Editorial draft v1 · Evidence reader R2 · Evidence cutoff: February 12, 2025

Disclosures covered: July 12, 2024 Form 8-K and the 2024 annual report filed February 12, 2025. The case concerns the cloud call-record incident identified in the July filing, not other AT&T incidents.

AT&T's July 2024 disclosure concerned records of customer calls and texts copied from a workspace on a third-party cloud platform. The company believed the copying occurred in April 2024, but the records principally described interactions from 2022, plus a day in January 2023. The distinction between when records were created, when they were taken, and when the incident became public is central to understanding the account. July filing

Three different timelines

AT&T said it learned on April 19, 2024 that a threat actor claimed to have unlawfully accessed and copied call logs. It activated its incident-response process and retained external cybersecurity experts. Its investigation led it to believe actors accessed the cloud workspace and exfiltrated files between April 14 and April 25. The filing carries a May 6 report header, but was filed and signed July 12. According to AT&T, Justice Department determinations on May 9 and June 5 warranted delaying public disclosure. Those dates have different roles; the header is not evidence of a May 6 intrusion. July filing

The copied records covered interactions from approximately May 1 through October 31, 2022, and January 2, 2023. AT&T's then-current analysis indicated that, for those periods, the data included records for nearly all its wireless customers and customers of mobile virtual network operators using its wireless network. This is a statement about a defined record population and historical windows, rather than all customer information across all years or an exact number of unique people. July filing

What the records contained

The records identified telephone numbers with which an AT&T or MVNO wireless number interacted, including numbers belonging to AT&T wireline customers and customers of other carriers. They included interaction counts and aggregate call durations by day or month. A subset also included cell-site identification numbers. The company said the data did not contain call or text content, customer names, Social Security numbers, or dates of birth. July filing

AT&T nevertheless acknowledged that publicly available tools could often associate a telephone number with a name. The absence of names or message contents therefore does not make the records anonymous or establish that the exposure was harmless. That distinction follows the company's own description of the data and its identification limits. July filing

Response and later reporting

AT&T said it closed the point of unlawful access, took additional cybersecurity measures, and would notify current and former impacted customers. It was working with law enforcement and understood, from the information available to it, that at least one person had been apprehended. As of the July filing, the company did not believe the data was publicly available. It reported no material operational impact and did not expect a material effect on financial condition or results. These were dated statements, not guarantees about later distribution or consequences. July filing

The annual report referred back to the July disclosure as an example involving copied mobile-customer call data. It also said AT&T had not identified cybersecurity risks during 2024 that it believed had materially affected, or were reasonably likely to materially affect, its strategy, results, or financial condition. The same broader risk discussion mentioned past attacks by state-sponsored actors. It did not attribute this call-record incident to a state actor; the general risk language cannot supply event-specific attribution. 2024 annual report

Editorial interpretation: the case illustrates how a later intrusion can expose older records, and how disclosure timing can differ from awareness and access. The selected evidence does not name the cloud provider, establish a named attacker, quantify a unique affected-person count, or provide a final account of misuse. It supports a bounded history of the incident identified in the July filing. July filing · 2024 annual report

Sources

Disclosure history

Article draft version 1 · Evidence reader revision 2 · Evidence cutoff Feb 12, 2025, 12:00 AM UTC

The narrative has editorial wording approval. The evaluations below apply to retained extractive disclosure readers, not to the narrative wording.

Disclosure sources and provenance

  • U.S. Securities and Exchange Commission Filed July 12, 2024Report/event date: May 6, 2024Document form: 8-K · Item 1.05 and9.01SEC HTTPS source · Retrieved Oct 7, 2026, 2:38 PM UTC · Retained Oct 7, 2026, 2:38 PM UTC
  • U.S. Securities and Exchange Commission Filed February 12, 2025Report/event date: December 31, 2024Document form: 10-K · Item 1A and1CSEC HTTPS source · Retrieved Oct 7, 2026, 2:38 PM UTC · Retained Oct 7, 2026, 2:38 PM UTC