AT&T Paid $370,000 For the Deletion of Stolen Phone Call Records

Summary:

  1. Ransom Payment: AT&T paid over $300,000 to a hacker from the ShinyHunters group to delete stolen phone call records of tens of millions of customers. The payment was verified through a blockchain transaction on May 17 for 5.7 bitcoin, reduced from an initial $1 million demand.

  2. Data Breach: The hacker exploited unsecured Snowflake cloud storage accounts, lacking multi-factor authentication, to steal data from more than 150 companies. Victims include Ticketmaster, Santander, LendingTree, and Advance Auto Parts.

  3. Proof of Deletion: AT&T received a video as proof of data deletion from the hacker. The hacker, likely John Binns, was already under indictment for a previous T-Mobile hack when the AT&T breach occurred.

Read more on Wired

3 Likes