AT&T

at&t:-data-breach-affects-73-million-or-51-million-customers-no,-we-won’t-explain.

AT&T: Data breach affects 73 million or 51 million customers. No, we won’t explain.

“SECURITY IS IMPORTANT TO US” —

When the data was published in 2021, the company said it didn’t belong to its customers.

AT&T: Data breach affects 73 million or 51 million customers. No, we won’t explain.

Getty Images

AT&T is notifying millions of current or former customers that their account data has been compromised and published last month on the dark web. Just how many millions, the company isn’t saying.

In a mandatory filing with the Maine Attorney General’s office, the telecommunications company said 51.2 million account holders were affected. On its corporate website, AT&T put the number at 73 million. In either event, compromised data included one or more of the following: full names, email addresses, mailing addresses, phone numbers, social security numbers, dates of birth, AT&T account numbers, and AT&T passcodes. Personal financial information and call history didn’t appear to be included, AT&T said, and data appeared to be from June 2019 or earlier.

The disclosure on the AT&T site said the 73 million affected customers comprised 7.6 million current customers and 65.4 million former customers. The notification said AT&T has reset the account PINs of all current customers and is notifying current and former customers by mail. AT&T representatives haven’t explained why the letter filed with the Maine AG lists 51.2 million affected and the disclosure on its site lists 73 million.

According to a March 30 article published by TechCrunch, a security researcher said the passcodes were stored in an encrypted format that could easily be decrypted. Bleeping Computer reported in 2021 that more than 70 million records containing AT&T customer data was put up for sale that year for $1 million. AT&T, at the time, told the news site that the amassed data didn’t belong to its customers and that the company’s systems had not been breached.

Last month, after the same data reappeared online, Bleeping Computer and TechCrunch confirmed that the data belonged to AT&T customers, and the company finally acknowledged the connection. AT&T has yet to say how the information was breached or why it took more than two years from the original date of publication to confirm that it belonged to its customers.

Given the length of time the data has been available, the damage that’s likely to result from the most recent publication is likely to be minimal. That said, anyone who is or was an AT&T customer should be on the lookout for scams that attempt to capitalize on the leaked data. AT&T is offering one year of free identity theft protection.

AT&T: Data breach affects 73 million or 51 million customers. No, we won’t explain. Read More »

epa-expands-“high-priority”-probe-into-at&t,-verizon-lead-contaminated-cables

EPA expands “high priority” probe into AT&T, Verizon lead-contaminated cables

EPA expands “high priority” probe into AT&T, Verizon lead-contaminated cables

The Environmental Protection Agency (EPA) is expanding its investigation into potential risks posed by lead-covered cables installed nationwide by major telecommunications companies, The Wall Street Journal revealed in an exclusive report Thursday.

After finding “more than 100 readings with elevated lead near cables,” the EPA sent letters to AT&T and Verizon in December, requesting a meeting later this month, the Journal revealed. On the agenda, the EPA expects the companies to share internal data on their own testing of the cables, as well as details from any “technical reports related to the companies’ testing and sampling,” the WSJ reported.

The EPA’s investigation was prompted by a WSJ report published last July, alleging that AT&T, Verizon, and other companies were aware that thousands of miles of cables could be contaminating soils throughout the US, “where Americans live, work and play,” but did nothing to intervene despite the many public health risks associated with lead exposure.

In that report, tests showed that the telecom cables were likely the source of lead contaminated soils because “the amount measured in the soil was highest directly under or next to the cables and dropped within a few feet.” WSJ also spoke to residents and former telecom employees in areas tested who had contracted illnesses commonly linked to lead exposure.

Immediately, WSJ’s report spurred lawmakers to demand a response from USTelecom—a telecommunications trade association representing companies accused—with Senator Ed Markey (D-Mass.) suggesting that telecom giants were seemingly committing “corporate irresponsibility of the worst kind.”

Since then, the EPA has followed up and developed “its own testing data” in West Orange, New Jersey, southwest Pennsylvania, and Louisiana—the same locations flagged by the WSJ. In all locations, the EPA found lead contamination exceeding the “current recommendation for levels of lead it believes are generally safe in soil where children play,” 400-parts-per-million, the WSJ reported. In West Orange, two testing sites found lead “at 3,300 parts per million or higher.”

According to the EPA, initial testing by a national working group led to a conclusion that none of these sites poses an immediate health risk or requires an emergency response, but that finding hasn’t stopped the probe. The EPA told the WSJ that it still needs to address unanswered questions to decide “whether further actions may be required to address risks from the lead-containing cables.”

“While some locations sampled show concentrations above screening levels for long term exposures, existing data is not sufficient to determine whether lead from the cables poses a threat, or a potential threat, to human health or the environment,” the EPA said in a Reuters report.

Companies maintain that evidence from their own testing has shown lead cables do not pose public health risks requiring remediation.

USTelecom, speaking on behalf of Verizon and other telecom companies, told the WSJ that “our industry has been engaging with the EPA and our companies look forward to meeting with the EPA to discuss agency and industry testing results. We will continue to follow the science, which has not identified that lead-sheathed telecom cables are a leading cause of lead exposure or the cause of a public health issue.”

AT&T told the WSJ that it “will continue to work collaboratively with the EPA as it undertakes its review of lead-clad telecommunications cables. We look forward to the opportunity to meet with the EPA to discuss recent testing and other evidence that contradicts the Wall Street Journal’s assertions.”

An EPA spokesperson, Nick Conger, told Bloomberg that there is no date set for the meeting yet.

EPA expands “high priority” probe into AT&T, Verizon lead-contaminated cables Read More »