Hackers stole almost everyone’s AT&T call records. What should you do? (2024)

Another day, another data breach. But this one is nasty.

AT&T said Friday that hackers who have hit other companies also swiped at least six months of 2022 phone records for — that’s roughly 110 million customer accounts. AT&T said hackers don’t have the content of people’s calls or texts.

For what AT&T says is a portion of those records, the stolen data also included some people’s estimated locations.

The swiped location data is relatively unusual in a cyberattack, and it’s the part that freaked out Albert Fox Cahn, founder of the Surveillance Technology Oversight Project.

GET CAUGHT UP

Stories to keep you informed

Dissenting Republican delegates sign protest of Trump platform SparkleSummary is AI-generated, newsroom-reviewed.
U.S., Germany foiled Russian plot to assassinate CEO of arms manufacturer, officials saySparkleSummary is AI-generated, newsroom-reviewed.
Family of teen who died after ‘One Chip Challenge’ sues snack companySparkleSummary is AI-generated, newsroom-reviewed.
La Niña is coming. Here’s how it could change the weather.SparkleSummary is AI-generated, newsroom-reviewed.
Do landlords have to provide AC? Here’s what renters should know.SparkleSummary is AI-generated, newsroom-reviewed.

Your phone company logs the nearest cellular tower every time your device connects to its mobile network. That data is essentially a rough timeline and map of everywhere you go with your smartphone, including your home, work, house of worship, medical appointments and more.

Advertisem*nt

Skip to end of carousel

Shira Ovide

Hackers stole almost everyone’s AT&T call records. What should you do? (6)Hackers stole almost everyone’s AT&T call records. What should you do? (7)

Tech Friend writer Shira Ovide gives you advice and context to make technology work for you. Sign up for the free Tech Friend newsletter.

End of carousel

“It’s such an invasive window into our lives,” Cahn said. The stolen location records about AT&T customers were limited to data from older 3G mobile connections and during slices of the day, an AT&T spokeswoman said. That’s probably a relatively limited amount of data on customers’ estimated whereabouts.

You can’t know for sure how this stolen AT&T information might be used against you. I’ll talk you through how to know if your data was swiped, what could go wrong and how to protect yourself.

Also, take a moment to feel furious. This data theft shows the risks from the United States’ largely unregulated personal data harvesting. You, and generally not the companies, bear the burden when companies fail to secure your information from thieves.

How do you know whether your phone records were stolen?

AT&T said it will notify affected customers by text, email or physical mail.

Advertisem*nt

But if you had AT&T mobile service between the beginning of May and the end of October in 2022 or on Jan. 2, 2023, you should assume your phone records were stolen.

What information is in those hacked phone records?

The swiped records include information like every number you texted and called and how many times you called your spouse in a given month and the cumulative time those calls lasted.

AT&T said monthly wireless and home telephone customers can go to this website to see the phone numbers of your calls and texts that were in the stolen records.

AT&T said that the names associated with accounts, Social Security numbers and credit card numbers weren’t stolen.

Another potential risk may be from the stolen logs of AT&T customers’ locations.

Even if the stolen data had relatively limited data about customers’ physical whereabouts when they connect to a mobile network, the location data from cellphones is so sensitive that the Supreme Court has said it generally deserves extra legal protections. Police must have a warrant to obtain the kind of location data that thieves just stole from AT&T.

What do you have to worry about?

AT&T’s statement said it doesn’t believe the stolen phone records have been leaked online. But Cahn said the thieves could at any time sell the phone records to other criminals or post them on the web for anyone to see.

Advertisem*nt

With information like the numbers you frequently call, a crook could impersonate your boss, brother or bank to get you to hand over money, said Frédéric Rivain, chief technology officer of the password management service Dashlane. (Although crooks already can and do impersonate your contacts’ phone numbers without stealing your phone records.)

In the wrong hands, stolen data from phone records could also be used to blackmail people having affairs, for criminals to find the homes of police officers and prosecutors, or for abusers to track down their former romantic partners.

If you think I’m exaggerating: Phone location and call records from two Georgia prosecutors pursuing a legal case against former president Donald Trump were presented as evidence of their romantic relationship. And in 2021, a priest was ousted from his job after a conservative Catholic group used location information from the gay dating app Grindr to trace his movements to a gay bar and a gay bathhouse and spa.

What can you do to protect yourself?

It’s an unfair burden, but personal vigilance is your best defense.

Advertisem*nt

If it seems like your sister is texting you in a panic to ask for bail money or if someone calls from what seems like your grandson’s phone number and says he’s holding your grandson for ransom, be suspicious. Hang up and try to reach your loved one directly or through a family member or friend.

Be extra vigilant about phone calls and texts that seem to come from your bank, too, in case crooks are impersonating the bank’s phone number.

AT&T said if you’re a target of fraud on your wireless number, you should report it to the company’s fraud team.

And if you typically have numerical codes texted to your phone to confirm your identity when you log into Facebook, a credit card account, your email or other websites, this might be a good moment for a security upgrade.

If you can manage it on your sensitive accounts, use an app like Authy or Google Authenticator that generates single-use codes instead of text messaged codes. Using an app instead of texts protects you from a serious but uncommon type of hack in which criminals intercept calls or texts to your phone number.

