Skip to content

Incidents attributed to:

UNC5537 (Mandiant designation)

Related incidents

Credential stuffingRansom paid

AT&T Snowflake call-records breach

AT&T disclosed that attackers used credentials stolen by infostealers to authenticate into its Snowflake cloud-data-warehouse tenant — which lacked MFA — and exfiltrated call and text metadata covering nearly all 110 million AT&T wireless customers.

Victim
AT&T Communications
Loss
$200.0M
Records
110.0M