Historical disclosure revision 2
Disclosures and evidence
Revision 2 of 2 · Evidence cutoff Feb 12, 2025, 12:00 AM UTC
14 prior statements preserved · 2 statements added. Attributed source statements retain the source’s qualifications.
What the company disclosed
AT&T Inc. stated: “On April 19, 2024, AT&T Inc. (“AT&T”) learned that a threat actor claimed to have unlawfully accessed and copied AT&T call logs. AT&T immediately activated its incident response process to investigate and retained external cybersecurity experts to assist. Based on its investigation, AT&T believes that threat actors unlawfully accessed an AT&T workspace on a third-party cloud platform and, between April 14 and April 25, 2024, exfiltrated files containing AT&T records of customer call and text interactions that occurred between approximately May 1 and October 31, 2022, as well as on January 2, 2023, as described below.”
Affected organizations and relationships
AT&T Inc. stated: “On April 19, 2024, AT&T Inc. (“AT&T”) learned that a threat actor claimed to have unlawfully accessed and copied AT&T call logs. AT&T immediately activated its incident response process to investigate and retained external cybersecurity experts to assist. Based on its investigation, AT&T believes that threat actors unlawfully accessed an AT&T workspace on a third-party cloud platform and, between April 14 and April 25, 2024, exfiltrated files containing AT&T records of customer call and text interactions that occurred between approximately May 1 and October 31, 2022, as well as on January 2, 2023, as described below.”
Operational impact
AT&T Inc. stated: “As of the date of this filing, this incident has not had a material impact on AT&T’s operations, and AT&T does not believe that this incident is reasonably likely to materially impact AT&T’s financial condition or results of operations.”
Reported data impact
AT&T Inc. stated: “On April 19, 2024, AT&T Inc. (“AT&T”) learned that a threat actor claimed to have unlawfully accessed and copied AT&T call logs. AT&T immediately activated its incident response process to investigate and retained external cybersecurity experts to assist. Based on its investigation, AT&T believes that threat actors unlawfully accessed an AT&T workspace on a third-party cloud platform and, between April 14 and April 25, 2024, exfiltrated files containing AT&T records of customer call and text interactions that occurred between approximately May 1 and October 31, 2022, as well as on January 2, 2023, as described below.”
AT&T Inc. stated: “The data does not contain the content of calls or texts, personal information such as Social Security numbers, dates of birth, or other personally identifiable information. Current analysis indicates that the data includes, for these periods of time, records of calls and texts of nearly all of AT&T’s wireless customers and customers of mobile virtual network operators (“MVNO”) using AT&T’s wireless network. These records identify the telephone numbers with which an AT&T or MVNO wireless number interacted during these periods, including telephone numbers of AT&T wireline customers and customers of other carriers, counts of those interactions, and aggregate call duration for a day or month. For a subset of records, one or more cell site identification number(s) are also included. While the data does not include customer names, there are often ways, using publicly available online tools, to find the name associated with a specific telephone number.”
Response
AT&T Inc. stated: “On April 19, 2024, AT&T Inc. (“AT&T”) learned that a threat actor claimed to have unlawfully accessed and copied AT&T call logs. AT&T immediately activated its incident response process to investigate and retained external cybersecurity experts to assist. Based on its investigation, AT&T believes that threat actors unlawfully accessed an AT&T workspace on a third-party cloud platform and, between April 14 and April 25, 2024, exfiltrated files containing AT&T records of customer call and text interactions that occurred between approximately May 1 and October 31, 2022, as well as on January 2, 2023, as described below.”
AT&T Inc. stated: “AT&T has taken additional cybersecurity measures in response to this incident including closing off the point of unlawful access. AT&T will provide notice to its current and former impacted customers.”
Disclosure timeline
AT&T Inc. stated: “On April 19, 2024, AT&T Inc. (“AT&T”) learned that a threat actor claimed to have unlawfully accessed and copied AT&T call logs. AT&T immediately activated its incident response process to investigate and retained external cybersecurity experts to assist. Based on its investigation, AT&T believes that threat actors unlawfully accessed an AT&T workspace on a third-party cloud platform and, between April 14 and April 25, 2024, exfiltrated files containing AT&T records of customer call and text interactions that occurred between approximately May 1 and October 31, 2022, as well as on January 2, 2023, as described below.”
AT&T Inc. stated: “Date of report (Date of earliest event reported) May 6, 2024”
AT&T Inc. stated: “| Date: July 12, 2024 | By: / s/ Stacey Maris . Stacey Maris Senior Vice President, Secretary and Chief Privacy Officer”
Disclosure evolution
AT&T Inc. stated: “On May 9, 2024, and again on June 5, 2024, the U.S. Department of Justice determined that, under Item 1.05(c) of Form 8-K, a delay in providing public disclosure was warranted. AT&T is now timely filing this report. AT&T is working with law enforcement in its efforts to arrest those involved in the incident. Based on information available to AT&T, it understands that at least one person has been apprehended. As of the date of this filing, AT&T does not believe that the data is publicly available.”
AT&T Inc. stated: “Cyberattacks can cause equipment or network failures, copying or loss of information, including sensitive personal information of customers or employees or proprietary information, as well as disruptions to our or our customers’, suppliers’ or vendors’ operations, which could result in significant expenses, potential investigations and legal liability, a loss of current or future customers and reputational damage. Additional resources and management attention may be necessary to respond to government inquiries and requirements, including potentially conflicting demands and requirements from multiple government agencies. Moreover, the amount and scope of insurance that we maintain against losses resulting from any such events or security breaches may not be sufficient to cover our losses or otherwise adequately compensate us for any disruptions to our business that may result. As our networks evolve, they are becoming increasingly reliant on software and cloud technologies to handle growing demands for data consumption. Cyberattacks against the Company and its suppliers and vendors have occurred in the past, including from highly sophisticated, state-sponsored actors as noted above, and will continue to occur in the future and are increasing in frequency, scope and potential harm over time. For example, in July 2024, the Company disclosed a cybersecurity incident on Item 1.05 of Form 8-K relating to the copying of mobile customer call data.”
Qualifications and uncertainty
AT&T Inc. stated: “On April 19, 2024, AT&T Inc. (“AT&T”) learned that a threat actor claimed to have unlawfully accessed and copied AT&T call logs. AT&T immediately activated its incident response process to investigate and retained external cybersecurity experts to assist. Based on its investigation, AT&T believes that threat actors unlawfully accessed an AT&T workspace on a third-party cloud platform and, between April 14 and April 25, 2024, exfiltrated files containing AT&T records of customer call and text interactions that occurred between approximately May 1 and October 31, 2022, as well as on January 2, 2023, as described below.”
AT&T Inc. stated: “On May 9, 2024, and again on June 5, 2024, the U.S. Department of Justice determined that, under Item 1.05(c) of Form 8-K, a delay in providing public disclosure was warranted. AT&T is now timely filing this report. AT&T is working with law enforcement in its efforts to arrest those involved in the incident. Based on information available to AT&T, it understands that at least one person has been apprehended. As of the date of this filing, AT&T does not believe that the data is publicly available.”
AT&T Inc. stated: “As of the date of this filing, this incident has not had a material impact on AT&T’s operations, and AT&T does not believe that this incident is reasonably likely to materially impact AT&T’s financial condition or results of operations.”
AT&T Inc. stated: “In 2024, we did not identify and were not aware of any risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, that we believe have materially affected or are reasonably likely to materially affect our business strategy, results of operations or financial condition. For a discussion of cybersecurity risk, please see the information contained under the heading “Cyberattacks impacting our networks, systems or data or those of our suppliers or vendors may have a material adverse effect on our operations or results of operations” of Item 1A.”
Disclosure sources and provenance
- U.S. Securities and Exchange Commission Filed July 12, 2024Report/event date: May 6, 2024Document form: 8-K · Item 1.05 and9.01SEC HTTPS source · Retrieved Oct 7, 2026, 2:38 PM UTC · Retained Oct 7, 2026, 2:38 PM UTC
- U.S. Securities and Exchange Commission Filed February 12, 2025Report/event date: December 31, 2024Document form: 10-K · Item 1A and1CSEC HTTPS source · Retrieved Oct 7, 2026, 2:38 PM UTC · Retained Oct 7, 2026, 2:38 PM UTC
Evidence limitations
- Issuer disclosures establish what was reported, not independent incident verification.