• AT&T apparently paid a hacker big bucks to delete stolen phone re

    From TechnologyDaily@1337:1/100 to All on Mon Jul 15 15:45:05 2024
    AT&T apparently paid a hacker big bucks to delete stolen phone record data

    Date:
    Mon, 15 Jul 2024 15:40:01 +0000

    Description:
    AT&T allegedly pays more than $300,000 for hackers to wipe the data stolen from affected Snowflake account.

    FULL STORY ======================================================================

    A poorly protected Snowflake account has reprotedly cost AT&T more than $300,000 following the recent cyberattack against the telecom giant.

    A few months ago, it was reported that a threat actor managed to compromise more than 150 company accounts on Snowflake, thanks to their poor password hygiene, and not securing their accounts with multi-factor authentication ( MFA ).

    Among them was AT&T, after a hacker who was reportedly part of the ShinyHunters threat actor group, accessed the companys Snowflake account, and stole sensitive customer data. Bitcoin ransom

    The data included call and text messaging metadata (but not the contents of the communications), telephone numbers of nearly all AT&Ts cellular
    customers, numbers of customers of other wireless carriers who communicated with AT&T customers in mid-2022, and landline phone numbers of people communicating with AT&T customers during the same timeframe.

    Apparently, hackers could use the data to identify the owners of individual phone numbers.

    At the same time, a different hacker also accessed the same database - John Erin Binns - who later reached out to a security researcher with the alias Reddington, to help facilitate a buyback of the data. These two individuals were apparently asking for $1 million in cryptocurrency, in exchange for permanently deleting the data. AT&T took it down to roughly $300,000, but before the transaction could be made, Binns was arrested in Turkey, for an entirely different cybercrime, allegedly committed in 2021.

    In the end, Reddington facilitated the transaction to the ShinyHunters
    hacker, in the amount of 5.72 bitcoin (around $359,000 at press time). Multiple researchers confirmed that the transaction had taken place, and that the hackers provided video proof that the entire database was wiped.

    Via Wired More from TechRadar Pro Snowflake is bringing in some big MFA changes following recent security incidents Here's a list of the best firewalls today These are the best endpoint protection tools right now



    ======================================================================
    Link to news story: https://www.techradar.com/pro/security/atandt-apparently-paid-a-hacker-big-buc ks-to-delete-stolen-phone-record-dats


    --- Mystic BBS v1.12 A47 (Linux/64)
    * Origin: tqwNet Technology News (1337:1/100)