I'm wondering what AT&T thinks they'll achieve? If they're lying, that is.
I'm wondering what AT&T thinks they'll achieve? If they're lying, that is.
https://www.sec.gov/news/statement/gerding-cybersecurity-dis...
But I expect the simplest explanation is, as the article posits:
1) ATT contracts out portions of its business operations to third parties.
2. Those third parties, in the course of their business, require and have access to customer information.
3 - One of those third parties was breached.
#4 ATT may or may not know. (Or may deliberately be not-asking their contractor)
Presto! Security by ignorance!
Given the access to SSNs, I'd assume something to do with private credit scoring.
The breach did happen, but things under the hood are so bad that they have no idea it happened. The layers of incompetence and don't-give-a-fuck completely obscure the evidence. The IT team, staffed mostly by young green cards who weren't even in this country 3 years ago, stare blankly at AT&T's internal auditing system developed in the 90's with a long dead and strictly proprietary language. Doesn't matter because the system didn't even catch the breach anyway. As you move up the chain, people just get more divorced from reality as they live in the delusion of AT&T still being a forefront technology company. So of course the breach didn't happen to them.
At least that it my theory.
Source: Worked sometime for a subcontractor of a subcontractor of AT&T from a third world country.
This doesn’t pass the basic smell test. I really don’t want HN to fall down the conspiracy hole that much of the internet now has. It’s eating away at our societal fabric and is wrong 99.9% of the time.