AT&T is Providing Evergreen Consumer Advice regarding a Data Security Attack on its Cellular Customers’ Networks in 2022 and 2023
AT&T revealed that a cybersecurity attack had exposed call records and texts from all of the carrier’s cellular customers (including people on mobile virtual network operators, or MVNOs), that use its network. The data breach includes data from May 1st, 2022. October 31st, 2022, and a small group of customers on January 2nd, 2023.
The downloaded data doesn’t include the content of any calls or texts. It doesn’t have the time stamps for the calls or texts. It also doesn’t have any details such as Social Security numbers, dates of birth, or other personally identifiable information.
There are a number of ways to find the name associated with a specific telephone number if the data does not include customer names.
The Dallas-based telecommunications company announced the massive data breach in a regulatory filing and press release on Friday morning, which said it believes the data is no longer publicly available.
The company wrote that the Justice Department decided a delay in providing public disclosure was needed because it first learned of the incident in April.
The records show the number of calls, texts, and durations that customers had with other telephone numbers, as well as AT&T’s landline and cell phone numbers.
The company says it will notify impacted users by text, email or U.S. mail, and has also set up a webpage where current and former customers can check to see if their information was involved.
It offers some evergreen advice for people who are concerned about online fraud, like not replying to a text with personal details from unknown sender and making sure websites are secure.
It adds that customers who suspect suspicious text activity should forward the message to AT&T, and report any suspected fraud on their AT&T wireless account to its team.
The Social Security Numbers of the U.S. Population are Not Included in a Dataset of Social Security Data and Data from Users’ Accounts
In March, it said that it reset the password of about 7.6 million users after it found a dataset containing Social Security numbers and other data of 70 million current and former account holders.



