Summary:
-
Ransom Payment: AT&T paid over $300,000 to a hacker from the ShinyHunters group to delete stolen phone call records of tens of millions of customers. The payment was verified through a blockchain transaction on May 17 for 5.7 bitcoin, reduced from an initial $1 million demand.
-
Data Breach: The hacker exploited unsecured Snowflake cloud storage accounts, lacking multi-factor authentication, to steal data from more than 150 companies. Victims include Ticketmaster, Santander, LendingTree, and Advance Auto Parts.
-
Proof of Deletion: AT&T received a video as proof of data deletion from the hacker. The hacker, likely John Binns, was already under indictment for a previous T-Mobile hack when the AT&T breach occurred.
!