The Quick Read
On July 12, 2024, AT&T filed an 8-K with the SEC confirming that a threat actor had copied call and text records for “nearly all” of AT&T’s wireless customers and MVNO customers on AT&T’s network. [1] The records covered interactions between roughly May 1, 2022 and October 31, 2022, plus January 2, 2023. [1] AT&T’s 8-K says the files were taken from an AT&T workspace on a third-party cloud platform. [1] Public reporting names AT&T among the companies affected by the campaign against Snowflake customer accounts. [3] Mandiant, which tracks the campaign as UNC5537, says Mandiant and Snowflake notified approximately 165 potentially exposed organizations. [2] Companies publicly named as affected include Ticketmaster, Santander, Advance Auto Parts, LendingTree, Neiman Marcus, and Bausch Health. [3] AT&T’s stolen dataset did not include the contents of calls or texts, names, SSNs, or dates of birth, but it did include the phone numbers you talked to and, for a subset of records, the cell tower IDs that pin you to a place. [1]
What AT&T Said Was Stolen
AT&T’s own SEC filing is the most reliable record of what was actually copied. Read carefully, because the headline number is scarier than the file contents.
The records exfiltrated contained, per the 8-K AT&T filed on July 12, 2024:
- Telephone numbers of AT&T customers.
- Telephone numbers of customers those AT&T customers called or texted.
- Counts of those interactions and aggregate call duration for a day or month.
- For a subset of records, one or more cell site identification numbers tied to a call or text event.
The same filing explicitly says what was not in the file:
- The content of any calls or texts.
- Social Security numbers, dates of birth, or other standard personal identifiers.
- Customer names.
AT&T’s 8-K describes the scope as “nearly all of AT&T’s wireless customers and customers of mobile virtual network operators (‘MVNO’) using AT&T’s wireless network.” [1] The records cover interactions between approximately May 1, 2022 and October 31, 2022, plus January 2, 2023. [1]
If you were an AT&T wireless customer at any point from May to October 2022 and you made or received a call or text, your phone number and the phone number of the other party are likely in this database. The 8-K says the records include telephone numbers of AT&T wireline customers and customers of other carriers. [1]
What Was Not Stolen
Two details are easy to misread and worth slowing down on.
No names, no SSNs, no DOBs. AT&T’s filing says the records did not include customer names. [1] That means the file is, by itself, a list of phone numbers and call relationships, not a list of people. That is reassuring on its face. It is much less reassuring when you consider the third parties who can attach names to phone numbers in seconds: data brokers, public people-search sites, marketing databases, leaked contact lists from other breaches, and the carrier itself.
No content. Nobody can replay your calls or read your texts from this file. End-to-end encrypted messengers (Signal, WhatsApp, iMessage) are not affected because the metadata captured here is the carrier-level call detail record, not the contents of the chat. Standard SMS and standard phone calls were always visible to AT&T as metadata, so the breach does not put anything new in a different adversary’s hands on that axis.
What an attacker does get is the pattern: who you talked to, how often, when, and from which cell tower. That is enough to infer medical visits, romantic relationships, business contacts, political organizing, immigration status conversations, and any other sensitive category of association.
How the Breach Happened
The disclosure was not a ransomware-style break-in. AT&T’s 8-K says threat actors unlawfully accessed an AT&T workspace on a third-party cloud platform and, between April 14 and April 25, 2024, exfiltrated files containing AT&T records of customer call and text interactions. [1]
Mandiant published its report on the campaign on June 10, 2024, tracking the threat cluster as UNC5537. [2] According to that report, the attackers used Snowflake customer credentials previously exposed via infostealer malware (named variants include VIDAR, RISEPRO, REDLINE, RACOON STEALER, LUMMA, METASTEALER). [2]
Mandiant’s report lists three primary failures that allowed the campaign to succeed:
- No MFA. Many of the affected Snowflake customer accounts required only a username and password. [2]
- Stale credentials. Credentials found in infostealer output were still valid, in some cases years after they were stolen, and had not been rotated or updated. The earliest infostealer infection date Mandiant observed for a credential used in the campaign dated back to November 2020. [2]
- No network allow-lists. The impacted Snowflake customer instances did not have network allow lists in place to only allow access from trusted locations. [2]
Mandiant wrote that at least 79.7% of the accounts leveraged by the threat actor in this campaign had prior credential exposure. [2] In other words: the campaign exploited the infostealer marketplace, not a novel Snowflake vulnerability.
