{
  "id": "case-att-telecom-metadata-theft",
  "slug": "att-telecom-metadata-snowflake-breach",
  "title": "AT&T Cloud Telecom Call and Text Metadata Exfiltration",
  "summary": "Illegal exfiltration of call and text interaction metadata spanning six months for approximately 110 million AT&T wireless customers. Intrusion stemmed from an illicit access point to a third-party Snowflake cloud environment, leading to a 5.7 Bitcoin extortion fee paid through an intermediary to obtain verified video evidence of dataset deletion.",
  "case_number": "SEC-2024-8K-ATT",
  "court": "U.S. Securities and Exchange Commission & DOJ National Security Division",
  "district": "N.D. Tex.",
  "country": "United States",
  "opened_at": "2024-07-12",
  "status": "investigation",
  "victim_sector": "Telecommunications",
  "victim_country": "United States",
  "loss_amount_usd": 100000000,
  "loss_amount_note": "Major regulatory investigations, carrier mitigation costs, and $370,000 cryptocurrency deletion proof payment.",
  "first_seen_at": "2024-04-14T00:00:00Z",
  "last_updated_at": "2026-09-01T00:00:00Z",
  "actor_slug": "unc5537-scattered-spider",
  "defendant_slugs": [],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1078",
      "evidence_excerpt": "Attackers logged into AT&T customer Snowflake cloud workspace using compromised access tokens without hardware multi-factor verification.",
      "evidence_locator": "AT&T Form 8-K Current Report to SEC",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "SEC Form 8-K AT&T Inc.",
      "source_url": "https://www.sec.gov",
      "technique_name": "Valid Accounts",
      "tactic": "Defense Evasion"
    },
    {
      "technique_id": "T1567",
      "evidence_excerpt": "The threat actor exfiltrated phone numbers, call durations, and cell tower interaction identifiers covering May 1 to October 31, 2022.",
      "evidence_locator": "FCC Formal Notice of Inquiry into AT&T Cloud Breach",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "FCC Public Notice",
      "source_url": "https://www.fcc.gov",
      "technique_name": "Exfiltration Over Web Service",
      "tactic": "Exfiltration"
    }
  ],
  "events": [
    {
      "event_type": "incident",
      "event_date": "2024-04-19",
      "description": "Attackers download phone call and text records of cellular customers from May to October 2022."
    },
    {
      "event_type": "discovery",
      "event_date": "2024-05-17",
      "description": "AT&T security operations identify unauthorized workspace queries and terminate compromised tokens."
    },
    {
      "event_type": "ransom_payment",
      "event_date": "2024-05-25",
      "description": "Intermediary transfers 5.7 Bitcoin ($370,000) to threat actor for video proof of database deletion."
    },
    {
      "event_type": "disclosure",
      "event_date": "2024-07-12",
      "description": "AT&T files Form 8-K with the SEC following two national security disclosure delays by the DOJ."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Threat actors accessed an AT&T corporate workspace hosted on Snowflake using compromised credentials that lacked hardware multi-factor authentication.",
    "blast_radius": "Exfiltration of phone numbers, call records, and text message metadata covering approximately 110 million wireless customers over six months (May to October 2022). Included cell site tower interaction coordinates enabling geographic tracking. AT&T negotiated and paid a 5.7 Bitcoin ($370,000) extortion payment to verify deletion.",
    "kill_chain": [
      {
        "phase": "Workspace Access",
        "title": "Compromised Access Token Authentication",
        "description": "Adversaries authenticated to the AT&T analytical workspace hosted in Snowflake using stolen API access tokens without secondary hardware security key verification.",
        "technical_artifacts": [
          "Snowflake analytical tokens",
          "API query session logs"
        ],
        "mitre_technique_id": "T1078"
      },
      {
        "phase": "Mass Query & Harvesting",
        "title": "Call Detail Record (CDR) Data Extraction",
        "description": "Attackers executed automated queries to pull massive tables containing Call Detail Records (CDRs), phone numbers, interaction counts, and cell tower IDs.",
        "technical_artifacts": [
          "SQL table SELECT queries",
          "CDR database views",
          "Tower identification records"
        ],
        "mitre_technique_id": "T1530"
      },
      {
        "phase": "Data Exfiltration",
        "title": "Cloud-to-Cloud Data Transfer",
        "description": "Extracted records were channeled to external cloud storage buckets controlled by the threat actor group, bypassing perimeter data loss prevention inspection.",
        "technical_artifacts": [
          "External cloud storage bucket",
          "Compressed tar.gz partitions"
        ],
        "mitre_technique_id": "T1567"
      },
      {
        "phase": "Verification & Deletion",
        "title": "Extortion Negotiation and Deletion Proof",
        "description": "Adversaries demanded cryptocurrency extortion to prevent public dissemination, providing video screen recording evidence of database deletion upon receiving 5.7 Bitcoin.",
        "technical_artifacts": [
          "Bitcoin blockchain transaction",
          "Video verification proof",
          "Intermediary forensic escrow"
        ],
        "mitre_technique_id": "T1485"
      }
    ],
    "defensive_takeaways": [
      "Apply zero trust conditional access policies requiring managed device certificates and hardware FIDO2 tokens for all cloud analytical environments.",
      "Implement strict data masking and tokenization on Call Detail Records and customer telephony metadata.",
      "Establish continuous behavioral anomaly detection on bulk database query volumes and off-hours extraction.",
      "Require network IP allowlisting for all third-party cloud data warehouse connections."
    ]
  }
}