AT&T Fined $13 Million for Supply Chain Data Breach

Share post:

AT&T has agreed to pay a $13 million fine following a significant data breach that exposed information of 8.9 million wireless customers. This incident highlights the growing risks of supply chain attacks and the importance of robust data management practices, especially when working with third-party vendors.

AT&T shared customer bill information with a vendor to create personalized videos between 2015 and 2017.  The data was supposed to be destroyed by 2018, but remained in the vendor’s cloud environment for years. In January 2023, threat actors accessed the vendor’s cloud, exfiltrating AT&T customer information.

The FCC criticized AT&T for failing to ensure the vendor adequately protected the data and properly destroyed it when no longer needed.  

This breach underscores the vulnerabilities in the supply chain, where a company’s data security is only as strong as its weakest vendor.

As part of the settlement, AT&T must implement stricter controls on sharing data with vendors, including improved due diligence, enhanced vendor oversight, and annual compliance audits.

This case serves as a warning to other companies about the importance of managing data throughout its lifecycle, even when in the hands of third-party vendors.

This incident demonstrates how supply chain vulnerabilities can lead to significant data breaches, affecting millions of customers. It emphasizes the need for companies to take a more proactive approach in managing data security across their entire ecosystem of partners and vendors.

SUBSCRIBE NOW

Related articles

Operation Endgame: Burnaby, BC Resident Arrested As Cops Go After Individual Hackers

As part of Operation Endgame, international law enforcement agencies have arrested a Burnaby, British Columbia resident accused of...

US Bank Regulator Hacked – Sensitive Banking Info Stolen

The US Office of the Comptroller of the Currency (OCC) reported a cybersecurity breach involving unauthorized access to...

OpenAI Revokes Spammers Account After 80,000 Messages Evade Detection

Spammers have exploited OpenAI's GPT language model to send over 80,000 unsolicited messages that bypassed spam filters, according...

Cloudflare Launches Open Source Tool for Secure, Keyless SSH Authentication

Cloudflare has released an open-source tool called OPKSSH (OpenPubkey SSH), which allows developers and IT teams to use...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways