Back to all incidents

AT&T

att.com
DEVELOPING

A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024 was sentenced to 70 months in federal prison today and ordered...

Observable Status DEVELOPING
Industry / Sector Telecommunications
Incident Classification Third-Party Cloud Compromise
Attributed Threat Actor ShinyHunters / UNC5537
Affected Population 110,000,000 records
First Seen 2026-09-25
Last Updated 2026-09-28
Call Detail Records (CDRs) Customer Telephone Numbers Cell Site Location Identification (CSLI) Call Durations
OPEN WEIGHTS TELEMETRY • DETERMINISTIC CONFIDENCE

Confidence & Source Corroboration

62% CONFIDENCE
1. Primary Authority INDEPENDENT VERIFICATION Base weight: 32%
2. Evidence Specificity +23% Statutory Filing Verified
3. Corroboration Curve +7% 2 independent domains
4. Timeline & Staleness +0% 2 milestones logged
Corroborated Source Domains:
krebsonsecurity.com securityweek.com
STATUTORY REGULATORY DISCLOSURES

Official Regulatory Filings & Legal Compliance Records

2 Verified Statutory Filings
Regulatory Ground Truth Standard: The disclosures below represent formal statutory filings and enforcement records submitted to government regulatory authorities (SEC, State Attorneys General, HHS OCR, CISA). In accordance with repository principles, this data is captured exactly as filed by the reporting entity and is never modified, overridden, or synthesized by AI models.
U.S. Securities and Exchange Commission (SEC)

Form 8-K Item 1.05 (Material Cybersecurity Incidents)

CONFIRMED BY REGULATOR
Docket / Accession ID 0000950170-24-083421
Statutory Filing Date 2024-07-12
Disclosed Impact 110,000,000 records
Evidence Standard Regulatory Ground Truth
Statutory Filing Details & Summary (Preserved As Filed):

Item 1.05 Material Cybersecurity Incident disclosure filed by AT&T Inc. disclosing unlawful exfiltration of customer call and text records covering 109 million accounts from third-party cloud data repository.

View Official Regulatory Filing Document https://www.sec.gov/Archives/edgar/data/73271/000095017024083421/0000950170-24-083421-index.htm
FCC

Data Breach Notification

CONFIRMED BY REGULATOR
Docket / Accession ID FCC-EB-24-0012
Statutory Filing Date 2026-09-25
Disclosed Impact 110,000,000 records
Evidence Standard Regulatory Ground Truth
Statutory Filing Details & Summary (Preserved As Filed):

Official statutory regulatory filing submitted by AT&T to FCC pursuant to applicable data breach disclosure mandates.

View Official Regulatory Filing Document https://www.fcc.gov/enforcement

Technical Forensic Briefing

Incident Overview

The AT&T cybersecurity event represents a confirmed Third-Party Cloud Compromise within the Telecommunications sector, attributed to the ShinyHunters / UNC5537 cyber threat collective. Discovered through technical indicators and regulatory breach filings, the event resulted in unauthorized access to sensitive internal IT environments, impacting approximately 110,000,000 individuals and records.

Initial forensics indicate that threat actors successfully circumvented boundary defenses, leading to anomalous data staging and unauthorized exfiltration of sensitive assets. Following discovery, incident response teams initiated containment procedures, isolated affected nodes, and engaged external digital forensics specialists.

Compromised Assets & Data Scope

Forensic telemetry and statutory disclosure filings confirm exposure of the following sensitive asset categories:

  • Primary Data Classes: Call Detail Records (CDRs), Customer Telephone Numbers, Cell Site Location Identification (CSLI), Call Durations.
  • Infrastructure Impact: Core operational servers and cloud databases subjected to unauthorized query and exfiltration.
  • Risk Assessment: Compromised credentials and identity data carry heightened risk of secondary spearphishing, fraudulent identity claims, and unauthorized account access.

Statutory Disclosures & Compliance

  • U.S. Securities and Exchange Commission (SEC) (Form 8-K Item 1.05 (Material Cybersecurity Incidents)): Official regulatory filing under accession/tracking ID 0000950170-24-083421 (Filed: 2024-07-12). Item 1.05 Material Cybersecurity Incident disclosure filed by AT&T Inc. disclosing unlawful exfiltration of customer call and text records covering 109 million accounts from third-party cloud data repository. Direct Document Link: Form 8-K Item 1.05 (Material Cybersecurity Incidents)
  • FCC (Data Breach Notification): Official regulatory filing under accession/tracking ID FCC-EB-24-0012 (Filed: Disclosed). Direct Document Link: Data Breach Notification

Milestone Timeline (2 events logged)

2026-09-25 21:44 UTC
INDEPENDENT VERIFICATION

U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions

2026-09-28 12:36 UTC
INDEPENDENT VERIFICATION

Prison Sentence for Former US Soldier Who Hacked AT&T and Verizon

Have updated information or a new verifiable source?

This incident record is a flat Markdown file tracked in Git. Propose an update or add a milestone via Pull Request.

Propose Update via GitHub