← Case Files · The Breach Files
AT&T, 2024: who called whom, for nearly every customer
- People affected
- call and text metadata for nearly all mobile customers, about 109 million accounts
- When it happened
- April 2024 (covering records from 2022)
- Made public
- 12 July 2024
- How they got in
- A third-party cloud data warehouse account without multi-factor authentication
- Attributed to
- Part of the campaign tracked as UNC5537; charges followed in late 2024
- What it cost
- A proposed $177 million settlement covering both 2024 incidents
What was exposed: Phone numbers contacted · Counts of calls and texts · Call durations · Cell site identifiers for some records
In July 2024, AT&T disclosed that call and text metadata for nearly all of its mobile customers — roughly 109 million accounts — had been copied from a cloud data warehouse. The records covered a six-month window in 2022. No conversations were taken, and that fact has been used to soften the story ever since. It should not.
What was taken
For the period from 1 May to 31 October 2022, plus a further day in January 2023, the data described which phone numbers interacted with which, the number of calls and texts between them, and call durations. For a subset of records it also included cell site identifiers — meaning an approximate location for where the device was when the call took place.
It did not include the contents of calls or messages, names, or dates of birth. AT&T noted that the numbers are not directly linked to names in the data — although publicly available lookup tools make that a thin protection, since a phone number is one of the easiest identifiers in the world to resolve to a person.
The route in was the same as the wider 2024 campaign against cloud data warehouses: a customer account on a third-party analytics platform, accessible with a password and no second factor.
Why metadata is not the lesser category
This is the argument worth making carefully, because "no message content was affected" appears in almost every telecommunications breach notice.
Content is ambiguous; patterns are not. A phone call to a cancer clinic followed by three calls to close family members, then a call to an employer, is a diagnosis narrative. Repeated late-night calls between two numbers over four months is a relationship. A single call to a domestic violence helpline is a disclosure. None of those inferences requires a word of what was actually said, and all of them can be drawn by a script across a hundred million records.
Metadata has three properties that make it more dangerous in bulk than content:
- It is structured. Content requires interpretation; metadata is already a graph of who contacts whom, ready to query.
- It is complete. Interception captures some conversations. Carrier records capture every connection.
- It resists denial. You can dispute what was said in a call. You cannot dispute that it happened, for how long, and from where.
For most people the practical risk from this breach is modest. For journalists and their sources, for people in abusive situations, for anyone whose contacts are sensitive, a complete six-month connection graph is a serious exposure that no password change addresses.
The two AT&T incidents of 2024
Confusion between them is common, so it is worth separating them:
- March 2024. A dataset containing roughly 73 million current and former customer records — dating from 2019 or earlier and including Social Security numbers and account passcodes — appeared publicly. AT&T reset passcodes for affected accounts. Its origin was disputed for some time.
- July 2024. The call and text metadata disclosure covered here, from a cloud data warehouse compromised in April 2024.
A third matter, a 2023 incident involving a cloud vendor, was settled separately with the Federal Communications Commission. Three unrelated failures inside eighteen months at one carrier is itself the finding.
The delayed disclosure
AT&T's July filing noted that the US Department of Justice had determined a delay to public disclosure was warranted, twice, on national security and public safety grounds. The SEC's 2023 cybersecurity disclosure rules allow exactly this: a company can postpone reporting a material incident if the Attorney General determines that immediate disclosure would pose a substantial risk.
It is a legitimate mechanism and it was used here in what appears to be the way it was designed to be used. It is also worth noticing, because it means the four-business-day disclosure rule people cite is not absolute, and the public timeline of a major breach can legally be weeks or months behind the private one.
What it changed
Metadata protection climbed the agenda. Regulators had treated customer proprietary network information as a privacy category for decades; this breach turned it into a security one, and reinforced the FCC's more aggressive posture towards carriers' data handling.
Cloud analytics platforms got audited. The AT&T disclosure is what moved the Snowflake campaign from a security-industry story into a mainstream one, and it prompted a wave of enterprise reviews of where bulk data had been copied for analysis and who could log into it.
If you were an AT&T customer in 2022
- There is no remediation for a connection graph, and it would be dishonest to suggest otherwise. Changing your number would break the link going forward and is disruptive enough that it is only worth it for people at genuine risk.
- If your contacts are sensitive, adjust the channel rather than the number. End-to-end encrypted messaging that does not route through carrier records is the control that actually addresses this.
- Set a port-out PIN. Separate risk, cheap fix, and relevant to every carrier breach.
- For the March 2024 dataset, treat your old account passcode as public and make sure it is not reused anywhere else — the reuse problem in practical terms.
Questions people ask
Were the contents of my calls or messages stolen?
No. The data was metadata: which numbers interacted, how many times, and for how long, plus cell site identifiers for a subset of records. The words spoken and the text of messages were not included.
If it is only metadata, why does it matter?
Because a complete record of who you contact reveals relationships that content often does not. A sequence of calls to an oncology practice, a divorce lawyer, a rehabilitation clinic or a domestic violence helpline tells the story without a single word being read. Metadata at scale is also easy to analyse automatically, which content is not.
I was not an AT&T customer. Am I in it?
Possibly. The records cover numbers that AT&T customers interacted with, and that includes people on other networks. You can be in a telephone metadata set without ever having had a relationship with the carrier that lost it.
Was this the same as the other AT&T leak in 2024?
No, they are separate. In March 2024, a dataset of about 73 million current and former customer records from 2019 or earlier surfaced publicly, including Social Security numbers and account passcodes, prompting a mass passcode reset. The July disclosure concerned call and text metadata taken from a cloud data warehouse in April 2024.
Sources
- AT&T Form 8-K filing and customer notice, July 2024
- Mandiant analysis of UNC5537 and the Snowflake-related campaign, June 2024
- Federal Communications Commission enforcement actions against AT&T, 2024
- Proposed class settlement filings, 2025
Read next
Case files are written from the public record: regulatory findings, court filings, company disclosures and contemporaneous reporting, cited above. Figures are the ones the organisation or its regulator finally settled on, which is often not the number first reported — where that differs, the page says so. Disputed accounts are marked as disputed rather than resolved in either direction.