AT&T Tried To Deny This Massive Data Breach

Поділитися
Вставка
  • Опубліковано 3 кві 2024
  • In this video I discuss how a database containing the personal information of over 70 million AT&T customers was sold on the darkweb back in 2021, AT&T denied the data breach, but now the data has been released for free and AT&T is doing damage control (and also facing lawsuits)
    My merch is available at
    based.win/
    Subscribe to me on Odysee.com
    odysee.com/@AlphaNerd:8
    ₿💰💵💲Help Support the Channel by Donating Crypto💲💵💰₿
    Monero
    45F2bNHVcRzXVBsvZ5giyvKGAgm6LFhMsjUUVPTEtdgJJ5SNyxzSNUmFSBR5qCCWLpjiUjYMkmZoX9b3cChNjvxR7kvh436
    Bitcoin
    3MMKHXPQrGHEsmdHaAGD59FWhKFGeUsAxV
    Ethereum
    0xeA4DA3F9BAb091Eb86921CA6E41712438f4E5079
    Litecoin
    MBfrxLJMuw26hbVi2MjCVDFkkExz8rYvUF
  • Наука та технологія

КОМЕНТАРІ • 553

  • @w4439
    @w4439 Місяць тому +1204

    70m?! Theres only 350m mfs out here 😱.
    These telecom companies must be broken up as a matter of national security

    • @r.a.6382
      @r.a.6382 Місяць тому

      Agree. I worked in telecom for years. Their corrupt unions collect tax payer money and sit on their ass all day long. They try to hire illegals and only pay them based on customer reviews (for the cable companies). Literally like 20$ for a service call on your own dime (must have truck and tools lmao). Cell tower contractors are all fly by nights that don't pay their employees because they bankrupt out and run and are staffed full of meth heads. I would love nothing more than to return to my passion and make an honest wage and help people gtfo from under their monopoly.

    • @Vifnis
      @Vifnis Місяць тому

      Bro that already happened already, like several times already.... in fact anti-trust prevented AT&T from merging with T-mobile... ever heard of Bell labs? Well yea of course not if you are younger than 20 years old bcuz they were broken up a long time ago but they made EVERYTHING under the sun in telecommunications...

    • @bingobongo6258
      @bingobongo6258 Місяць тому +40

      There’s upwards of 8 billion people on the planet and AT&T has 222 million customers. What are you talking about

    • @tamagodonald7149
      @tamagodonald7149 Місяць тому +259

      ​​​@@bingobongo6258he means in the US, AT&T only operates in USA due to way signals in phones are transmitted in USA that specifically can't make all phones be used inside of USA that's why there are us and NON-us phones it's complicated but it's something like that if i remember, most evident i Samsung's lineup snapdragon for US, exynos for global it's similar to imperial system and metric system difference you could sau

    • @bingobongo6258
      @bingobongo6258 Місяць тому

      @@tamagodonald7149 Thanks that makes more sense. I was misconstruing some stats I was looking at.

  • @Rensbril
    @Rensbril Місяць тому +230

    If they were located in the EU they would've been f'ed. Here companies MUST report any data breach within 24 hours after finding out or receive a massive fine.

    • @maciej.opalinski
      @maciej.opalinski Місяць тому +10

      And they still receive a fine for bad security measures that lead to the leak

    • @inLoopie
      @inLoopie Місяць тому +15

      America, the land of the free from consequences

    • @Dracula.25
      @Dracula.25 Місяць тому +1

      Yeeehhaaaaahhhh​@@inLoopie

    • @Shajirr_
      @Shajirr_ 25 днів тому

      @@inLoopie yep, that seems to be the case. Every time some incident happens caused by a major company, it either gets away entirely or gets some joke fine equal to their 1 hour revenue or something

  • @bilboswaggings
    @bilboswaggings Місяць тому +525

    Human makes a mistake and gets locked up for years
    Businesses knowingly committing actions that result in them getting fined should get bigger penalties including being forced to stop business

    • @fastshuther
      @fastshuther Місяць тому +13

      I wouldn't say stop the business its a American source so it's better to forcefully change the ceo

    • @bilboswaggings
      @bilboswaggings Місяць тому +6

      @@fastshuther obviously there would be different levels depending on the severity and how many times they have been fined

    • @habibikebabtheiii2037
      @habibikebabtheiii2037 Місяць тому +36

      The Pentagon and at&t are in bed together

    • @fastshuther
      @fastshuther Місяць тому +12

      @@bilboswaggings this is pretty severe I wouldn’t shut down the company over it though, just forcefully change the CEO

    • @mistersir3020
      @mistersir3020 Місяць тому +7

      In a normally functioning world, employees who are in the know of this kind of amateurism ought to be jointly and severally liable if they do not report this kind of shit to some authority.
      Alas that's never going to happen because the people who would make or lobby for such laws are themselves some of the biggest incompetent fools.

  • @kcsguitar
    @kcsguitar Місяць тому +618

    The fact that these companies are not held accountable for their shitty security practices infuriates me. Sue and fine the ever loving crap out of them. ReeEEeeeEee

    • @gatonegro187
      @gatonegro187 Місяць тому

      all this is totally legal they passed legislation letting them off the hook for spying on and collecting data a decade ago at least

    • @shapelessed
      @shapelessed Місяць тому +21

      I worked for a company that shall not be named, that provided a remote desktop service, that effectively just made it so you didn't have to forward ports and remember your IPs.
      I found 3 0-click RCE exploits in their packages within the first WEEK.

    • @Top_Weeb
      @Top_Weeb Місяць тому +6

      This is what happens when a country legalizes bribery.

    • @sugarpuddin
      @sugarpuddin Місяць тому

      These illegal monopolies are protected by politicians on the take.
      The consumers are screwed and voting changes nothing

    • @umxltiii9796
      @umxltiii9796 Місяць тому

      I go to a small school they had 150,000 ssns and info stolen during a data breach cause they didn’t apply iot security the way they should have here’s the catch they haven’t cleared there database since the 70’s people who attendees in 1971 have there info stolen as well as current students smh they gave us one of them credit watching accounts for scams for 6 months smh

  • @joshuamurphy75
    @joshuamurphy75 Місяць тому +794

    And most customers can’t do anything about it because they are stuck dealing with a monopoly for their area.

    • @r.a.6382
      @r.a.6382 Місяць тому

      The government causes this. Look at Helium mobile. The cost of setting up a network is the cheapest its ever been - the government/fcc create the monopoly we have now. Has been since ma bell and if you stand against it you go to jail for made up fraud charges (qwest).

    • @Dratchev241
      @Dratchev241 Місяць тому +47

      and that right there has been the problem all along.

    • @ast12321
      @ast12321 Місяць тому

      I haven't used AT&T in literally 10 years but I showed up in haveibeenpwned. its wild lol.

    • @justaadhdgamerwesley6244
      @justaadhdgamerwesley6244 Місяць тому +18

      In nc its 78% and they have the fastest speed in my area.

    • @MrBurns-lx3dx
      @MrBurns-lx3dx Місяць тому +3

      Yep. Was my only option at one of my past addresses. Either that or starlink which was only available for preorder. Only coverage I got with mobile back then too that wouldn’t drop out at work.

  • @m1k0h
    @m1k0h Місяць тому +317

    I'm an AT&T customer. They still haven't sent me shit to notify me. I first heard about it last Sunday from my girlfriend of all people, who isn't even into tech or anything like this.

    • @gatonegro187
      @gatonegro187 Місяць тому +28

      weird flex but ok

    • @thebearisradd
      @thebearisradd Місяць тому

      I Don’t Believe That’s a "Flex"… He’s Just Making a Simple Statement. Just because He Mentioned a Significant Other (Which You Likely Don’t Have) Doesn’t Mean Anything.
      Why Even Make Stupid Ass Replies/Comments Such as Yours?

    • @Omega-mr1jg
      @Omega-mr1jg Місяць тому +51

      @@gatonegro187 flex? whos flexing?

