HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTCREDENTIALSFINANCIALMediumContained
AT&T INC.
bd_0a9f6e0692a2bbdc · schema v1 · pii pii-v1
Full breach record for AT&T INC. →AT&T reported unauthorized access to customer accounts between February and July 2014. The incident involved an effort to request codes allowing phones to be used on other networks. While there is no evidence that Social Security Numbers or Customer Proprietary Network Information (CPNI) were acquired, this data was contained in the accessed system. AT&T offered one year of free credit monitoring to affected customers and strengthened account security policies.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-55594
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 23, 2015
- Raw hash
- c12752b0b778ef8512bca62cd625e6567ebf78b78a0345ca1ba8a41adaa28aa9
Reporting entity
- Name
- AT&T INC.norm: at t
Victim entity
- Name
- AT&T INC.norm: at t
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTCREDENTIALSFINANCIAL
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.