AT&T logo retail location
(Image source: 123RF, 2019)
One-sentence summary:
AT&T’s marketing vendor was hacked due to an upgrade eligibility exploit, allowing the customer proprietary network information (CPNI) of over 9 million customers to be breached.
Who was involved?
AT&T, AT&T’s marketing vendor, a threat actor, and 9 million AT&T customers.
What was the timeline?
January 2023: AT&T’s marketing vendor gets hacked
March 6, 2023: Customers report getting the breach notice online.
What occurred?
In January of 2023, a third-party marketing vendor had a vulnerability in their “device upgrade eligibility” integration exploited, allowing the breach of AT&T customers’ CPNI (Customer Proprietary Network Information) for over 9 million customers (Gatlan, 2023). A customer reported the breach notice via AT&T’s Community Forums, subsequently getting media attention and a media response from AT&T (Is This CPNI Email a Phishing Scam? | AT&T Community Forums, 2023; Gatlan, 2023). Breached data included: the “number of lines on your account or the wireless plan to which you are subscribed,” “customer first names, wireless account numbers, wireless phone numbers, and email addresses,” and even “rate plan name, past due amount, monthly payment amount, various monthly charges and/or minutes used” (Is This CPNI Email a Phishing Scam? | AT&T Community Forums, 2023; Gatlan, 2023).
Estimated costs:
TBA or N/A (see disclaimer)
Involved laws:
Federal: Communications Act of 1934 (47 U.S.C. § 151 et seq.); 47 CFR § 64.2001 et seq.
Root cause:
Third-party marketing vendor with a “vulnerability.”
Lessons learned:
Telecommunication providers: Potential third-party due diligence, pending more information (see disclaimer).
Customers: Should opt out of CPNI if they desire to prevent future breaches. AT&T has not made this process easy for all users.
Sources:
123RF. (2019, April). img-att-logo.jpg. secureyourtrademark.com. https://www.123rf.com/photo_125169533_st-marys-circa-april-2019-at-t-retail-cell-phone-and-mobility-store-at-t-wrapped-up-its-merger.html?vti=o1rph3wrwq34j6b2uk-1-1
Gatlan, S. (2023, March 9). AT&T alerts 9 million customers of data breach after vendor hack. BleepingComputer. Retrieved March 10, 2023, from https://www.bleepingcomputer.com/news/security/atandt-alerts-9-million-customers-of-data-breach-after-vendor-hack/
Is this CPNI email a phishing scam? | AT&T Community Forums. (2023, March 9). AT&T Community Forums. https://forums.att.com/conversations/att-mail-features/is-this-cpni-email-a-phishing-scam/64066deaac6ccc24bdf19e05?page=1
