Home › Intelligence › Brief
BREACH BRIEF 🟠 High Breach

U.S. Soldier Sentenced for Stealing Call Metadata of 100 M AT&T Customers and Extorting Telecoms

A U.S. Army soldier hacked into AT&T, Verizon and a cloud provider, stealing metadata for over 100 million customers and extorting the companies. The case underscores the need for enforceable MFA and continuous access‑control monitoring to satisfy audit and trust requirements.

Verisq™ Intelligence · 📅 September 26, 2026 · 📰 krebsonsecurity.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
krebsonsecurity.com

U.S. Soldier Sentenced for Stealing Call Metadata of 100 M AT&T Customers and Extorting Telecoms

What Happened – A 22‑year‑old U.S. Army soldier, operating under the alias “Kiberphant0m,” hacked into multiple telecom carriers and a cloud data‑storage service, exfiltrating call‑and‑text metadata for more than 100 million AT&T customers. He then extorted AT&T, Verizon and others, demanding payment to keep the data private. The soldier received a 70‑month federal prison sentence and was ordered to pay nearly $300 K in restitution.

Why It Matters for Trust & Control Assurance

  • Highlights the risk of weak credential hygiene and the absence of mandatory multi‑factor authentication (MFA) on privileged accounts.
  • Demonstrates why continuous monitoring of access controls and credential usage is a core control‑assurance requirement.
  • Shows that a robust identity‑access program provides defensible evidence for auditors and regulators when a breach occurs.

Who Is Affected – Telecommunications carriers, cloud service providers handling telecom data, and any organization that stores or processes large volumes of call metadata.

Recommended Actions

  • Enforce MFA on all privileged and service accounts, especially for cloud platforms and telecom back‑ends.
  • Deploy continuous credential‑monitoring tools that flag anomalous logins, reused passwords, or exposed secrets.
  • Conduct a third‑party risk review of cloud providers that host telecom data, documenting MFA enforcement as part of the audit trail.

Technical Notes – The attacker leveraged exposed Snowflake credentials that lacked MFA, then used those accounts to download telecom metadata. No specific CVE is cited; the vector was credential theft and misuse of cloud‑service access. Source: Krebs on Security

📰 Original Source
https://krebsonsecurity.com/2026/09/u-s-soldier-gets-70-months-in-prison-for-att-verizon-extortions/ ↗

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →