Hackers stole almost everyone’s AT&T call records. What should you do? (2024)

Another day, another data breach. But this one is nasty.

AT&T said Friday that hackers who have hit other companies also swiped at least six months of 2022 phone records for — that’s roughly 110 million customer accounts. AT&T said hackers don’t have the content of people’s calls or texts.

For what AT&T says is a portion of those records, the stolen data also included some people’s estimated locations.

The swiped location data is relatively unusual in a cyberattack, and it’s the part that freaked out Albert Fox Cahn, founder of the Surveillance Technology Oversight Project.

GET CAUGHT UP

Stories to keep you informed

Dissenting Republican delegates sign protest of Trump platform SparkleSummary is AI-generated, newsroom-reviewed.
U.S., Germany foiled Russian plot to assassinate CEO of arms manufacturer, officials saySparkleSummary is AI-generated, newsroom-reviewed.
Family of teen who died after ‘One Chip Challenge’ sues snack companySparkleSummary is AI-generated, newsroom-reviewed.
La Niña is coming. Here’s how it could change the weather.SparkleSummary is AI-generated, newsroom-reviewed.
Do landlords have to provide AC? Here’s what renters should know.SparkleSummary is AI-generated, newsroom-reviewed.

Your phone company logs the nearest cellular tower every time your device connects to its mobile network. That data is essentially a rough timeline and map of everywhere you go with your smartphone, including your home, work, house of worship, medical appointments and more.

Advertisem*nt

Skip to end of carousel

Shira Ovide

Hackers stole almost everyone’s AT&T call records. What should you do? (6)Hackers stole almost everyone’s AT&T call records. What should you do? (7)

Tech Friend writer Shira Ovide gives you advice and context to make technology work for you. Sign up for the free Tech Friend newsletter.

End of carousel

“It’s such an invasive window into our lives,” Cahn said. The stolen location records about AT&T customers were limited to data from older 3G mobile connections and during slices of the day, an AT&T spokeswoman said. That’s likely a relatively limited amount of data on customers’ estimated whereabouts.

You can’t know for sure how this stolen AT&T information might be used against you. I’ll talk you through how to know if your data was swiped, what could go wrong and how to protect yourself.

Also, take a moment to feel furious. This data theft shows the risks from America’s largely unregulated personal data harvesting. You, and generally not the companies, bear the burden when companies fail to secure your information from thieves.

How do you know whether your phone records were stolen?

AT&T said it will notify affected customers by text, email or physical mail.

Advertisem*nt

But if you had AT&T mobile service between the beginning of May and the end of October in 2022 or on Jan. 2, 2023, you should assume your phone records were stolen.

What information is in those hacked phone records?

The swiped records include information like every number you texted and called and how many times you called your spouse in a given month and the cumulative time those calls lasted.

AT&T said monthly wireless and home telephone customers can go to this website to see the phone numbers of your calls and texts that were in the stolen records.

AT&T said that the names associated with accounts, Social Security numbers and credit card numbers weren’t stolen.

Another potential risk may be from the stolen logs of AT&T customers’ locations.

Even if the stolen data had relatively limited data about customers’ physical whereabouts when they connect to a mobile network, the location data from cellphones is so sensitive that the Supreme Court has said it generally deserves extra legal protections. Police must have a warrant to obtain the kind of location data that thieves just stole from AT&T.

What do you have to worry about?

AT&T’s statement said it doesn’t believe the stolen phone records have been leaked online. But Cahn said the thieves could at any time sell the phone records to other criminals or post them on the web for anyone to see.

Advertisem*nt

With information like the numbers you frequently call, a crook could impersonate your boss, brother or bank to get you to hand over money, said Frédéric Rivain, chief technology officer of the password management service Dashlane. (Although crooks already can and do impersonate your contacts’ phone numbers without stealing your phone records.)

In the wrong hands, stolen data from phone records could also be used to blackmail people having affairs, for criminals to find the homes of police officers and prosecutors or for abusers to track down their former romantic partners.

If you think I’m exaggerating: Phone location and call records from two Georgia prosecutors pursuing a legal case against former president Donald Trump were presented as evidence of their romantic relationship. And in 2021, a priest was ousted from his job after a conservative Catholic group used location information from the gay dating app Grindr to trace his movements to a gay bar and a gay bathhouse and spa.

What can you do to protect yourself?

It’s an unfair burden, but personal vigilance is your best defense.

Advertisem*nt

If it seems like your sister is texting you in a panic to ask for bail money or if someone calls from what seems like your grandson’s phone number and says he’s holding your grandson for ransom, be suspicious. Hang up and try to reach your loved one directly or through a family member or friend.

Be extra vigilant about phone calls and texts that seem to come from your bank, too, in case crooks are impersonating the bank’s phone number.

AT&T said if you’re a target of fraud on your wireless number, you should report it to the company’s fraud team.

And if you typically have numerical codes texted to your phone to confirm your identity when you log into Facebook, a credit card account, your email or other websites, this might be a good moment for a security upgrade.

If you can manage it on your sensitive accounts, use an app like Authy or Google Authenticator that generates single-use codes instead of text messaged codes. Using an app instead of texts protects you from a serious but uncommon type of hack in which criminals intercept calls or texts to your phone number.

Advertisem*nt

Cahn said the location data saved by AT&T and other cellphone providers is not something you can protect on your own. That’s on companies to keep safe.

He says location data could be abused to endanger vulnerable people, including victims of stalkers or intimate partner violence.

“Where it could be potentially really scary is for people who put a premium on protecting their location privacy,” he said.

correction

A previous version of this article incorrectly said the AT&T breach affects customers with mobile service on Jan. 1, 2023, among other dates. It should have said Jan. 2, 2023. The article has been corrected.

Hackers stole almost everyone’s AT&T call records. What should you do? (2024)

FAQs

Hackers stole almost everyone’s AT&T call records. What should you do? ›

AT&T said if you're a target of fraud on your wireless number, you should report it to the company's fraud team.

What to do about att hack? ›

What should I do if I'm an AT&T customer? AT&T subscribers affected by the hack, including former customers, can request until December that the company send them the phone numbers illegally downloaded from their records. For more information, check AT&T's website.

Am I affected by an AT&T data breach? ›

AT&T will contact you by text, email or U.S. mail if your account was affected by the cyberattack, the company said. But AT&T also said that “nearly all” customers had been affected by the breach. So if you were a customer from May 1, 2022, to Oct. 31, 2022, or on Jan. 2, 2023, your phone logs were most likely exposed.

What data was stolen from AT&T? ›

Hackers stole data from nearly every AT&T customer in a new data breach, taking six months of calls and text message records between May 1 and Oct. 31 of 2022 and on Jan. 2, 2023. “According to what we know publicly, this wasn't a breach of AT&T per se,” said Kern Smith, a mobile security expert.

How to report stolen phone att? ›

Device was lost/stolen

If you require assistance, you will need to contact Customer Care by dialing 1-800-331-0500.

Who should I contact if I have been hacked? ›

What to do: File an identity theft report with the FTC on IdentityTheft.gov. File a complaint with the FBI's Internet Crime Complaint Center (IC3). File a police report when you discover that you've been hacked, especially in cases of identity theft.

What's the best thing to do when your phone has been hacked? ›

My Phone Was Hacked. How Do I Fix It?
  • To start, install and run security software on your phone. ...
  • Next, check your bank accounts and your credit card statements. ...
  • If you still have issues, wiping and then restoring your phone is an option. ...
  • Don't Download Sketchy Software (Including Apps) ...
  • Always Keep Your Phone with You.
Mar 12, 2024

Who do I contact if my data has been breached? ›

File a complaint with the Federal Trade Commission. Place a fraud alert with one of the three national credit reporting bureaus. This will let any company that checks your credit know your information was stolen, and they should contact you by phone before authorizing new credit.

Did AT&T get hacked recently? ›

The company said in an SEC filing that it learned from an internal investigation that in April, hackers "unlawfully accessed and copied AT&T call logs" that were saved on a third-party cloud platform. The data contains records of calls and texts between approximately May 1 and Oct. 31, 2022, and on Jan. 2, 2023.

How do I contact AT&T about data breach? ›

The company added that if you were affected by the breach, AT&T will reach out by mail or email and offer complimentary identity theft and credit monitoring services. Concerned customers with any questions can also call AT&T wireless customer service at 1-800-331-0500.

What happens when an AT&T phone is reported stolen? ›

Report the claim within 60 days of the date of loss. If your device was lost or stolen, please contact AT&T Customer Care at 866. MOBILITY to temporarily suspend service and prevent unauthorized use. A non-refundable deductible will be charged to your wireless bill following each approved claim.

How can I protect my AT&T account? ›

Create a new passcode to keep your account secure. Try to avoid numbers that are easy to guess like any part of a SSN, account number, or phone number. Enter any wireless number on your AT&T account to create a passcode. Be sure to enter your wireless number.

Where can I check if my data has been breached? ›

Use Avast Hack Check to see what accounts have been compromised. If you find any, change their passwords immediately — use our password generator for the best results.

Is it worth reporting a stolen phone? ›

Is it worth reporting a stolen phone? Yes, especially if you see it on Find My iPhone or Find My Device. Police can put phones on a blacklist, and credit card companies may need their records.

Is it better to report phone lost or stolen? ›

Immediately report the theft or loss to your service provider. You will be responsible for any charges incurred prior to when you report the stolen or lost device. Your service provider may be able to use your IMEI or MEID or ESN number to disable your device and block access to the information it carries.

How do I report a scammer to AT&T? ›

Examples include phishing and emails pretending to be from AT&T.
  1. Forward a suspicious email to abuse@att.net.
  2. Forward the email to the Anti-Phishing Working Group at reportphishing@apwg.org.
  3. Report email fraud on the FTC Consumer Info site.

Was AT&T recently hacked? ›

The company said in an SEC filing that it learned from an internal investigation that in April, hackers "unlawfully accessed and copied AT&T call logs" that were saved on a third-party cloud platform. The data contains records of calls and texts between approximately May 1 and Oct. 31, 2022, and on Jan. 2, 2023.

Can a hack on a phone be removed? ›

Many hackers use malware to control their victim's device or access sensitive files, photos, and videos. Using a reputable antivirus scanner can help you detect and remove malware — but only on Android devices (Apple doesn't allow third-party apps to scan for viruses).

Where do I report AT&T phishing? ›

Email Fraud Reporting
  • Forward a suspicious email to abuse@att.net.
  • Forward the email to the Anti-Phishing Working Group at reportphishing@apwg.org.
  • Report email fraud on the FTC Consumer Info site.

What can you do when you get hacked? ›

Think you've been hacked? 3 quick steps to take
  • Step 1: Change your passwords. This is important because hackers are looking for any point of entry into a larger network, and may gain access through a weak password. ...
  • Step 2: Secure your log-in process. ...
  • Step 3: Contact people who can help.
Apr 21, 2023

Top Articles
Latest Posts
Article information

Author: Duncan Muller

Last Updated:

Views: 6323

Rating: 4.9 / 5 (59 voted)

Reviews: 82% of readers found this page helpful

Author information

Name: Duncan Muller

Birthday: 1997-01-13

Address: Apt. 505 914 Phillip Crossroad, O'Konborough, NV 62411

Phone: +8555305800947

Job: Construction Agent

Hobby: Shopping, Table tennis, Snowboarding, Rafting, Motor sports, Homebrewing, Taxidermy

Introduction: My name is Duncan Muller, I am a enchanting, good, gentle, modern, tasty, nice, elegant person who loves writing and wants to share my knowledge and understanding with you.