Incident · 8-K Item 1.05
AT&T discloses theft of call and text records for nearly all wireless customers
Compiled 2026-09-27 from public records. By the cisonews.net Desk.
AT&T disclosed on July 12, 2024 that threat actors had copied files containing records of calls and texts made by nearly all of its wireless customers over roughly six months in 2022. The company learned of the claim on April 19, 2024; the filing came 84 days later because the US Department of Justice twice decided a delay was warranted.
What was taken
AT&T said the access was to a workspace it held on a third-party cloud platform, with files taken between April 14 and 25, 2024. The records cover interactions from about May 1 to October 31, 2022, plus January 2, 2023, and include the numbers each line interacted with, counts, and aggregate duration, with cell site identifiers for a subset. The files did not contain call or text content, Social Security numbers or dates of birth.
The disclosure delay
This is one of the few filings in the log that used the national security delay in Item 1.05(c).
Status at filing
AT&T said it did not believe the data was publicly available and did not expect a material financial impact. The filing does not name the cloud platform.
Sources
- 2024-07-12 · AAT&T Inc., Form 8-K (SEC EDGAR), published July 12, 2024
Tier A: the organization itself, a regulator or SEC EDGAR. Tier B: established press. Each fact on this page carries its supporting passage in the page source.
See an error? Corrections are made on the page and logged on the corrections page. Send them through contact.