AT&T Says Personal Information from 73M Customers Leaked on the Dark Web(forbes.com)
forbes.com
AT&T Says Personal Information from 73M Customers Leaked on the Dark Web
https://www.forbes.com/sites/tylerroush/2024/03/30/att-says-personal-information-from-73-million-customers-leaked-on-the-dark-web-including-social-security-numbers/
10 comments
This breach is quite old (2019), the news here is AT&T finally put out a press release today a week after the big story about the data finally showing up in public. Note AT&T still has no idea how their customers' data got out. At least they're admitting now the data is really theirs. Still not taking any responsibility for how it escaped or why it's been five years and they still don't know what went wrong.
Maybe they are better off not knowing - if they found out there would be a fair chance it was their fault.
Any consequences for them for the breach, or is it the customers' problem?
Any consequences for them for the breach, or is it the customers' problem?
Their press release ends with “As of today, this incident has not had a material impact on AT&T’s operations”. I assume that's some dumb legal requirement related to being a publicly traded company. But it sure looks like a statement of the legal problem right now with privacy breaches in the US.
Here's perhaps a naive question: How does AT&T have customer social security numbers? Would this be something they received directly from customers, or data they've acquired elsewhere and associated with their customer accounts? I may be forgetting it, but I don't recall giving my SSN to any cell provider.
It's pretty common for post-paid cell phone plans (especially with 'subsidized' phones) to credit check.
I've definitely always had to provide it when setting up an account. I assume for credit purposes.
Fun fact: if you tell AT&T you're an American citizen who is uncomfortable giving them your SSN, they will simply refuse to do business with you, but if you tell them you're an illegal immigrant who doesn't have an SSN, go into the store to show photo ID, and pay a $200 security deposit, they'll gladly sign you up with no SSN.
Extra fun fact: you can get a California driver's license as an undocumented immigrant without an SSN, but if you provide any documents that show you have legal presence then your SSN name must match exactly on the other documents before you can get a license.
Why would that be an issue, unless your name didn't match across documents you have?
Or are you trying to make some big deal about undocumented immigrants being able to get a driver's license?
Fun fact: Some state governments, and many of their residents agree, believe that it is not the state governments responsibility to handle federal immigration law, and that being able to meet the requirements to drive a car has nothing to do with residency status.
Or are you trying to make some big deal about undocumented immigrants being able to get a driver's license?
Fun fact: Some state governments, and many of their residents agree, believe that it is not the state governments responsibility to handle federal immigration law, and that being able to meet the requirements to drive a car has nothing to do with residency status.
It poses an annoyance, If you move to the US, get married, then attempt to get a driver's license it sets your plans back at least a few weeks while you get the paperwork done.
This doesn't make much sense, unless you live in an "antiquated" county. As an immigrant who got married shortly after arrival in the US, all the driver's license required for name discrepancies was the marriage certificate.
Yikes
Sometimes I think it would be a really fun challenge building a "matrix" of sorts to evaluate requirements and mitigations for large, real-world identity systems across various jurisdictions and with various merchants, something broadly similar to MITRE's ATT&CK Framework.
You can get a California driver's license. You can't get a RealID or Enhanced license. The state doesn't have the jurisdiction to enforce federal immigration law. Also an SSN is not proof of citizenship and is not enough to get a RealID or US passport, that requires a birth certificate or certificate of naturalization. Most "undocumented" immigrants don't stay fully undocumented for long, they get tax IDs from the IRS to pay taxes, driver's licenses from the states they live in to drive, etc. It's just CBP that doesn't get documentation of them.
Fun fact: if you repeat nonsense in multiple threads, people will stop listening to you. It’s kinda like a messaging broker ignoring malicious clients spewing garbage, in case you only understand programming analogies.
Then offer a rebuttal instead of threats of censorship. This isn’t Reddit.
It’s just BS, they offer prepaid service without any credit checks. Thus the upfront payment.
https://www.att.com/prepaid/plans/
IMO that 300$ upfront for a year plan is really compelling if you’re not constantly watching videos on your phone.
https://www.att.com/prepaid/plans/
IMO that 300$ upfront for a year plan is really compelling if you’re not constantly watching videos on your phone.
I was referring to home internet (fiber), not cellular service. Home internet does not offer a prepaid option.
So you acknowledge that “they will simply refuse to do business with you” is false.
Anyway, I’m actually them for home internet service and didn’t give them a SSN. No idea who you where you got the idea from.
Anyway, I’m actually them for home internet service and didn’t give them a SSN. No idea who you where you got the idea from.
From AT&T, when they told me that, after I told them I wasn't comfortable giving AT&T my SSN, because AT&T is not competent enough to keep that data safe. Case in point: the original post we're commenting on.
Though I will do a better job of clarifying in the future that I am specifically referring to my experiences with home internet and not cellular service, you raised a valid criticism of what I posted.
Hope you're not adversely affected by this breach. I know for sure I'm not.
Though I will do a better job of clarifying in the future that I am specifically referring to my experiences with home internet and not cellular service, you raised a valid criticism of what I posted.
Hope you're not adversely affected by this breach. I know for sure I'm not.
I'm sorry, I didn't realize every single subsection of every comment on HN were all meant to be strictly mutually exclusive, I'll do better in the future.
It’s even worse. I haven’t had att since 2011 and my data was in there. So they never delete former customer data. We need a federal law against this.
Why do these companies retain personal data when people are no longer customers? Like, the majority of the breach are people that ended their business relationship with these companies and yet they are the ones that suffer.
where on the darkweb?
we don't talk about clearnet like this, we say specific forums and websites even for leaks. which is the exact same form that the darkweb exists as
we don't talk about clearnet like this, we say specific forums and websites even for leaks. which is the exact same form that the darkweb exists as
When I see a story about a teacher being fired for being on onlyfans, I've never seen them include a link to their
I would chuckle and move on, but in this example I typically do go look and it turns out its usually just an ad campaign. As in, the firing did happen, but so did the hiring of a publicist and resharing on her social media and forums as the top of the funnel to join her OnlyFans.
With the darkweb I don't know where that discussion would be. which marketplace. and it is so cumbersome to go look.
(edit: and as the sister comment pointed out, OnlyFans is a "where", a specific website.)
With the darkweb I don't know where that discussion would be. which marketplace. and it is so cumbersome to go look.
(edit: and as the sister comment pointed out, OnlyFans is a "where", a specific website.)
To op's point, they do specify a website and not just 'internet'. I don't think they're necessarily saying they should include the onion link. You used to specifically hear about the Silk Road, for example.
Yes, and Silk Road was a darknet site.
Silk Road was pretty well known in mainstream culture, was a featured story in Wired, etc.. maybe that's what made it worth mentioning.
If this info is posted on some mostly unknown darknet site, maybe they just don't want to make it more popular.
Silk Road was pretty well known in mainstream culture, was a featured story in Wired, etc.. maybe that's what made it worth mentioning.
If this info is posted on some mostly unknown darknet site, maybe they just don't want to make it more popular.
To be fairer mainstream only ever mentioned Silk Road for the past 12 years consecutively and I only occasionally see another market when the Department of Justice does a press release, despite Silk Road being gone for a decade all the same
All markets were immediately bigger than Silk Road and continued growing far beyond what silk road ever was, bigger by every metric such as number of listings, breadth of types of products, volume, more advanced, more resilient to government fund and server seizure attempts…
We dont actually know if it was a “unknown darknet site” or one of the major ones, or simply a link posted on a Dread subreddit
All markets were immediately bigger than Silk Road and continued growing far beyond what silk road ever was, bigger by every metric such as number of listings, breadth of types of products, volume, more advanced, more resilient to government fund and server seizure attempts…
We dont actually know if it was a “unknown darknet site” or one of the major ones, or simply a link posted on a Dread subreddit
[dupe]
More discussion: https://news.ycombinator.com/item?id=39876565
More discussion: https://news.ycombinator.com/item?id=39876565
Is there an easy way to check if you're in the data set?
This is a great site for checking current and monitoring future breaches: https://haveibeenpwned.com/
It doesn't have this one, at least not yet. It has a different unconfirmed AT&T breach from 2021. https://www.troyhunt.com/inside-the-massive-alleged-att-data...
this is how data brokers and people sites get your private info if you are not already in their database
[deleted]