What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
AT&T confirmed that attackers copied historical call-and-text metadata linked to nearly all of its wireless customers. The records could show which phone numbers interacted, how often, and the aggregate duration of calls; some included cell-site identifiers. AT&T said the files did not contain call or message content, customer names, Social Security numbers, or dates of birth.
What happened in the AT&T data theft?
AT&T said a threat actor accessed a workspace it used on a third-party cloud platform and copied files containing call and text interaction records. AT&T learned of the incident on April 19, 2024, and believes the files were accessed and copied between approximately April 14 and April 25. It disclosed the incident in an SEC filing on July 12, 2024; the filing said the Department of Justice had authorized disclosure delays on May 9 and June 5 for investigative reasons. AT&T’s SEC filing
The intrusion date and the dates represented in the stolen records are different. The incident occurred in 2024, while the records were primarily historical data from 2022 and one day in 2023.
What information was exposed—and what was not?
AT&T described the files as communications metadata, not recordings or message contents. Metadata can still reveal relationships and patterns: for example, which numbers communicated and how frequently.
#1 Best Overall
- (1) Att 5g Nano Size Sim Card included
- (1) SimBros Sim pin for removing old sims included
- Works with all unlocked or Att Devices from the past 10 years
- If your device is very old please check to make sure "NANO" sim is the correct size you need
- Will work on Both Postpaid and Prepaid!
| AT&T said the files included | AT&T said the files did not include |
|---|---|
| Telephone numbers associated with AT&T or AT&T-network accounts and numbers they interacted with | The content of phone calls |
| Counts of calls or texts and aggregate call duration | The content of text messages |
| Cell-site identification numbers for a subset of records | Customer names as a direct field in the disclosed files |
| Some numbers belonging to people who used other carriers | Social Security numbers or dates of birth |
AT&T said the files did not include other personal information of the kind listed above. But the absence of names does not make interaction records harmless: phone numbers can sometimes be connected to people through public or commercial databases, social media, or other sources.
What the cell-site identifiers can—and cannot—show
Cell-site identifiers appeared only in a subset of records. They may provide approximate location context associated with network activity, but AT&T’s filing did not describe a complete GPS trail or precise, real-time location history. It would be inaccurate to say that this incident exposed everyone’s exact movements.
Who may have been affected?
AT&T said the records covered nearly all of its wireless customers and customers of mobile virtual network operators (MVNOs) using AT&T’s network. The records could also contain AT&T wireline numbers and numbers belonging to customers of other carriers when those numbers interacted with AT&T or AT&T-network numbers.
“Nearly all” refers to AT&T wireless customers represented in the affected records; it does not mean every AT&T customer or every person who contacted an AT&T number had an entire account compromised. The inclusion of a non-AT&T number in an interaction record does not establish that the person’s carrier account was breached.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Rank #2
- 📦 10-Pack Value Bundle: Includes ten (10) genuine AT&T-compatible tri-cut SIM cards – perfect for resellers, phone shops, or bulk users.
- 🔓 Universal Compatibility: Works with all AT&T locked phones and any unlocked GSM device that supports AT&T’s network.
- 📱 3-in-1 SIM Format: Each SIM includes Standard, Micro, and Nano cuts to fit any device – no adapters needed.
- ⚡ 4G LTE & 5G Ready: Access fast and reliable AT&T coverage with support for 4G LTE and 5G networks (where available).
- 🛠️ Easy Activation: Pair with any AT&T prepaid or postpaid plan. Simply insert, activate online or by phone, and you're ready to go.
Which dates were covered?
| What the date refers to | Dates |
|---|---|
| Historical interaction records primarily covered | May 1–October 31, 2022 |
| Additional record date | January 2, 2023 |
| Approximate period attackers accessed and copied files | April 14–25, 2024 |
| AT&T said it learned of the incident | April 19, 2024 |
| Public SEC disclosure | July 12, 2024 |
AT&T said on July 12, 2024, that it did not believe the data was publicly available. That was its assessment at the time of disclosure, not a guarantee that no copies existed or that the information could never be misused.
Is this the same as AT&T’s other 2024 breach?
No. AT&T’s July call-and-text metadata disclosure was separate from a personal-information incident disclosed in March 2024. The March disclosure concerned records associated with approximately 7.6 million current customers and 65.4 million former customers, with more sensitive personal fields in some records. The two incidents involved different data and should not be treated as one breach. Associated Press coverage of the separate March incident
| Incident | Disclosure | Main data involved |
|---|---|---|
| Separate personal-information incident | March 2024 | Older personal and account information, with more sensitive fields in some records |
| Call-and-text metadata incident | July 12, 2024 | Numbers contacted, interaction counts, aggregate call duration, and limited cell-site identifiers |
What does the breach mean in practice?
The principal concern from this dataset is not that an attacker could directly read a message or use an exposed password. Rather, communication patterns can help a scammer tailor a convincing call or text, impersonate a familiar contact or organization, or exploit private relationships and business connections. Such information can also create risks of harassment or unwanted scrutiny.
Reporting linked the incident to attacks involving customer environments hosted on Snowflake. That attribution should not be simplified to “Snowflake’s core platform was breached”: contemporary reporting quoted Snowflake as saying it found no evidence that the incident resulted from a vulnerability, misconfiguration, or breach of its platform. The Washington Post’s account of the incident and cloud-platform context
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Rank #3
- NO CONTRACT: Pay $5 - $25/month for a fully customizable phone plan - choose your talk, text, and data with no strings attached; upgrade, downgrade or cancel your plan anytime with no penalties
- UNIVERSAL SIM CARD INCLUDED: The kit contains one three-in-one SIM card (nano, micro, and standard sizes) to fit most unlocked GSM-compatible smartphones
- NATIONWIDE 5G COVERAGE: Stay connected coast to coast with nationwide coverage on America's largest 5G network
- INTERNATIONAL CALLS TO 60+ COUNTRIES: All Tello plans include international calling to over 60 countries
- EASY ACTIVATION: Bring your own phone and activate your SIM on the Tello website; check your phone compatibility and coverage maps before purchasing to confirm service in your area
What should AT&T customers do?
These steps are proportionate to exposed call-and-text metadata and useful against targeted scams:
- Treat unexpected calls and texts cautiously. A message that references a person or organization you contact may still be fraudulent. Verify requests through a separate, trusted channel.
- Do not give out passwords, one-time codes, Social Security numbers, or payment details in response to an unsolicited call, text, or email.
- Go directly to AT&T’s app or website instead of following links in unexpected messages.
- Use unique passwords and multifactor authentication for email, financial, social-media, and messaging accounts. This is good account security, although AT&T did not report passwords in this incident’s dataset.
- Check AT&T account activity and bills for unfamiliar services or account changes. If you find an unauthorized account change, contact AT&T’s wireless fraud team at 877-844-5584.
- Report suspicious calls or texts. AT&T says customers can forward suspicious messages to 7726 (SPAM); its spam-reporting page also describes its ActiveArmor service.
Do you need to change your password, number, or credit status?
- Password: A password change is reasonable general hygiene, but this particular dataset was not reported to contain passwords. Prioritize a change if you reused a password, received a separate credential-exposure notice, or see suspicious account activity.
- Phone number: A number change is not a routine response to historical metadata exposure. Consider it only if you face persistent harassment, stalking, or targeted abuse.
- Credit freeze: A freeze is aimed at new-account fraud and is not a direct remedy for call-detail records. It may be relevant if your Social Security number or other identity data was exposed in the separate March incident or another breach.
What remains uncertain, and what is the current status?
AT&T’s 2025 annual report continued to identify the July 2024 copying of mobile customer call data as a cybersecurity incident and noted related litigation and regulatory risks. That establishes the incident remained relevant to AT&T’s disclosures; it does not by itself resolve every question about the disposition of copies or the outcome of legal matters. AT&T’s 2025 annual report
Later reporting said AT&T paid about $370,000 to a person who claimed to have obtained the data, with the reported aim of securing its deletion. A payment or deletion claim cannot establish for outsiders that every copy was destroyed or that the data was never shared. The reported payment and deletion claim
Later reporting also identified Connor Moucka and John Binns as people U.S. authorities accused of involvement in broader Snowflake-related attacks that included the AT&T theft. Those are allegations as described in the report, not a basis here to assert a final finding of responsibility. TechCrunch’s report on the charges
Can you request your AT&T data?
AT&T’s U.S. Data Request Center explains how residents can request information associated with them, subject to verification and applicable limits. It is a general privacy request process, not a guaranteed breach-specific lookup that will confirm whether a particular record appeared in the stolen files. See the Data Request Center overview and request submission page.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




