Yazılar

FBI Warns of Call Log Breach Following Hack of AT&T’s System

The FBI has warned its agents that a significant data breach of AT&T’s system last year likely resulted in hackers stealing months’ worth of call and text logs, potentially compromising the identities of confidential informants. This breach, which impacted all FBI devices using AT&T’s public safety network, included sensitive information such as mobile phone numbers and the numbers agents communicated with, according to reports from Bloomberg News.

The breach occurred in April 2022, when hackers downloaded data from around 109 million customer accounts, which included records of calls and texts. The stolen records, while not containing the content of the communications, could still expose sensitive connections between FBI agents and their informants. This raises serious concerns about the security of confidential sources, especially since the breach could link agents to their secret sources.

In a communication to FBI agents across the country, the agency warned that their activities on the AT&T network were likely among the stolen data, putting both agents and their sources at risk. An FBI spokesperson emphasized the agency’s duty to safeguard the identities and safety of its confidential informants, who often provide critical information at great personal risk.

AT&T spokesperson Alex Byers responded to the breach, stating that the company had worked closely with law enforcement to mitigate the impact on government operations following the incident. This breach is part of a broader concern about cyber-espionage targeting U.S. telecom networks. The U.S. government has responded to these threats, including recent steps to counter Chinese-linked cyber-espionage efforts against U.S. telecom companies.

While AT&T and other major telecom firms such as Verizon have confirmed their networks were targeted by cyber hackers, they also assured that their systems are now secure after cooperating with U.S. law enforcement and government agencies.

 

Meta’s Irish Division Penalized $264 Million for Data Breach

Meta Fined $264 Million Over 2018 Data Breach Impacting 29 Million Users

Meta Platforms’ Irish division has been fined €251 million ($264 million or approximately Rs. 2,242 crore) by Ireland’s Data Protection Commission (DPC) following two investigations into a 2018 data breach. The breach reportedly exposed the personal data of 29 million Facebook users globally, including full names, email addresses, phone numbers, timeline posts, and group memberships.

Breach Details and Global Impact

The breach was first reported by Meta Platforms Ireland Limited in September 2018. According to the DPC’s findings, the data of around three million users in the European Union and European Economic Area was compromised. The breach occurred due to unauthorized third-party exploitation of user tokens on Facebook. Meta and its US parent company addressed the issue shortly after it was discovered.

GDPR Violations and Findings

The DPC concluded that Meta violated General Data Protection Regulation (GDPR) rules by failing to adequately document details of the breach and the corrective measures taken. Additionally, Meta was found to have breached GDPR’s requirement to ensure that only data necessary for specific purposes is processed by default.

Meta’s Response and Prior Fines

In a statement, a Meta spokesperson highlighted that the company had taken immediate action to address the breach, notified affected users, and implemented measures to prevent future incidents. Earlier this year, the Irish watchdog fined Meta €91 million ($95.6 million or approximately Rs. 812 crore) over an investigation related to password storage practices.

AT&T and Verizon Acknowledge Salt Typhoon Cyberespionage, Networks Secured

AT&T and Verizon confirmed on Saturday that their systems were targeted by Salt Typhoon, a Chinese-linked cyberespionage operation, but assured the public that their U.S. networks are now secure. Both companies are collaborating with law enforcement and government agencies to assess and mitigate any remaining risks.

An AT&T spokesperson stated, “We detect no activity by nation-state actors in our networks at this time.” They added that the People’s Republic of China targeted a small group of individuals with foreign intelligence value. While only limited information was compromised, AT&T continues to monitor and remediate its networks to safeguard customer data.

Verizon, in its statement, reported similar containment efforts. Chief Legal Officer Craig Silliman said, “We have not detected threat actor activity in Verizon’s network for some time, and after considerable work addressing this incident, we can report that Verizon has contained the activities associated with this particular incident.” The containment has been independently verified by a respected cybersecurity firm.

The U.S. Department of Defense and Federal Communications Commission have not commented on the incident. However, on Friday, officials added a ninth unnamed telecom company to the list of victims. Hackers affiliated with Salt Typhoon allegedly gained extensive access to telecom networks, enabling them to geolocate millions of individuals and intercept phone calls at will.

Chinese officials have dismissed such allegations as disinformation, maintaining that Beijing opposes cyberattacks in all forms. Previous reports linked the Salt Typhoon operation to theft of telephone audio intercepts and call record data from companies like AT&T, Verizon, and Lumen.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) responded to the breach on Dec. 18 by recommending that senior government and political figures transition to end-to-end encrypted communication apps. High-profile targets of Salt Typhoon reportedly included individuals associated with Vice President Kamala Harris and former President Donald Trump’s campaigns.

Lawmakers expressed bipartisan concern over the severity of the breach. Senator Ben Ray Luján (D-NM) described it as “the largest telecommunications hack in our nation’s history,” while Senator Ted Cruz (R-TX) emphasized the urgent need to address vulnerabilities in the nation’s communications networks.

The Salt Typhoon hack has raised alarm over the scale and impact of Chinese cyberattacks on U.S. telecommunications. Both companies and government agencies face mounting pressure to assure the public about the security of the nation’s critical communication infrastructure.