    • @Fatih120
      @Fatih120 Місяць тому +81

      @@Omega-mr1jg man thinks women is a flex 🤯

    • @yunggoosbumps215
      @yunggoosbumps215 Місяць тому +1

      @@gatonegro187Yeah, this piece of shit OP flexing that he has a girlfriend 😤

  • @valcaron
    @valcaron Місяць тому +211

    Considering how lovey-dovey AT&T is with the NSA, you'd think they'd have osmosed some of that security knowledge from their BFF.

    • @hanelyp1
      @hanelyp1 Місяць тому +14

      Conflicting nsa mandates. Help friendlies avoid cyber compromises, while comitting them on others, with the help to friendlies in the wild.

    • @highbread817
      @highbread817 Місяць тому +14

      Meh the only "security" the NSA does is offensive

    • @First-lx9hs
      @First-lx9hs Місяць тому +5

      They did, that’s the problem. 😂

    • @MrYehaha
      @MrYehaha 27 днів тому

      NSA wouldn’t tell you if they have a breach.. but most likely it’s because cyber security is a cat and mouse race, there will never be a winner and the only time you know about it is when the “good guy” loses.

  • @williammartin500
    @williammartin500 Місяць тому +177

    Ah yes, deny it ever happened so you don't lose millions in a law suit and millions more when customers dump you for being negligent with data, very smart of them.

    • @taureon_
      @taureon_ Місяць тому +14

      they cant switch lol
      local monopolies

    • @poorly_dressd
      @poorly_dressd Місяць тому +2

      @@taureon_well luckily i can, so i’m leaving them

    • @williammartin500
      @williammartin500 Місяць тому

      @taureon_ you can "switch" ..... just to another company owned by them lmao.

  • @undertheweather246
    @undertheweather246 Місяць тому +228

    A couple years ago, I got at&t internet at my apartment and like 10 minutes later I get a scam call from some company that had almost all my information and were trying to sell me some home security garbage. Called at&t back and they had no idea how anyone would have that information.

    • @MushookieMan
      @MushookieMan Місяць тому

      It's because they sell it immediately. Ally Bank sells your data. The USPS sells your data. The DMV sells your data. Because we live in a corporate kleptocracy where nothing is illegal if number go up

    • @mistersir3020
      @mistersir3020 Місяць тому +12

      lol if true

    • @qmac9966
      @qmac9966 Місяць тому +5

      10 minutes is not that long at all...

    • @undertheweather246
      @undertheweather246 Місяць тому +6

      Completely true story. This was before I discovered this Channel and began learning about security and privacy but even then, I felt like I was getting fucked over.

    • @RoastCDuck
      @RoastCDuck Місяць тому +2

      Totally would've cancelled any relationships with AT&T right at the moment, since otherwise the broken butt of north america doesn't lets people do shit.

  • @greedtheron8362
    @greedtheron8362 Місяць тому +101

    Honestly the idea that anything serious can be put behind a 4 digit code is horrid.

    • @ICE0124
      @ICE0124 Місяць тому +16

      wait until you see how many peoples phones protect all their passwords, accounts, sim card, files, and more on their phones thats secured behind a 4 digit pin of their birth year

    • @SkylineFTW97
      @SkylineFTW97 Місяць тому +1

      ​@@ICE0124 And people think I'm nuts for using a 10 digit code on my phone that's completely separate from all my other passwords. Most people wouldn't even think to try one that long if they didn't see me punch it in.

  • @glitchy_weasel
    @glitchy_weasel Місяць тому +93

    About to get my 83 cents class action compensation 😊

    • @Thomahawk1234
      @Thomahawk1234 Місяць тому +20

      You can get a pretty big gumball with that. Something to chew on.

    • @Will-uv9kx
      @Will-uv9kx 28 днів тому +2

      ​Don't chew on it while configuring any large databases though...

    • @Molon_Labe1776
      @Molon_Labe1776 24 дні тому +1

      Don't worry, the lawyer will get millions!

  • @Nick-zp8wk
    @Nick-zp8wk Місяць тому +53

    Watch AT&T put a forced arbitration clause into their TOS so they can't get sued any more.

    • @hanelyp1
      @hanelyp1 Місяць тому +3

      The terms when the breech took place =should= apply.

    • @InternetKilledTV21
      @InternetKilledTV21 Місяць тому +1

      Eh, a lot of garbage thrown into TOS is being scrutinized and sometimes ignored. Won't surprise me when someone successfully sues despite a forced arbitration clause soon.

    • @K_Z_R
      @K_Z_R 25 днів тому

      ELI5 pls

    • @InternetKilledTV21
      @InternetKilledTV21 25 днів тому +1

      @@K_Z_R A lot of the "We've updated our terms of service" emails you've received from services (other than EU updates) have been increasingly for the purpose of adding a forced arbitration clause. If you agree to the new terms with this clause, you are waiving your right to sue (both named and as a member of a class action). Instead you must file a dispute directly with the party and enter a binding arbitration process. The decision made is final and you cannot appeal. At least that is what the common knowledge behind the move is. But in the US some of that very dense TOS legalese is being tossed out as its wording is too complex for ordinary consumers to fully understand, it is outright illegal what's written, the language is too restrictive/burdensome on the consumer as it relates to what the service can actually require, and many other reasons

  • @chubbycatfish4573
    @chubbycatfish4573 Місяць тому +103

    ATT should be fined 25k for each person compromised.

    • @river559
      @river559 Місяць тому +7

      Should be per personal identifying information per person in a perfect world

    • @Mitch-xo1rd
      @Mitch-xo1rd Місяць тому +49

      My dude, this is class action case, you will be lucky to get $25. The lawyers on the other hand will get 25M

    • @harrychufan
      @harrychufan Місяць тому +11

      Ah yes, 1.75 trillion dollar payout. AT&T as an entire company is worth 126 billion and has only 7.5 billion in cash, I’m sure $25,000 per person will work out.

    • @yunggoosbumps215
      @yunggoosbumps215 Місяць тому +7

      @@Mitch-xo1rdYup. Apple lawsuit led to rewarding its victims with enough money to buy 5 months of apple music subscriptions. 😂

    • @MrNexor-cj8gs
      @MrNexor-cj8gs Місяць тому +21

      ​@@harrychufan He said fine, not some payout. It would bankrupt them, which is the point.

  • @klarusboy
    @klarusboy Місяць тому +66

    "no seasonin' on they password hashes" kinda got me

  • @poldek1337
    @poldek1337 Місяць тому +64

    As a att customer with this news coming out I am glad that they have decided to charge me a $99 dispatch fee because my service was down. Turns out the fiber line was loose at the pole outside my residence I called to ask about the charge and brough up the data breech and they offered me a $50 credit. These companies are next level.

  • @icankickflipok
    @icankickflipok Місяць тому +32

    Managers ignoring warnings from their software engineers about potential issues to push software into production should be negligence when the exact problem they were warned about ends up happening and causing damage to people.

  • @stage6fan475
    @stage6fan475 Місяць тому +74

    algorithm. Wasn't ATT the fools who had a massive network outage, affecting many 911 services, just this last February? Boy, they are really hitting on all cylinders!

  • @papabaddad
    @papabaddad Місяць тому +19

    I think we're past the point where we need a way to get a new SSN at the very least

  • @octonoozle
    @octonoozle Місяць тому +13

    This is why its dumb to require social security numbers for everything.

  • @meteor4716
    @meteor4716 Місяць тому +39

    -30 reputation for AT&T 😢

  • @mack4691
    @mack4691 Місяць тому +32

    CRIMINAL NEGLIGENCE

  • @MrValiant101
    @MrValiant101 Місяць тому +25

    AT&T really using a cheeto to hold their door lock.

  • @steve7814
    @steve7814 Місяць тому +20

    All data collected by companies and institutions should be shared with the individual it is about. This is a good starting point.

    • @Thomahawk1234
      @Thomahawk1234 Місяць тому +2

      You know they'll just mix it up

  • @DrakeDealer
    @DrakeDealer Місяць тому +7

    If executives ever took responsibility for anything like this they would be in prison instead of meaningless words.

  • @jalight27
    @jalight27 Місяць тому +18

    Just fyi, even of you had AT&T at one point you should look into seeing if your info was stolen. I haven't had AT&T since 2014 and my info was in the dump.

  • @XoloitzcuintIi
    @XoloitzcuintIi Місяць тому +29

    $100 Billion dollar company btw.

    • @shenxi
      @shenxi Місяць тому +1

      Yeah, we know.

  • @zachonthego6318
    @zachonthego6318 Місяць тому +11

    Dude I called AT&T and said “Hi, uh, what are you doing about this, can I get some identity theft prevention service or anything?”
    Them: “did AT&T ask you to change your password? If not your data should be safe”
    Me: “Great, can I have that in writing on AT&T letterhead? That would be hilarious”
    They won’t do shit and I’m probably fucked

  • @SudoTragic
    @SudoTragic Місяць тому +134

    Breach Forums is def a glowie honey pot

    • @ozziedevamp
      @ozziedevamp Місяць тому +3

      why u say that?

    • @SudoTragic
      @SudoTragic Місяць тому +40

      @@ozziedevamp just stating the obvious

    • @LukSter18998
      @LukSter18998 Місяць тому

      on (pootube)

    • @viceroybolt3518
      @viceroybolt3518 Місяць тому

      @@ozziedevamp It's been more than a year before the site owner got a very secure apartment, orange jumpsuit makeover, and free set of steel bracelets from the government, but his site's still up? Now it's harder to set up an account, I'm gonna guess most likely there's some java based captcha in place to easily pierce TOR too like they did when they took out the opva sickos, I know I wouldn't touch that place even if I was behind ten proxies because I value my freedom.

    • @zanebartlett8004
      @zanebartlett8004 Місяць тому +34

      @@SudoTragic Lmao if someone asks "why u say that?" and they don't sound sarcastic, I feel like they don't know what the obvious is, and that's literally what they're asking about. I'm not too deep in these dark net forums, so I couldn't tell you why it's obvious either. Your reply literally made me blow air through my nose harder than usual because it was so unhelpful

  • @user-nk2re7ms7d
    @user-nk2re7ms7d Місяць тому +61

    It’s too bad we don’t have free and open source cellular services

    • @aynonymos
      @aynonymos Місяць тому +33

      That would require free and open source infrastructure, open source is one thing, but free isn't happening.

    • @zanebartlett8004
      @zanebartlett8004 Місяць тому

      @@aynonymos I mean, free could happen if the government wasn't a bunch of cucks that let the internet providers fuck them. In American we paid 400 billion for fiber already, I don't know what the situation is with cell towers, but I feel like it could be "free". It could be, more technically put, at cost. Which is essentially free at the costs it would be at that scale. Don't normalize corporation fuckery.
      Another argument is why besides where we need to, why are we still using sms and normal voice calling. Internet based messaging (Signal, whatsapp, etc) is already good enough, and wifi calling and stuff seems just fine. We could absolutely either nationalize or make internet a utility like service and make it essentially free. At cost, at scale, essentially free.

    • @river559
      @river559 Місяць тому +5

      @MainiaHause Sure they could still be breached since no system is perfect, but assuming having no support or legal team just because it's open source is kinda wild

    • @user-nk2re7ms7d
      @user-nk2re7ms7d Місяць тому +7

      @@aynonymos Free as in freedom to control your own data, or better yet, have little data attached at all. I’m not gonna pretend I understand how cell services work, but I’m willing to bet it would be possible to implement without requiring the plethora of information given e.g. email, birthday, etc. If we were able to largely decentralize and anonymize money away from banks, I’d imagine it would be possible to do with phone services.

    • @joshuamurphy75
      @joshuamurphy75 Місяць тому

      @@user-nk2re7ms7dthe protocols to make most of the Internet work are open standards and you can peer with any other ISPs at one of their central offices or at an IPX. I think the biggest obstacles are that location tracking is required so the network knows what cell tower to use when talking to your device, and that all the telco vendors add back doors for CALEA. I would not be surprised if some agency would show up with a warrant asking to leave some sort of trackers on your network when they found out that you built a free open source one.

