Supply chain β›“ Supply Chain

AT&T Third-Party Breach (July 2024)

πŸ“… 2024-07-01 🏒 Snowflake
Primary Source β†—

Incident Details

Massive AT&T data breach exposes call logs of 109 million customers. AT&T is warning of a massive data breach where threat actors stole the call logs for approximately 109 million customers, or nearly all of its mobile customers, from an online database on the company’s Snowflake account. The company confirmed to BleepingComputer that the data was stolen from the Snowflake account between April 14 and April 25, 2024. In a Friday morning Form 8-K filling with the SEC, AT&T says that the stolen data contains the call and text records of nearly all AT&T mobile clients and customers of mobile virtual network operators (MVNOs) made from May 1 to October 31, 2022 and on January 2, 2023. Third-party company: Snowflake.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Snowflake
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2024-07-01 Breach occurred
  2. 2024-07-12 Publicly disclosed