On April 19, 2024, AT&T learned a threat actor had unlawfully accessed an AT&T workspace on a third-party cloud platform and, between April 14 and April 25, 2024, exfiltrated call/text interaction records for nearly all AT&T wireless and MVNO customers covering May 1–October 31, 2022 and January 2, 2023. Records included phone numbers, interaction counts, aggregate durations, and some cell-site IDs, but no call content, SSNs, or DOBs. AT&T contained access; DOJ twice authorized 1.05(c) disclosure delays.