CASE DOSSIER investigation

AT&T Cloud Telecom Call and Text Metadata Exfiltration

Docket: SEC-2024-8K-ATT Court: U.S. Securities and Exchange Commission & DOJ National Security Division Opened: 2024-07-12 Sector: Telecommunications

Key Facts

Status
INVESTIGATION
Legal disposition
Loss Amount
$100.0 million
Major regulatory investigations, carrier mitigation costs, and $370,000 cryptocurrency deletion proof payment.
Techniques
2
Verified mappings
Defendants
0
Named in charges
  • Legal Status: INVESTIGATION in U.S. Securities and Exchange Commission & DOJ National Security Division.
  • Primary Target Sector: Telecommunications.
  • Documented Financial Loss: $100.0 million.
  • 2 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Illegal exfiltration of call and text interaction metadata spanning six months for approximately 110 million AT&T wireless customers. Intrusion stemmed from an illicit access point to a third-party Snowflake cloud environment, leading to a 5.7 Bitcoin extortion fee paid through an intermediary to obtain verified video evidence of dataset deletion.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Threat actors accessed an AT&T corporate workspace hosted on Snowflake using compromised credentials that lacked hardware multi-factor authentication.

Operational & Financial Fallout

Exfiltration of phone numbers, call records, and text message metadata covering approximately 110 million wireless customers over six months (May to October 2022). Included cell site tower interaction coordinates enabling geographic tracking. AT&T negotiated and paid a 5.7 Bitcoin ($370,000) extortion payment to verify deletion.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: INVESTIGATION
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Threat actors accessed an AT&T corporate workspace hosted on Snowflake using compromised credentials that lacked hardware multi-factor authentication.

Adversary Kill Chain Flow

4 Documented Phases
1
Workspace Access Compromised Access Token Authentication
MITRE ATT&CK T1078 →

Adversaries authenticated to the AT&T analytical workspace hosted in Snowflake using stolen API access tokens without secondary hardware security key verification.

Artifacts & Tooling: Snowflake analytical tokens API query session logs
2
Mass Query & Harvesting Call Detail Record (CDR) Data Extraction
MITRE ATT&CK T1530 →

Attackers executed automated queries to pull massive tables containing Call Detail Records (CDRs), phone numbers, interaction counts, and cell tower IDs.

Artifacts & Tooling: SQL table SELECT queries CDR database views Tower identification records
3
Data Exfiltration Cloud-to-Cloud Data Transfer
MITRE ATT&CK T1567 →

Extracted records were channeled to external cloud storage buckets controlled by the threat actor group, bypassing perimeter data loss prevention inspection.

Artifacts & Tooling: External cloud storage bucket Compressed tar.gz partitions
4
Verification & Deletion Extortion Negotiation and Deletion Proof
MITRE ATT&CK T1485 →

Adversaries demanded cryptocurrency extortion to prevent public dissemination, providing video screen recording evidence of database deletion upon receiving 5.7 Bitcoin.

Artifacts & Tooling: Bitcoin blockchain transaction Video verification proof Intermediary forensic escrow
Real-World Blast Radius & Operational Fallout

Exfiltration of phone numbers, call records, and text message metadata covering approximately 110 million wireless customers over six months (May to October 2022). Included cell site tower interaction coordinates enabling geographic tracking. AT&T negotiated and paid a 5.7 Bitcoin ($370,000) extortion payment to verify deletion.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Apply zero trust conditional access policies requiring managed device certificates and hardware FIDO2 tokens for all cloud analytical environments.
✓ Implement strict data masking and tokenization on Call Detail Records and customer telephony metadata.
✓ Establish continuous behavioral anomaly detection on bulk database query volumes and off-hours extraction.
✓ Require network IP allowlisting for all third-party cloud data warehouse connections.

Procedural & Incident Timeline

2024-04-19 incident

Attackers download phone call and text records of cellular customers from May to October 2022.

2024-05-17 discovery

AT&T security operations identify unauthorized workspace queries and terminate compromised tokens.

2024-05-25 ransom_payment

Intermediary transfers 5.7 Bitcoin ($370,000) to threat actor for video proof of database deletion.

2024-07-12 disclosure

AT&T files Form 8-K with the SEC following two national security disclosure delays by the DOJ.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1078 Valid Accounts
Defense Evasion
"Attackers logged into AT&T customer Snowflake cloud workspace using compromised access tokens without hardware multi-factor verification." AT&T Form 8-K Current Report to SEC reviewed
T1567 Exfiltration Over Web Service
Exfiltration
"The threat actor exfiltrated phone numbers, call durations, and cell tower interaction identifiers covering May 1 to October 31, 2022." FCC Formal Notice of Inquiry into AT&T Cloud Breach reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, AT&T Cloud Telecom Call and Text Metadata Exfiltration, No. SEC-2024-8K-ATT (U.S. Securities and Exchange Commission & DOJ National Security Division 2024), https://cybercaselibrary.com/cases/att-telecom-metadata-snowflake-breach/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/att-telecom-metadata-snowflake-breach" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>