Advertisem*nt

Cahn said the location data saved by AT&T and other cellphone providers is not something you can protect on your own. That’s on companies to keep safe.

He says location data could be abused to endanger vulnerable people, including victims of stalkers or intimate partner violence.

“Where it could be potentially really scary is for people who put a premium on protecting their location privacy,” he said.

correction

A previous version of this article incorrectly said the AT&T breach affects customers with mobile service on Jan. 1, 2023, among other dates. It should have said Jan. 2, 2023. The article has been corrected.

Hackers stole almost everyone’s AT&T call records. What should you do? (2024)

FAQs

What should I do about the AT&T data breach? ›

After a hack disclosed in March, AT&T encouraged customers to monitor their account activity and credit reports, which is another smart move to protect yourself on a regular basis. At the time, AT&T recommended setting up free fraud alerts from credit bureaus Equifax, Experian and TransUnion.

How to find out if you were affected by an AT&T data breach? ›

If your account was included AT&T said they would contact you by text, email, or U.S. mail. You can also check if their data was compromised – including texts and phone numbers included in the download - by logging onto their accounts.

Was AT&T hacked recently? ›

The company said hackers downloaded customer data from a third-party cloud platform from May 1, 2022, to Aug. 31, 2022, and on Jan. 2. The stolen data included the numbers that hacked users called and received calls from, as well as call lengths, and users' locations when they made or received a call, the company said.

What data was stolen from AT&T? ›

Importance of call data records

AT&T told the SEC on Friday that metadata from “nearly all” call logs and texts made by AT&T customers over a six-month period in 2022 was stolen. A spokesperson for the telecom giant confirmed that the number of people affected was about 109 million.

Who do I contact if my data has been breached? ›

If you find that someone is using your information to commit fraud, identitytheft.gov can help you report that, too. Find out how to recover from a data breach at identitytheft.gov/databreach.

What are my rights if my data has been breached? ›

To address any harm you endured, the law gives you the right to seek financial compensation following a data breach. You can and should seek legal recourse from a company that exposed your data, and you can file a lawsuit to obtain payment for your losses.

How can I protect my AT&T account? ›

Enable Two-Factor Authentication: Enable two-factor authentication whenever possible to add an extra layer of security to your accounts. Be Cautious of Phishing Attempts: Stay vigilant against phishing emails, calls, or texts that may try to trick you into revealing sensitive information.

Can I find out if my data has been breached? ›

Bitdefender Digital Identity Protection only needs your email address and phone number to crawl data leaked from breaches to see if your information was exposed. You get a full list of organizations that revealed your details and what type of personal information was exposed.

What are signs my phone is hacked? ›

Signs of a hacked phone include reduced battery life, higher data usage, unusual device behavior, new apps, locked accounts, or receiving 2FA codes. Ryan Toohil has a BS in Computer Engineering from Virginia Tech and holds multiple patents in the web services domain.

What does AT&T do when phone is stolen? ›

Report the claim within 60 days of the date of loss. If your device was lost or stolen, please contact AT&T Customer Care at 866. MOBILITY to temporarily suspend service and prevent unauthorized use. A non-refundable deductible will be charged to your wireless bill following each approved claim.

How do I know that I have been hacked? ›

A hacked phone will show signs of malicious activity. Your contacts may get messages that you didn't send, unexpected apps may pop up on your device, you could spot new logins to your accounts, or even experience a significant decrease in your phone's speed.

How do I know if my AT&T data was breached? ›

AT&T said customers can visit att.com/DataIncident for more information. The compromised data involves records of calls and texts for AT&T customers, but doesn't include the content of the calls or texts, or personal information such as Social Security numbers, birth dates or other personally identifiable information.

Does AT&T need my social security number? ›

How AT&T uses your Social Security number. AT&T uses this information to confirm your identity during the credit inquiry. Please be assured that it is safe to provide us with this information as AT&T uses 128 bit SSL (Secure Socket Layer) encryption to keep your personal information safe.

What should I do if I am aware of a data breach? ›

If you're notified that your personal information was exposed in a data breach, act immediately to change your passwords, add a security alert to your credit reports and consider placing a security freeze on your credit reports.

What should you do if you see a breach of data protection? ›

By law, you've got to report a personal data breach to the ICO without undue delay (if it meets the threshold for reporting) and within 72 hours. You might end up not needing to report it, but start a log anyway, to record what happened, who is involved and what you're doing about it.

Top Articles
Latest Posts
Article information

Author: Rev. Leonie Wyman

Last Updated:

Views: 5914

Rating: 4.9 / 5 (79 voted)

Reviews: 94% of readers found this page helpful

Author information

Name: Rev. Leonie Wyman

Birthday: 1993-07-01

Address: Suite 763 6272 Lang Bypass, New Xochitlport, VT 72704-3308

Phone: +22014484519944

Job: Banking Officer

Hobby: Sailing, Gaming, Basketball, Calligraphy, Mycology, Astronomy, Juggling

Introduction: My name is Rev. Leonie Wyman, I am a colorful, tasty, splendid, fair, witty, gorgeous, splendid person who loves writing and wants to share my knowledge and understanding with you.