What happened?
In July 2024, court filings and confirming reporting revealed that AT&T had paid roughly $370,000 to a hacking crew — part of the UNC5537 cluster behind the Snowflake credential-theft campaign — to delete call and text records for nearly all of its wireless subscribers, and to pledge a pause on further leaks. The payment, made in cryptocurrency during May and June as the data hung on a criminal market, resolved the extortion but set a precedent question the industry had dodged for years: when a Fortune 50 pays an extortionist for deletion of stolen data, what exactly has it bought? By 31 July, when this post publishes, the number was public, the crew was indicted, and the debate over ransom economics had a new, expensive data point.
Quick Answer: After infostealer-harvested credentials granted access to AT&T’s Snowflake workspace (via a third-party subcontractor’s account lacking MFA), attackers copied call-detail and metadata records covering roughly 109 million customer lines — numbers, call counts, durations, cell-site identifiers. One defendant, in a Canadian court filing, admitted paying about $370,000 in crypto for the crew’s silence; AT&T’s role as payer was later confirmed by the Wall Street Journal. The episode closed the largest data-theft chapter of the Snowflake extortion wave with cash-for-deletion — the quiet, rarely-acknowledged cousin of ransomware payment.
The dataset’s sensitivity explained the price. It was not message content — it was the metadata mesh: who called whom, when, from which approximate location, in aggregate covering most AT&T wireless users over a six-month window in 2024 (plus some older records). For divorce lawyers, private investigators, stalkers and foreign intelligence services alike, CDR mass is a surveillance gift; for the carrier, disclosing it triggered SEC-filed breach notifications and class-action exposure. The crew monetized that fear precisely — not by selling data broadly, but by auctioning the exclusivity of its non-release.
The Snowflake connection: one campaign, many payers
AT&T was the biggest name in UNC5537’s victim list, but the mechanics were identical across the campaign — and they repeated the year’s identity lessons. Credentials for the Snowflake tenant came not from AT&T directly but from a third party’s compromised environment; no Snowflake platform flaw was needed; MFA absence did the rest. In the indictments unsealed later in 2024, US prosecutors named crew members and their infra — initial access brokers handing infostealer logs to extortionists, data fenced on criminal forums, demands calibrated per victim’s regulatory exposure. AT&T’s payment made the campaign’s economics concrete for every board following along: identity failure had become a line item measured in six figures and regulator attention.
The paper trail
| Date | Event |
|---|---|
| 2024-04-14 | Attackers use stolen third-party credentials (no MFA) to access AT&T data on Snowflake; copy call-detail metadata for ~109M subscriber lines |
| 2024-06 → mid | Crew lists the dataset for sale at $1M on a criminal forum; AT&T incident response engages; extortion negotiation proceeds in parallel |
| 2024-05→06 | Approximately $370,000 in cryptocurrency paid for deletion and non-release; per one defendant’s filing, the crew destroys its copy |
| 2024-07-12 | AT&T files updated SEC breach letter confirming ~109M accounts affected; disclosure ricochets through press and Congress |
| 2024-07-26→31 | WSJ confirms AT&T as payer; Canadian court documents detail the scheme; this post publishes with the precedent now public |
Cash-for-deletion: the precedent problem
Encryption-for-ransom dominates headlines, but deletion-for-payment is the older and arguably larger shadow economy — and it runs on unmeasurable trust. AT&T bought a promise from criminals whose incentive structure includes resale to discreet buyers after “deletion.” Security economists were quick to note the asymmetry: nobody can audit a counterparty’s backups, so the transaction’s value rests on reputation-within-the-underworld (crews honor deletion deals to keep future victims paying). For the payer, accounting treatment is easier than a ransomware episode — no operational restoration, just a quiet transfer — which is exactly why disclosure rules and journalistic verification matter. The July filings dragged the practice into daylight, giving regulators on two continents fresh appetite for mandatory reporting of data-extortion payments.
The third-party angle: your subcontractor’s MFA is your exposure
Every major Snowflake-wave victim shared one root cause: reused or harvested credentials reaching a SaaS tenant through some non-core workforce — a contractor’s analyst, a partner’s integration account, a forgotten service identity. AT&T’s entry came via a third party, underscoring how SaaS sprawl multiplies identity surface beyond the org chart. Post-incident, enterprises moved on three fronts: enforcing phishing-resistant MFA on every data-platform seat including vendor accounts, inventorying third-party access to data warehouses as a named risk register, and contractually requiring vendors to notify customers of credential incidents touching customer tenants. None of this is novel; the wave simply tallied the bill of skipping it — and one carrier’s bill was public.
- Metadata is sensitive data: CDR-scale logs enable relationship mapping and location inference without reading a single message; treat them as tier-one PII in classification and retention.
- Infostealers are the new port scan: the campaign’s fuel was credential logs harvested from contractor endpoints; endpoint hygiene upstream determines warehouse exposure downstream.
- Deletion promises are unauditable: paying for deletion is a bet on criminal reputation, not a control; regulators treat it accordingly.
- Disclose the mechanism, not just the count: AT&T’s SEC letters and the court filings enabled real analysis; vague disclosures leave customers guessing and researchers blind.
FAQ
Did AT&T pay a ransom?
Semantics matter here: there was no ransomware — no systems were encrypted or disrupted. AT&T faced data theft with extortion. Reporting and a defendant’s own admission establish a payment of roughly $370,000 in cryptocurrency intended to secure deletion and non-release of the stolen records. Whether one calls that a ransom or a settlement with extortionists, it is a payment to criminals under threat — and it is now the flagship public example of cash-for-deletion in the SaaS era.
Whose data was in the stolen set?
Nearly all AT&T wireless subscribers of the period — about 109 million customer lines/pseudonymized identifiers covering calls and texts from roughly May through October of 2022 in the initial disclosure, with the filing later describing a broader 2024-referenced window for a subset. Contents of calls and texts were not included; the exposure is metadata: numbers contacted, interaction counts and durations, and in some cases cell-site information enabling coarse location. The company posted a dedicated explanation page and offered contact for affected customers.
Does paying for deletion actually work?
Operationally, the receiving crew can honor its side — attackers destroy local copies and forgo resale to protect the market for future deletion deals. Strategically, the buyer cannot verify any of it: copies may already have moved, brokers may retain logs, and “deletion” does not bind confederates. The consensus among incident responders is that payment occasionally achieves its narrow goal while reliably achieving one broader effect — funding and validating the extortion business model that produced the July 2024 wave in the first place.
Aftermath: indictments, ripples, and the number everyone remembers
The legal coda came fast by breach standards. US prosecutors indicted crew members including a Canadian national whose own filing accidentally exposed the payment figure; Canada arrested him; the stolen-data market listing vanished. AT&T absorbed a two-part SEC disclosure, congressional letters, and consolidation of class actions, while its security organization rolled out the expected remediations — credential rotation, third-party access review, Snowflake hardening alongside the vendor’s own new security posture. Meanwhile the figure itself became shorthand in boardrooms: “the AT&T number.” Three hundred seventy thousand dollars — roughly three cents per affected record — stuck as the visceral proof that metadata at carrier scale prices like a crown jewel, and that in 2024’s threat economy, the most valuable thing a thief can steal is not the data but the decision about what happens next.
