Inside the Massive Alleged AT&T Data Breach
troyhunt.com
troyhunt.com
Lack of stewardship for folk's data should not just be the "cost of doing business".
[0] https://www.usa.gov/elected-officials
[1] https://consumercomplaints.fcc.gov/hc/en-us/articles/8824334...
Edit: My parents' email addresses aren't showing this dump either. Looks like we weren't included at all, so it can't just straight be all AT&T customers.
> As of now, all 49M impacted email addresses are searchable within HIBP.
full disclosure: i have not seen the raw dataset.
... Honestly, that shouldn't really make us feel any better about them though, like why would AT&T give out data that includes SSNs to third-party data-processors.
"This guy looks like he could drop dead any minute, let's put a million dollars on him"
"free credit monitoring" should not be a considered a valid solution to "oops we leaked your private data".
I doubt anyone affected will care about any such distinction.
That being said, I've never heard of hackers performing Master Data Management but I guess it's possible. I'd hope they'd use something other than full name for their matches...
[1] maybe the wireless was with cingular@ though, I think I signed on before AT&T reassembled, like the T-1000.
I can imagine, though, that hiding information is a lot easier when you're less often in the public eye. Amazon and Google, through their ubiquity, have a higher hill to climb when it comes to avoiding scrutiny.
1 - https://www.opensecrets.org/federal-lobbying/top-spenders
I'm wondering what AT&T thinks they'll achieve? If they're lying, that is.
https://www.sec.gov/news/statement/gerding-cybersecurity-dis...
This doesn’t pass the basic smell test. I really don’t want HN to fall down the conspiracy hole that much of the internet now has. It’s eating away at our societal fabric and is wrong 99.9% of the time.
But I expect the simplest explanation is, as the article posits:
1) ATT contracts out portions of its business operations to third parties.
2. Those third parties, in the course of their business, require and have access to customer information.
3 - One of those third parties was breached.
#4 ATT may or may not know. (Or may deliberately be not-asking their contractor)
Presto! Security by ignorance!
Given the access to SSNs, I'd assume something to do with private credit scoring.
The breach did happen, but things under the hood are so bad that they have no idea it happened. The layers of incompetence and don't-give-a-fuck completely obscure the evidence. The IT team, staffed mostly by young green cards who weren't even in this country 3 years ago, stare blankly at AT&T's internal auditing system developed in the 90's with a long dead and strictly proprietary language. Doesn't matter because the system didn't even catch the breach anyway. As you move up the chain, people just get more divorced from reality as they live in the delusion of AT&T still being a forefront technology company. So of course the breach didn't happen to them.
At least that it my theory.
Source: Worked sometime for a subcontractor of a subcontractor of AT&T from a third world country.
However, my former work email, that I used to sign up for both U-verse fiber and a corporate mobile account, is on the list. I suppose that all happened in 2016-2018.
Seeing this now, it makes a lot of sense how the scammers would know to target me.
tl;dr is that some scammers knew I had an AT&T account, and called posing as some AT&T branch that could only speak Chinese (ostensibly serving NYC Chinatown). I think they're targeting 2nd-gen Chinese speakers and forcing them into likely broken Chinese to throw them off guard.
I've always thought companies offer those for ulterior motives, e.g. maybe they get a fee for giving the protection service future customers. Do others use them? Maybe I've been wrong here.
Even if we had AT&T’s keys, I think it might be non-trivial to verify that they correspond to this data, depending on how AT&T encrypts.
What I was trying to say is that if AT&T systems (or a backup) contain that exact encrypted value (no need for a decryption key), it's a near-certain proof that the data came from their system.
> then at the end you say “(or not)”.
Well, only AT&T DBAs/SREs should be able to confirm what I wrote above and I don't want to accuse anyone without proof. Same reason why Troy Hunt wrote "allegedly".
Of course that doesn't say anything about the other PII but at this point, I figure my PII has already been leaked multiple times.
Hackers could then use the watermark to prove the authenticity of the data and users could use it to check if their data have been breached.
There's 13bn leaked accounts on the site, and although Hunt does appear to run the site entirely selflessly with little/no profit motive, there is at least some commercialisation of the accounts listed bringing in revenues to cover its costs.
It's free for us because somewhere in the chain, someone is paying for data about us - even if their use-case isn't nefarious.
It's not free unless you just have one email.
Would love to see what's in it but, eh.