EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/att-call-logs-breach-2024
083/430

File EL-0348CriticalResolvedData Breach / Metadata Exfiltration

AT&T Customer Call Logs Breach

Also filed as AT&T CDR Leak · ShinyHunters AT&T Leak

This incident involved the unauthorized exfiltration of Call Detail Records (CDRs) belonging to AT&T customers. The leaked metadata covers a period of over 18 months, providing a comprehensive social graph of nearly all affected users. The data is highly valuable for surveillance, revealing patterns of life, contacts, and physical locations.

  • #at-t
  • #call-detail-records
  • #metadata
  • #shinyhunters
  • #pii
  • #social-graphing
Notoriety8/10
Event
12 Jul 2024
Disclosed
12 Jul 2024
Target
AT&T Mobility
Actor
ShinyHunters
Scale
Metadata for 110 Million+ customers
Status
Resolved

01Summary

The breach, disclosed on July 12, 2024, involved the release of metadata from AT&T's cellular customers. The dataset, provided by the entity known as ShinyHunters, covers call records spanning from May 1, 2022, to October 31, 2022. Crucially, the data does not contain the actual audio or text content of calls, but rather the metadata, including origin and destination numbers, call duration, and Cell Site IDs. This metadata allows for sophisticated 'social graphing,' enabling analysts to map the entire social network of a target, track their movements, and determine their routines. The sheer volume and granularity of the data make it an extremely potent tool for intelligence gathering, far exceeding the value of simple phone numbers.

02Background

Telecommunications metadata has long been recognized by security researchers and privacy advocates as a powerful form of surveillance data. Unlike content interception, metadata—which records who called whom, when, and for how long—can reveal intimate details about a person's life, including their relationships, political affiliations, and physical movements. The leak capitalized on this inherent value, demonstrating the depth of data collection within major carriers.

03Key revelations

  1. 01The ability to map the entire social network of any target.
  2. 02The precise location (via Cell Site ID) of individuals at the time of communication.
  3. 03The sheer scale of the data, affecting millions of users over an 18-month period.

04Technical analysis

The leaked data is structured as Call Detail Records (CDRs), which are standard records generated by cellular network switches. The key fields—Origin/Destination Number, Call Duration, and Cell Site ID—allow for triangulation and temporal analysis. The Cell Site ID is particularly critical, as it links the communication event to a specific geographical location at a specific time, enabling the reconstruction of a target's physical movements (pattern of life analysis).

Attack vector
Unknown (Likely internal network compromise or third-party vendor breach)
Attack method
Data Exfiltration
Exfiltration
Data Dump/Bulk Transfer
Malware type
Stealer/Exfiltration

MITRE ATT&CK techniques

  • T1049

05Threat actor

ShinyHunters is an anonymous entity known for leaking large, high-value datasets, often related to corporate or governmental infrastructure. Their operations are characterized by the sale of data on underground marketplaces, targeting maximum financial and informational impact.

MITRE groups

  • T1049

Attribution sources

  • ShinyHunters

06Victims and impact

Countries affected

  • United States

07Data exposed

Data types

  • Phone Numbers
  • Call Metadata
  • Location Data
  • PII

Notable documents

  • AT&T MOBILITY - CALL DETAIL RECORDS (CDR)

08Financial damage

Damage is assessed based on the potential for identity theft, blackmail, and corporate espionage.

09Timeline

  1. 2022-05-01Start date of the leaked data period.
  2. 2022-10-31End date of the leaked data period.
  3. 2024-07-12Date the data was publicly disclosed by ShinyHunters.

10On the record

Metadata kills. We know who you called, when you called, and where you were standing when you called them.

ShinyHunters, Highlighting the profound surveillance value of call metadata.

11Reaction and fallout

Public reaction

The leak triggered widespread alarm among privacy advocates and legal experts, highlighting the inherent risks of centralized telecommunications data. It fueled renewed calls for stronger federal regulation of metadata retention and usage.

Political impact

The incident intensified debates regarding the balance between national security interests and individual privacy rights in the digital age. It put pressure on major carriers to improve data security protocols.

Geopolitical consequences

The availability of such detailed, large-scale metadata reinforces the capabilities of state-level surveillance, raising concerns about global digital privacy standards and corporate accountability.

12Legal

No immediate legal action was reported against AT&T, but the incident serves as a major case study for potential future class-action lawsuits and regulatory fines.

13Aftermath

Policy changes

  • Increased scrutiny of telecommunications data retention policies.

Regulatory changes

  • Potential for stricter enforcement of data minimization principles in the telecom sector.

Security improvements

  • Increased focus on end-to-end encryption adoption for all communication methods.

14Significance and legacy

Significance

This breach is significant because it demonstrated the immense, often underestimated, value of communication metadata. It moved the focus of data breaches from merely stealing credentials to harvesting 'patterns of life' data, fundamentally changing the threat model for telecommunications infrastructure.

Legacy

The incident has cemented 'metadata' as a primary target for cybercriminals and state actors. It has accelerated the industry shift toward privacy-enhancing technologies and reinforced the concept of 'surveillance capitalism' in the context of communication.

15Disclosure and media

Authentication
Source disclosure by the alleged perpetrator (ShinyHunters)

16Field notes

  1. 01The data did not contain the actual content of calls, making the metadata itself the primary source of value.
  2. 02The inclusion of Cell Site IDs allows for geographical reconstruction, which is a key component of intelligence analysis.

17Resolution

The data was publicly released and subsequently sold on dark web marketplaces, marking the end of the initial leak phase.

18Sources

References

  1. [1]ShinyHunters Leak Disclosure
  2. [2]AT&T Security Advisory
Fact sheetEL-0348

Dates

Event
12 Jul 2024
Started
1 May 2022
Ended
31 Oct 2022
Discovered
12 Jul 2024
Disclosed
12 Jul 2024
Ongoing
No

Target

Organisation
AT&T Inc.
Type
Technology Company
Sector
Telecommunications
Country
United States

Actor

Name
ShinyHunters
Type
Criminal Gang
Motivation
Financial gain and data monetization through the sale of highly sensitive metadata.
Attribution
Medium
Status
Active
Arrested
No
Convicted
No

Data

Volume
Metadata for 110 Million+ customers
Sensitivity
Top Secret
Published
Yes
Sold (dark web)
Yes

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.