AT&T has acknowledged the authenticity of a dataset containing the small print of 73 million present and former prospects after a hacker marketed it on a dark web marketplace round March 17.
🚨BREAKING🚨Allegedly, a risk actor has uncovered knowledge from AT&T @ATT. They declare the information reveals SSN, DOB, Full Names, Telephone, Addresses, Emails, and different information. The quantity of data are 73,481,539. #ATT #Clearnet #DarkWebInformer #Cyberattack #Cybercrime #Infosec #CTI pic.twitter.com/6Q3KPPkpFK
— Darkish Net Informer (@DarkWebInformer) March 17, 2024
Writing in a discover on Saturday, the telecommunications large revealed that the dataset includes data courting again to 2019 or earlier, affecting roughly 7.6 million current AT&T account holders and about 65.4 million previous prospects.
“The priority is especially round inside processes at AT&T, which initially denied {that a} knowledge breach even occurred again in 2021 earlier than admitting it,” commented Zendata CEO, Narayana Pappu.
“Assuming this data is from the earlier hack, hopefully, AT&T has already carried out remediation, asking customers to replace their data. If it has not, AT&T ought to consider the processes they’ve in place to determine publicity and remediation.”
Learn extra on the 2021 claims: AT&T Denies Knowledge Breach
Whereas AT&T has now confirmed that particular knowledge fields from the printed dataset align with its data, the corporate mentioned it stays unsure whether or not these originated from AT&T itself or one in every of its distributors.
An investigation has been initiated by AT&T to delve into the matter additional. Nevertheless, the supply of non-public data, resembling social safety numbers, remains to be beneath analysis.
Presently, AT&T has not discovered proof indicating unauthorized entry to its methods ensuing within the elimination of the dataset. The corporate has taken proactive steps to have interaction with affected people, providing credit score monitoring companies the place acceptable.
Present and former prospects are inspired to go to the official AT&T web site for extra data. Regardless of the severity of the state of affairs, the corporate asserts that the incident has not but considerably impacted its day-to-day operations.
“Present and former AT&T prospects ought to assume they’ve already been breached and act accordingly,” warned Anne Cutler, cybersecurity evangelist at Keeper Safety.
In line with the safety skilled, people ought to take proactive measures. These embrace updating their AT&T account login credentials, subscribing to a darkish internet monitoring service, overseeing or freezing their credit score and adhering to sound cyber-hygiene practices.
“By utilizing sturdy and distinctive passwords for each account, enabling MFA in every single place potential, updating software program usually and at all times pondering earlier than they click on, people can drastically improve their private cybersecurity,” concluded Cutler.
The AT&T discover comes weeks after American Categorical warned customers that bank card knowledge was uncovered in a third-party breach.
Picture credit score: viewimage / Shutterstock.com