U.S. Soldier Sentenced for Stealing Call Metadata of 100 M AT&T Customers and Extorting Telecoms
What Happened – A 22‑year‑old U.S. Army soldier, operating under the alias “Kiberphant0m,” hacked into multiple telecom carriers and a cloud data‑storage service, exfiltrating call‑and‑text metadata for more than 100 million AT&T customers. He then extorted AT&T, Verizon and others, demanding payment to keep the data private. The soldier received a 70‑month federal prison sentence and was ordered to pay nearly $300 K in restitution.
Why It Matters for Trust & Control Assurance
- Highlights the risk of weak credential hygiene and the absence of mandatory multi‑factor authentication (MFA) on privileged accounts.
- Demonstrates why continuous monitoring of access controls and credential usage is a core control‑assurance requirement.
- Shows that a robust identity‑access program provides defensible evidence for auditors and regulators when a breach occurs.
Who Is Affected – Telecommunications carriers, cloud service providers handling telecom data, and any organization that stores or processes large volumes of call metadata.
Recommended Actions
- Enforce MFA on all privileged and service accounts, especially for cloud platforms and telecom back‑ends.
- Deploy continuous credential‑monitoring tools that flag anomalous logins, reused passwords, or exposed secrets.
- Conduct a third‑party risk review of cloud providers that host telecom data, documenting MFA enforcement as part of the audit trail.
Technical Notes – The attacker leveraged exposed Snowflake credentials that lacked MFA, then used those accounts to download telecom metadata. No specific CVE is cited; the vector was credential theft and misuse of cloud‑service access. Source: Krebs on Security