AT&T Cloud Telecom Call and Text Metadata Exfiltration
Key Facts
- Legal Status: INVESTIGATION in U.S. Securities and Exchange Commission & DOJ National Security Division.
- Primary Target Sector: Telecommunications.
- Documented Financial Loss: $100.0 million.
- 2 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Threat actors accessed an AT&T corporate workspace hosted on Snowflake using compromised credentials that lacked hardware multi-factor authentication.
Operational & Financial Fallout
Exfiltration of phone numbers, call records, and text message metadata covering approximately 110 million wireless customers over six months (May to October 2022). Included cell site tower interaction coordinates enabling geographic tracking. AT&T negotiated and paid a 5.7 Bitcoin ($370,000) extortion payment to verify deletion.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Threat actors accessed an AT&T corporate workspace hosted on Snowflake using compromised credentials that lacked hardware multi-factor authentication.
Adversary Kill Chain Flow
4 Documented PhasesAdversaries authenticated to the AT&T analytical workspace hosted in Snowflake using stolen API access tokens without secondary hardware security key verification.
Attackers executed automated queries to pull massive tables containing Call Detail Records (CDRs), phone numbers, interaction counts, and cell tower IDs.
Extracted records were channeled to external cloud storage buckets controlled by the threat actor group, bypassing perimeter data loss prevention inspection.
Adversaries demanded cryptocurrency extortion to prevent public dissemination, providing video screen recording evidence of database deletion upon receiving 5.7 Bitcoin.
Exfiltration of phone numbers, call records, and text message metadata covering approximately 110 million wireless customers over six months (May to October 2022). Included cell site tower interaction coordinates enabling geographic tracking. AT&T negotiated and paid a 5.7 Bitcoin ($370,000) extortion payment to verify deletion.
Procedural & Incident Timeline
Attackers download phone call and text records of cellular customers from May to October 2022.
AT&T security operations identify unauthorized workspace queries and terminate compromised tokens.
Intermediary transfers 5.7 Bitcoin ($370,000) to threat actor for video proof of database deletion.
AT&T files Form 8-K with the SEC following two national security disclosure delays by the DOJ.
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1078 | Valid Accounts Defense Evasion | "Attackers logged into AT&T customer Snowflake cloud workspace using compromised access tokens without hardware multi-factor verification." | AT&T Form 8-K Current Report to SEC | reviewed |
| T1567 | Exfiltration Over Web Service Exfiltration | "The threat actor exfiltrated phone numbers, call durations, and cell tower interaction identifiers covering May 1 to October 31, 2022." | FCC Formal Notice of Inquiry into AT&T Cloud Breach | reviewed |