AT&T’s Snowflake Ransom Payment: The $370K Precedent
On July 31, 2024, AT&T confirmed its customer data — including call and text metadata of nearly all subscribers and some SSNs — had been stolen off Snowflake's cloud via compromised service-account credentials, and that it had paid roughly $370,000 to the SQlMap-scanning crew known as ShinyHunters to delete it. This account reconstructs the credential theft, the infostealer-to-Snowflake kill chain, the economics of a mid-six-figure ransom, and the quarterly-burial of accountability between carrier, and its data-warehouse vendor.
