Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

AT&T’s 2024 call-record breach is confirmed; the reported $370,000 payment to delete the stolen data is not. WIRED reported that the company paid a threat actor in Bitcoin and received a video purporting to show deletion. AT&T did not publicly confirm the payment, and a video cannot prove that every copy was destroyed. The records contained call and text metadata, not the content of calls or messages, according to AT&T.

The distinction matters: the breach is documented in AT&T’s filing with the U.S. Securities and Exchange Commission, while the ransom transaction comes from media reporting. A later guilty plea in a wider hacking-and-extortion case adds context about the criminal campaign, but does not independently establish the details of AT&T’s payment or prove the stolen files are gone.

What the evidence establishes

Question What the public record says
Did AT&T suffer a breach? Yes. AT&T disclosed unauthorized access to and copying of call and text interaction records.
Did it pay $370,000? WIRED reported that it did, citing an alleged recipient, a researcher involved in facilitating the transaction and cryptocurrency evidence. AT&T has not publicly confirmed the payment.
Was the data deleted? A video purporting to show deletion was reportedly provided. That does not independently verify that every copy was destroyed.
Were calls or messages exposed? AT&T said the stolen records did not contain call or text content.
What did the later criminal case prove? It established a guilty plea related to a broad hacking-and-extortion conspiracy, not a court finding on every detail of AT&T’s individual payment.

What AT&T disclosed about the breach

In a July 12, 2024 SEC filing, AT&T said a threat actor unlawfully accessed and copied records from an AT&T workspace on a third-party cloud platform. The company said it learned on April 19, 2024 that an actor claimed to have accessed and copied call logs; its investigation found unauthorized access and exfiltration occurred between approximately April 14 and April 25, 2024.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The records covered calls and texts from May 1 through October 31, 2022, and January 2, 2023. AT&T said the records involved nearly all its wireless customers and customers of mobile virtual network operators using its network. Contemporary coverage often described the exposure as affecting more than 100 million people, but AT&T’s wording is safer: a record count is not automatically a count of unique people, since logs can include repeated interactions and numbers belonging to people who are not AT&T subscribers.

#1 Best Overall
RecorderGear TR600 Landline Phone Call Recorder for Analog/IP/Digital Lines, Automatic Telephone Recording Device - 16GB
  • AUTOMATIC / MANUAL CALL RECORDING - All incoming and outgoing calls can be set to record automatically. In manual mode, you can choose to record only certain phone calls with a click of a button. The TR600 is an upgraded model from our popular TR500 model.
  • ANALOG, IP, DIGITAL PHONE LINE COMPATIBLE - Not only can the TR600 record on analog phone lines, it can also record on digital and IP phones which sets it apart from our TR500 model. TIME/DATE STAMP - The time/date of each recording is displayed on the TR600 screen. Each file on the sd card is organized in chronological order and stamped with the time/date.
  • LOOP RECORDING / EXPANDABLE MEMORY (16GB INCLUDED) - Recording is never stopped due to a full memory card; when the memory fills up the newest calls are recorded over the oldest calls on the sd card.
  • EXTERNAL SPEAKER / COMPUTER PLAYBACK - Playback your recordings on the external speaker. Remove the SD card and playback/store the recordings on any MAC or Windows computer; no extra software is needed. VOICE/MEETING RECORDER MODE - Functions as a regular voice recorder for recording meetings/lectures.
  • CALLER ID / ASSISTANT RG SOFTWARE - Displays the callers information on the LCD screen (must have caller ID enabled phone line). Stay organize with the Call Assistant software (windows users only); easily manage and organize all your recordings.

The data included telephone numbers involved in interactions, counts of calls or texts, and aggregate call duration for a day or month. Some records also included cell-site identification numbers. Those identifiers can provide location-related context, but they are not the same as precise GPS tracking.

AT&T said the records did not contain the content of calls or texts, Social Security numbers, dates of birth, customer names as fields, or other direct personally identifiable information. It also cautioned that names can often be associated with phone numbers through publicly available tools. See the company’s filing for its full description.

AT&T said it activated incident response, hired outside cybersecurity experts and would notify current and former customers whose records were involved. It also disclosed that the Department of Justice granted delays in public disclosure on May 9 and June 5, 2024, citing potential national-security or public-safety concerns. At the time of the filing, AT&T said it did not believe the data was publicly available.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
LeCall Standalone Telephone Recorder/Phone Call Recorder/Call Recording Device for Analog Landline and Digital/IP Phones, AR120
  • 【Standalone】AR120 is a standalone digital telephone recorder with replaceable SD card, it can record for more than 970 hours with the attached 16GB card(expandable to 32GB). It will never stop recording because lack of storage if users have set LOOP recording.
  • 【MultiFunction Recording】AR120 is usually used to record phone calls. It can work with not only analog landlines/VoIP landlines, but also digital phones, IP phones, fixed wireless phones/terminals, PABX. Also, It can work as a voice logger for meetings, lectures, interviews, etc., and as a telephone answering machine.
  • 【Multiple Recording Modes】 It supports MANUAL/ AUTO(voltage trigger)/ TRIG(voice trigger) recording mode. Users can select proper mode according to requirements and conditions.
  • 【Easy setting】Users can set up the device on the keypad directly. Also, users can connect AR120 to a Windows PC to set it via “Log Manager Lite” software conveniently.
  • 【Convenient Recording Files Management】With built-in microphone, speaker and blue backlit LCD screen, users can search, review, playback, delete and mark the recording files on the device. While connecting the device to a Windows PC via the attached USB data cable, users can play back and manage recording files using the “Log Manager Lite” software on Windows(ONLY) computer. Users can export both recording audio files and records data sheet. Also, users can remove the SD card to play and store the recording files on MAC/Windows computer directly.

Where the $370,000 figure comes from

WIRED reported on July 14, 2024 that AT&T paid approximately $370,000 in Bitcoin in May to a member of the ShinyHunters hacking group in exchange for deletion of the stolen dataset and a video intended to demonstrate that deletion. The report relied on statements from the alleged recipient and a security researcher who helped facilitate the transaction, along with cryptocurrency-wallet evidence. The claim that the original demand was $1 million appears in secondary reporting and was not an AT&T statement.

That is meaningful reporting, but it is not the same as an official confirmation from AT&T. The SEC filing confirms the breach, not the ransom payment. The DOJ’s later account of a wider criminal scheme does not name this specific transaction as proof of AT&T’s payment. The accurate description is therefore “a payment reported by media, not publicly confirmed by AT&T.”

Why call metadata can still be sensitive

Metadata is not the conversation, but it can reveal patterns. A call graph—the numbers contacted, how often, and when—may expose relationships with family members, doctors, lawyers, financial institutions, journalists, political groups or law enforcement. When a number can be linked to a person using public information, those patterns can become more revealing. Cell-site identifiers in some records add limited location context.

Rank #3
RecorderGear PR200 Cell Phone Call Recording Device, Bluetooth Enabled, iPhone and Android Mobile Recorder
  • RECORDS CALLS ON ANY CELL PHONE (via bluetooth); Wirelessly Record both sides of a conversation on any bluetooth compatible mobile phone. Works on iPhone, Android, smart phones, and simple phones.
  • STAND ALONE VOICE RECORDER; In addition to recording cell phone calls, the PR200 can be used as a digital voice recorder to record meetings, lectures, dictations, or memos.
  • BUILT-IN SPEAKER; allows you to listen to recordings directly from the PR200. BUILT-IN USB PLUG; The PR200 turns into a USB flash drive; plug it into any MAC or Windows computer to listen to your recordings (no extra cables or software required)
  • 8GB MEMORY, 288HR CAPACITY, UP TO 12HR BATTERY; Plenty of room and battery life for your recordings
  • PREMIUM RECORDERGEAR BRAND; 1-Year warranty & Customer Support

That creates risks such as targeted phishing, impersonation and social engineering, as well as profiling of individuals or organizations. It does not mean every affected customer is at imminent risk of identity theft. AT&T said the records did not include Social Security numbers or dates of birth, so the incident’s most direct concerns are privacy and relationship mapping rather than conventional identity fraud based solely on those identifiers.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the Snowflake connection does—and does not—mean

AT&T described the affected location as a workspace on a third-party cloud platform; its filing excerpt did not name Snowflake. Contemporary reporting and congressional correspondence identified the platform as Snowflake and placed the incident among a wider campaign targeting customer environments. Senators’ July 2024 letter addressed AT&T and Snowflake following the breach.

Public reporting on the broader campaign pointed to compromised credentials and insufficient protections on some customer accounts, while the responsibilities and specific access paths were debated. The available AT&T disclosure does not establish that a vulnerability in Snowflake’s core service was exploited, nor does it publicly settle the exact initial access path into AT&T’s workspace. Describing the incident as an AT&T workspace breach hosted on a third-party cloud platform is more precise than saying simply that “Snowflake was hacked.”

Rank #4
Telephone Recorder,16GB USB Telephone Phone Voice Recorder,Mini Telephone Recorder for Landline,Get Power from Telephone System(Less Charging time)
  • AUTO RECHARGING AND MICRO SIZE – Micro size telephone record with auto recharging faction,just connect to the telephone line,no additional power needed
  • SUPPORT SD CARD FOR MEMORY STORAGE - Used for home/office telephone conversation recording,include 16GB memory card,support MAX 32GB micro SD card (not included)
  • RELIABLE FOR RECORDING - Designed by Embedded lunix system with high speed MCU,make it running stable,not like the other telephone recorder need PC support,its only support analog telephone system
  • PLUG & PLAY - Just connect the telephone cable to telephone line in / line out and turn the power switch to one side will start working,automatic recording each phone call

The later criminal case

On August 5, 2026, Canadian defendant Connor Riley Moucka pleaded guilty to a broad hacking-and-extortion conspiracy, according to the U.S. Department of Justice. Prosecutors described a campaign involving more than 165 organizations, billions of records and more than $2.5 million in ransom payments overall. The DOJ’s case materials describe stolen non-content call and text history records among data involved in the wider scheme.

Those campaign-wide figures must not be mistaken for AT&T-specific totals. The DOJ announcement does not publicly identify the reported $370,000 payment as part of its figure or independently establish the terms of AT&T’s transaction. The DOJ case page says alleged co-conspirator John Erin Binns remained outside U.S. custody. The guilty plea adds significant context about the broader operation, not certainty about whether every AT&T record was erased.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Can a ransom payment really delete stolen data?

Payment may be intended to reduce the risk of immediate publication, resale or further extortion, and may buy time for investigation and customer notification. But it cannot reverse the original access or make copies disappear by itself. A deletion video can show an actor removing files from one visible location; it cannot establish that no offline copy, backup, export, screenshot or collaborator-held duplicate exists, or that the displayed system held the entire dataset.

Even stronger verification—such as comparing cryptographic hashes or using a controlled escrow process—cannot guarantee that no duplicate exists elsewhere. A threat actor may also demand more money later. For a victim organization, a payment can raise legal, sanctions-screening, insurance, governance and reputational questions, and paying can incentivize further extortion. The reported AT&T transaction was a data-extortion payment, not a conventional ransomware payment to restore encrypted systems.

What AT&T customers can do

  • Be cautious with unexpected calls, texts and emails that mention your contacts, routines or a supposed AT&T account problem. Personal-seeming details do not prove the sender is legitimate.
  • Verify account or payment requests through a company’s official app, website or phone number—not a link or number in an unsolicited message.
  • Use unique passwords and multifactor authentication on important accounts, especially email, financial services and mobile-carrier accounts.
  • Watch for targeted impersonation attempts involving AT&T, banks, doctors, attorneys or family members. Do not share verification codes in response to an unsolicited request.
  • Be skeptical of messages offering breach compensation or demanding payment to protect your records. Contact AT&T through its official channels if you need to check a notice.

The disclosed data does not, by itself, mean every customer needs to buy credit monitoring. The practical response is to strengthen account security and stay alert to plausible, targeted social engineering.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.