Massive AT&T data breach hits 109 million customers — call logs and text messages stolen by hackers

An AT&T store with people walking in front of it
(Image credit: Shutterstock)

AT&T is the latest major company to fall victim to a massive data breach after customer data was stolen from an online database associated with its Snowflake account.

As reported by BleepingComputer, the call and text records of 109 million of the company’s customers or nearly all of its mobile subscribers were stolen by hackers between April 14 and April 25th of this year. However, it’s not just AT&T users who are affected but also Cricket, Boost Mobile and Consumer Cellular customers as well since these companies also use the carrier’s mobile network.

In a Form 8-K filing with the U.S. Securities and Exchange Commission (SEC), AT&T revealed that the stolen data includes mobile and landline telephone numbers, the number of calls and text messages sent over the network, aggregate call duration for a day or month and a subset of records containing one or more cell site identification numbers.

Fortunately though, sensitive personal data such as customer names, Social Security numbers and dates of birth were not exposed as a result of this breach. However, the logs accessed by the hackers behind the breach do contain enough communications metadata to figure out the identities of affected AT&T customers. 

Immediately after identifying the breach, AT&T contacted the FBI to report it and the mobile carrier is now working alongside law enforcement and the U.S. Department of Justice (DOJ) to catch those responsible. In fact, at least one person has already been apprehended as part of the investigation into the matter.

Yet another Snowflake victim

A hacker typing quickly on a keyboard

(Image credit: Shutterstock)

AT&T is the latest company to be added to a growing list of businesses that have suffered a data breach after using Snowflake’s cloud-based data warehouse and analytics platform.

Back in June of this year, the cyber threat intelligence firm Mandiant revealed that a financially motivated threat actor (tracked as UNC5537) was responsible for multiple attacks against Snowflake customers. All of these attacks were possible through the use of stolen Snowflake credentials obtained as a result of info-stealing malware. In the time since, Snowflake has made multi-factor authentication (MFA) mandatory for all of its customers to prevent further data breaches through its platform going forward.

In addition to AT&T, Ticketmaster, Neiman Marcus, Banco Santander, Advance Auto parts, Pure Storage and Los Angeles Unified have all been hit with similar data breaches as a result of using Snowflake to house their online databases.

How to see if your data was exposed and what to do next

A nervous woman looking at her phone

(Image credit: Shutterstock)

If you’re an AT&T customer worried your call and text logs may have been exposed, there are some steps you can take right now to see if you’re affected by this breach.

While the mobile carrier says that it will contact all affected customers by text, email or through the mail, this support document recommends that you also check your myAT&T account here. Likewise, there it also contains links for business customers as well as FirstNet users.

As with all data breaches, the biggest threat for AT&T users are phishing attacks and online fraud. Now that hackers could figure out your identity, they might try to reach out to you posing as AT&T. As such, you need to be extra careful when checking your inbox and messages.

You should avoid clicking on links or downloading attachments if a message from an unknown sender arrives in your inbox or over text. Hackers often set up fake pages as means to steal your credentials, credit card data and other sensitive info. For this reason, you want to go directly to AT&T’s page instead of clicking on any links that claim to take you to it.

While companies often provide free access to the best identity theft protection services after a data breach, AT&T hasn’t yet in this case. That could change in the future but given as call and text records instead of personal information were exposed, this seems rather unlikely.

We’ll be following this story closely and will update it accordingly as we learn more about this massive data breach and others like it.

More from Tom's Guide

Network
Arrow
Intego
Norton
Contract Length
Arrow
Showing 2 of 2 deals
Filters
Arrow
TOPICS
Anthony Spadafora
Managing Editor Security and Home Office

Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches to password managers and the best way to cover your whole home or business with Wi-Fi. He also reviews standing desks, office chairs and other home office accessories with a penchant for building desk setups. Before joining the team, Anthony wrote for ITProPortal while living in Korea and later for TechRadar Pro after moving back to the US. Based in Houston, Texas, when he’s not writing Anthony can be found tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
An open lock depicting a data breach
Massive healthcare data breach just exposed the personal info of 1 million Americans — what to do now
An open lock depicting a data breach
3.5 million hit in major law firm data breach — full names, SSNs, dates of birth, addresses and more exposed
Globe Life insurance company logo on a cell phone in front of a monitor display the About page for the company. Shadowy hand holds the phone.
850,000 people exposed in massive insurance data breach — full names, dates of birth and SSNs
An open lock depicting a data breach
The top 10 data breaches of 2024
An open lock depicting a data breach
Half a million teachers hit in major data breach with SSNs, financial data and more exposed — what to do now
Screen graphic showing data breach warning
5 worst data breaches of 2024 — including the mother of all breaches
Latest in Online Security
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
Hacker using a stolen social security card
Your Social Security number is a literal gold mine for scammers and identity thieves — here’s how to keep it safe
An open lock depicting a data breach
Half a million teachers hit in major data breach with SSNs, financial data and more exposed — what to do now
Green skull on smartphone screen.
Malicious Android apps with 60 million installs bombarding phones with ads and phishing attacks — how to stay safe
Malware
Dangerous new password-stealing trojan automatically reinstalls itself on infected PCs
Latest in News
Rendered images of rumored foldable iPhone.
Foldable iPhone report just revealed key details — here's what we know
Nintendo Switch 2
Nintendo Switch 2 rumored specs — here’s what we know so far
iPhone 17 Pro render
iPhone 17 Pro — 7 biggest rumored upgrades
CAD renderings of the Google Pixel 10 Pro XL
Pixel 10 leak could be good news for all Android phones
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
Lewis Hamilton of Great Britain and Scuderia Ferrari looks on during Sprint Qualifying ahead of the F1 Grand Prix of China at Shanghai International Circuit in Shanghai, China, on March 21, 2025. (Photo by Song Haiyuan/Paddocker/NurPhoto via Getty Images)
How to watch Chinese Grand Prix 2025 online – stream F1 without cable, qualifying highlights