Mandiant says it began notifying potential victims through its Victim Notification Program and that Mandiant and Snowflake have notified approximately 165 potentially exposed organizations. [2] Mandiant assesses with moderate confidence that UNC5537 comprises members based in North America and collaborates with an additional member in Turkey, and it assesses that UNC5537 will continue targeting additional SaaS platforms. [2]
The Wider Snowflake Campaign: Who Else Was Hit
AT&T was not the only company hit. The other named victims that have been publicly disclosed include:
- Ticketmaster / Live Nation. Ticketmaster’s own data security incident notice confirms that “limited personal information of some customers who bought tickets to events in North America” was exposed, including email, phone number, encrypted credit card information, and other personal details. [4] The Record reported on June 3, 2024 that Live Nation, in an 8-K filing, said it discovered unauthorized activity in a third-party cloud database that contained information primarily from Ticketmaster, and that Ticketmaster confirmed to TechCrunch the leaked data was from a database hosted on Snowflake. [5] ShinyHunters claimed to have a 1.3 terabyte database of information on about 560 million Ticketmaster users, including names, addresses, emails, phone numbers, event details and information on specific orders, and allegedly credit card details including the last four digits of card numbers. [5]
- Banco Santander. Santander’s own statement, dated May 14, 2024, confirms that an attacker accessed a database hosted by a third-party provider. [6] The bank said the database contained certain information relating to customers of Santander Chile, Spain, and Uruguay, and the data of all current and some former Santander employees across the group. [6] The same statement says the database did not contain transactional data or credentials enabling transactions. [6]
- LendingTree, Advance Auto Parts, Neiman Marcus, Bausch Health. Named by Wikipedia’s compiled public reporting on the campaign as confirmed Snowflake campaign victims. [3]
The pattern Mandiant describes across the campaign: a cloud account, a stolen credential, no MFA, and a password that had not been rotated. [2] The attack was not novel. The blast radius was.
Timeline of the AT&T Disclosure
- April 19, 2024: AT&T first learned that a threat actor claimed to have unlawfully accessed and copied AT&T call logs. [1]
- May 9, 2024 and June 5, 2024: The U.S. Department of Justice determined that, under Item 1.05(c) of Form 8-K, a delay in providing public disclosure was warranted. [1]
- June 10, 2024: Mandiant publishes its UNC5537 report. [2]
- July 12, 2024: AT&T files its 8-K with the SEC. The filing says AT&T will provide notice to its current and former impacted customers. [1]
AT&T’s 8-K says the company took additional cybersecurity measures, “including closing off the point of unlawful access,” and is working with law enforcement. The filing notes that “at least one person has been apprehended,” though the SEC filing does not name who. [1] Mandiant assesses with moderate confidence that UNC5537 has members based in North America and an additional member in Turkey. [2]
What an Attacker Can Do With This File
A list of phone numbers and call relationships is a starter kit for several specific follow-on attacks.
SIM swap fraud. SIM swap fraud convinces a carrier to port a target’s phone number to a new SIM controlled by the attacker. The attacker then intercepts SMS-based one-time codes for banking, email, social media, and crypto exchanges. Knowing the target’s phone number, the people they call often, and the cell tower IDs they usually connect to gives a SIM swap social-engineering call to a carrier employee a lot more credibility. The data stolen in this breach is the kind of dossier that helps an attacker pick a target and frame the conversation.
Targeted phishing (“vishing”). A phishing call that references a real recent contact between you and your bank, doctor, or lawyer is dramatically more convincing than a generic “your account has been compromised” call. The stolen call detail records supply the recent contacts.
Location history reconstruction. Cell site IDs are tied to specific cell towers with known geographic coordinates. Given a long enough window, the location history of a phone number can be reconstructed to a coarse neighborhood level. The AT&T file covers six months of records. That is enough to identify regular destinations: home, work, school, a clinic, a place of worship, a partner’s home.
Social graph mapping. The list of numbers you communicate with most often is a social graph. That graph can identify romantic partners, business associates, confidential sources, attorneys, doctors, and political organizers. Once the graph is known, the attacker can move laterally by targeting the contacts of the original target.
Law enforcement and intelligence interest. Governments already obtain communications data through other routes. A declassified 2022 ODNI report says the intelligence community acquires commercially available information, and describes a DIA-funded purchase of "commercially available geolocation metadata aggregated from smartphones." [7] Section 702 of FISA authorizes "the targeting of persons reasonably believed to be located outside the United States to acquire foreign intelligence information" and lets the government direct an electronic communication service provider to assist. [8] Executive Order 12333 assigns signals intelligence collection to the NSA. [9] A leaked copy in criminal hands does not displace that demand; it sits alongside it.
What To Do Right Now
These steps are based on what was actually stolen. They are not generic breach advice.
- Stop using SMS for second factors. Move any SMS-based two-factor authentication on banking, email, social media, and crypto accounts to an authenticator app (Authy, Google Authenticator) or a hardware security key (YubiKey, Titan). SMS is the single highest-risk channel exposed by this breach because it directly enables SIM swap and account takeover.
- Lock your carrier account against SIM changes and port-outs. FCC rules adopted in November 2023 require wireless carriers to authenticate customers with secure methods before a SIM change or a number port, and say that "readily available biographical information, account information, recent payment information, and call detail information do not constitute secure methods of authentication." The same rules require carriers to notify customers of port-out requests and to let customers lock their accounts to prevent SIM changes and port-outs. [10] Ask your carrier to turn that lock on, and set any account PIN or passcode it offers to something other than your date of birth or the last four digits of your SSN.
- Freeze your credit at all three bureaus. A credit freeze is free and stops new credit accounts from being opened in your name. The breach did not include SSNs, but the call detail records plus public data brokers are enough to enable targeted identity fraud against specific individuals.
- Audit your account recovery options. For any account that can be recovered by a phone number, switch the recovery to an authenticator app or a hardware key. SMS-based recovery is now a known-compromised channel.
- Be alert for targeted phishing for the next 12 months. A phishing call or text that knows who you actually called is the immediate follow-on risk. Treat any unsolicited contact that references a real prior call or text as a probable attack.
How to Tell If You Were Affected
AT&T’s 8-K says the company “will provide notice to its current and former impacted customers.” [1] The disclosure says the records covered “nearly all” AT&T wireless customers during the affected window. If you were an AT&T postpaid or prepaid wireless customer (or an MVNO customer riding AT&T’s network) between May and October 2022, or on January 2, 2023, treat your phone number as exposed.
The Federal Trade Commission’s IdentityTheft.gov site is the right place to start if you want to file an identity-theft report or check your options for fraud alerts.
What Happened Since
This page covers the 2024 incident as AT&T and Mandiant described it at the time. Two later reports on this site follow the data into 2026:
- AT&T Breach Data Resurfaces (February 4, 2026): a dataset circulating since February 2, 2026 combines AT&T customer data from the 2024 breaches into 176 million records, with up to 148 million Social Security numbers.
- AT&T Zombie Breach: 176 Million Enriched Records Now Circulating (February 12, 2026): how the earlier AT&T breach data was reportedly merged with the July 2024 Snowflake call and text records and its encrypted Social Security numbers decrypted.
The Bottom Line
This breach is a metadata breach, not an identity-credentials breach. That distinction matters because the response is different.
You do not need to replace your SSN. You do need to assume that for the rest of your life, anyone who has this file can map who you talked to, when, and roughly from where. The failure belongs to the company that stored that metadata, not to the customers whose calls it records. The fix is not a new credit-monitoring subscription. The fix is to remove SMS from your second-factor stack, lock your carrier account against SIM changes and port-outs, and treat any future unsolicited contact that cites your recent communications as adversarial.
Mandiant’s own assessment is that UNC5537 will keep running the same playbook against other SaaS platforms. [2] The lesson generalizes: if a service you rely on stores sensitive records and lets you log in with only a password, your data is at the same risk AT&T was at in 2024. Ask the vendor what they have done about MFA since.
References
- AT&T Inc. SEC Form 8-K filing, cybersecurity incident disclosure (accession 0000732717-24-000046, July 12, 2024)
- Mandiant / Google Cloud Threat Intelligence: UNC5537 Targets Snowflake Customer Instances for Data Theft and Extortion (June 10, 2024)
- Wikipedia: Snowflake data breach (corroborating timeline and named-victim list)
- Ticketmaster: Data Security Incident help page (vendor disclosure)
- The Record: Live Nation confirms Ticketmaster breach on Snowflake (June 3, 2024)
- Banco Santander: Official statement on the May 2024 data breach (May 14, 2024)
- Office of the Director of National Intelligence: Declassified Senior Advisory Group report on commercially available information (January 2022)
- 50 U.S.C. § 1881a: Procedures for targeting certain persons outside the United States other than United States persons (FISA Section 702)
- Executive Order 12333: United States Intelligence Activities (National Archives)
- FCC 23-95: Protecting Consumers from SIM Swap and Port-Out Fraud, Report and Order (November 16, 2023)