AT&T said Friday the company suffered a massive hacking incident as data from about 109 million customer accounts containing records of calls and texts from 2022 was illegally downloaded in April.
The US telecom company said the FBI is investigating and at least one person has been arrested after AT&T call logs were copied from its workspace on a third-party cloud platform in a significant breach of consumer communication records.
The Federal Communications Commission said it is also has an ongoing investigation.
The compromised data also includes records from Jan. 2, 2023, for a very small number of customers.
AT&T said it first learned on April 19 that a hacker had claimed to have unlawfully accessed and copied AT&T call logs. The company said its investigation found hackers had between April 14 and April 25 unlawfully exfiltrated files containing AT&T records of customer call and text interactions. The records also include AT&T customers of mobile virtual network operators using AT&T's wireless network.
Read: PAC concerned over NADRA data leak
These records identify telephone numbers with which a wireless number interacted during these periods and aggregate call duration. A subset of records includes one or more cell site identification number.
AT&T said it has closed off the point of unlawful access and will notify customers of the incident.
In March, AT&T said it was investigating a data set released on the "dark web" and said its preliminary analysis showed it impacted approximately 7.6 million current account holders and 65.4 million former account holders. The company said the data set appeared to be from 2019 or earlier.
AT&T is working with law enforcement and said it had delayed public notification based on a determination by the Justice Department. AT&T added it does not believe that the data is publicly available.