVNO customers with timestamps removed, but with location data, yet the phone numbers not obscured or removed. Doesn't sound like "internal analytics" or "competitor analysis". What sorts of end-users want to pay for the entire social-graph of 110m, regardless whether those customers never make a phone call again? [EDIT: I confused the details of this AT&T breach with the other (2019) one disclosed on 3/2024: 77m AT&T/MVNO customers, 90% of them former customers]

[0]: "FBI Guidance to Victims of Cyber Incidents on SEC Reporting Requirements: FBI Policy Notice Summary" https://www.fbi.gov/investigate/cyber/fbi-guidance-to-victim...

[1]: "US Corporate Alert - DOJ, FBI, and SEC provide guidance for delay requests relating to disclosure of cybersecurity incidents under form 8-K" https://www.klgates.com/DOJ-FBI-and-SEC-Provide-Guidance-for...

[2]: US House approves FISA renewal – warrantless surveillance and all https://news.ycombinator.com/item?id=40041784

[3]: Snowflake cloud Telco unit, 4/2023: "Unlocking the Value of Telecom Data: Why It’s Time to Act" https://www.snowflake.com/blog/telecom-data-partnerships/

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#463

AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…

Yeah, you're right. Data breaches are essentially just slaps on the wrist to companies like AT&T. Maybe it's possible to fine them based on the proportion of the userbase that was affected and the profits they generated for a certain time period. I wonder if this will push companies to stop using external vendors to store and process data. If companies stored all of their info in house, it would prevent the case wher…

The reason some companies use external vendors is to outsource the risk.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#464
post #456

Over in Europe this blanket saving of phone records beyond what it is necessary to operate would have been illegal in many countries, and is in general incompatible with the European Convention for the Protection of Human Rights and Fundamental Freedoms outside of active threats to national security and temporary measures overseen by a court.[1] There's really no reason why any service providers should save this stuf…

You live in a place where the government is for the people, not for themselves.

If it wasn't for the courts and a decent de-facto "constitution" (collection of treaties really), governments would absolutely love to expand the amount of data they (police, spy apparatus, etc.) have access to. That they also try to reduce the amount of data companies are allowed to save for themselves is tangential.

The court case I linked is evidence of that. The German state wanted Telekom to save more data, but the telco refused and won in court.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#465

This happened in 2022 and they're just disclosing it now? Or did they just find out about it, which is maybe even worse?

The authorities requested the delay of the disclosure: https://cbs58.com/news/nearly-all-at-t-cell-customers-call-a...

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#466
post #438

Earlier quoted context omitted.

> indeed was best practice until recently But we should remember why it's not always considered best practices... you shouldn't assume that your private network is any more secure than the public network. When you have too many devices attached to that private (overlay?) network, it can be at just as much risk as if it was on the public internet. So, the zero-trust model is that you don't trust anything... public...…

yep was trying to avoid word which carry varying connotations, e.g. vpn or zero trust. zero implicit trust is likely the best term? you have to trust something, but enforce (and therefore trust) strong (not network based) identity, authN and authZ. this can be done anywhere via a software-only overlay. a litmus test is server iptables (to use an example) looks like: iptables -P INPUT DROP iptables -P FORWARD DROP and…

For highly secured services, I completely see the rationale for a private overlayed network. Tailscale, et al are great for this, where you're only exposing services to members of the private network. The problems start when people make the assumption that the private network is a secured network.

I don't think any of this would have mattered to ATT, as the breach was from a third party that wouldn't have been on a private network anyway.

But, that would be a great service bonus -- only being able to connect to a service via a user-configurable private overlay network. It would be nice, but highly impractical... I can't even begin thinking about how customer support would be able to handle a scheme like this.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#467

Earlier quoted context omitted.

What the NSA wants, the NSA gets. No legislation is needed when the system is working as intended.

The NSA shouldn’t need the telcos to retain these records, just hand them over to the NSA to retain right?

It's a good business decision to make others do your work.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#468
post #70

AT&T stock has already bounced back from much of the initial -2.6% drop this morning, so the market thinks AT&T is immune. Meanwhile Snowflake is -3.9% down (they have many other customers than AT&T). https://www.marketwatch.com/investing/stock/T https://www.marketwatch.com/investing/stock/SNOW

I never got the impression that the market ever cares about data breaches. It seems most companies are rarely held financially responsible for data breaches anyway. I would bet any effects you’re seeing in stocks is unrelated to this news.

[dead]

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#469

AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…

> Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the corporate veil and criminally prosecute those whose negligence made this possible. Maybe have fines that are so massive that company leadership and stockholders face real consequences.

I really dislike this attitude.

AT&T were attacked, by criminals. The criminals are the ones who did something wrong, but here you are immediately blaming the victim. You're assuming negligence on the part of AT&T, and to the extent you're right, then I agree that they should be fined in a bigger manner.

But the truth is, given the size and international nature of the internet, there are effectively armies of criminals, sometimes actually linked to governments, that have incredible incentives to breach organizations. It doesn't require negligence for a data breach to occur - with enough resources, almost any organization can be breached.

Put another way - you trust a classical bank, with a money, to secure your money from criminals. But you don't expect it to protect your money in the case of an army attacking it. But that's exactly the situation these organizations are in - anyone on Earth can attack them, very much including basically armies. We cannot expect organizations to be able to defend themselves forever, it is an impossible ask in the long run. This has to be solved by the equivalent of a standing army protecting a country, and by going after the criminals who do these breaches.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#470

Earlier quoted context omitted.

What the NSA wants, the NSA gets. No legislation is needed when the system is working as intended.

The NSA shouldn’t need the telcos to retain these records, just hand them over to the NSA to retain right?

Which leads me to wonder - were any of the NSA’s own employee, call and SMS records at AT&T part of the comprised data?

(edited for grammar)

Post reply on HN