
What you need to know
- AT&T has confirmed that about 9 million customer accounts were exfiltrated after a third-party marketing vendor was hacked.
- As a result of the data breach, customer information such as names, account numbers, phone numbers, and email addresses were compromised.
- Nevertheless, AT&T’s own systems were not affected by the compromise.
AT&T has notified customers that one of its third-party vendors has experienced a data breach in which an attacker has access to information related to the customer’s “device upgrade eligibility.”
A major security breach affected approximately 9 million customer accounts. This happened in January, the same month T-Mobile suffered a massive data breach affecting about 37 million postpaid and prepaid accounts.
AT&T rep quoted by Bleeping Computer (opens in new tab) It said the incident compromised customer-specific network information, including data about the number of lines on an account or wireless tariff plan. In addition, personally identifiable information such as his name, his wireless account number, wireless phone number, and his email address was exposed.
In some cases, the hacks also affected customer information such as monthly payment amounts, delinquent amounts, rate plan names, monthly charges and hours of use.
A wireless carrier acknowledged a security breach in response to a customer who inquired on a forum page. (opens in new tab) Whether the email sent to the customer affected by the CPNI violation was legitimate. Federal law enforcement agencies have already been notified of the unauthorized access of CPNI pursuant to the Federal Communications Commission, according to a company spokesperson.
Fortunately, the breach did not involve credit card information, social security numbers, or account passwords. AT&T’s own systems were also not compromised.
AT&T has also confirmed that the vulnerability has been fixed. This latest hack is the first AT&T has had to deal with in a long time and proves that there are endless ways hackers can carry out fraud and identity theft.