  • @nevokrien95
    @nevokrien95 Місяць тому +11

    4 unsalted digits you can just run all the hashes and it takes a few minutes...

  • @Z29vZ2xlc3Vja3Mu
    @Z29vZ2xlc3Vja3Mu Місяць тому +14

    I'm an AT&T customer, but I used to be a TMobile customer so I'm used to it

    • @nojuanatall3281
      @nojuanatall3281 Місяць тому

      Cricket is the best IMO. Funny as that is.

  • @zyxwvutsrqponmlkh
    @zyxwvutsrqponmlkh Місяць тому +21

    4 digit numeric code? What a joke. That won't take a full rainbow table, more like a rainbow plate.

    • @mistersir3020
      @mistersir3020 Місяць тому +2

      idk how this goes in the US, but where I live, debit cards only have a 4 digit security code (PIN) (which through online banking you can use for transactions of up to 4 figure amounts).
      I never understood how this can be secure? How is the most important account you have (your bank account) secured by a 4 digit (0-9) PIN, while my password on some random website that I wouldn't even care if it got breached, requires minimum 8 characters, 1 capital letter, 1 number, 1 special character ???

    • @destructoidepic2685
      @destructoidepic2685 Місяць тому

      ​​@@mistersir3020because in most cases you require far more than a pin code to access someone's card. If your actual card details are out their they don't even need the pin. The pin is just the last step in ensuring someone picking up your card can't just use it. But nowadays contactless exists and hardly has any limits anyway so pins are also in effect useless
      In contrast, a password on a website for example is the only (other than 2fa) thing required to get into anyone's account, and a 4 digit numerical password takes milliseconds to randomly guess, which is why you can't just enter passwords over and over again, but when you have the hash you can "guess" as many times as you want

    • @Knirin
      @Knirin Місяць тому +4

      @@mistersir3020 Realtime lockouts. The card is locked after 4 to 6 wrong attempts.

    • @zyxwvutsrqponmlkh
      @zyxwvutsrqponmlkh Місяць тому +2

      @@Knirin There are only 9,999 possible variations and 70 million customers these were not properly salted so if you link up one you can identify everyone else with that same pin. You social engineer the pin out of one person and you now know the pin of ~7000 other people that also picked the same pin. This security is a joke.

    • @Knirin
      @Knirin Місяць тому

      @@zyxwvutsrqponmlkh I was talking about debit card PINs. You still need the debit card to perform the attack so the PIN by itself is almost worthless. The card by itself is actually far more useful. Using a 6 or 8 digit PIN would be nice but isn't required for what debit card PINs are designed to defend against. Replacing the PIN with any form of MFA is generally going to result in worse security and more customer headaches. Adding transaction notifications over a secondary channel would definitely improve security but you can't replace PINs with that mechanism.
      Back to the ATT&T account PIN. What is salting designed to do? Originally it was to prevent simple offline attacks on one password from compromising other accounts because of reused passwords. Now it is to prevent you from using a rainbow table to "instantly" know all of the passwords in the password database. It doesn't help you if the password database also includes all of the required information for a password reset. Password salting is especially useless if there isn't any rate limiting on the password reset mechanism itself.
      Unfortunately the account PIN is the least useful information that got leaked. Would it be nice if the account PINs were longer? Yes. Would it stop data breaches? No. What would salting the account PIN do right now? Cost ATT&T and the customers more money without stopping the underlying data theft problem.
      You talked about social engineering the PIN out of one person. Without access to the database how do you know who else uses that PIN? You don't. If you had the leaked database you don't need the PIN to damage someones ATT&T account even if it was properly salted, because you know enough to reset the PIN. Also you aren't widely attacking ATT&T accounts because that makes a lot of noise at ATT&T. You go commit fraud elsewhere with the information you learned in the data leak.
      Properly salting the PINs is the last action ATT&T needs to make, not the first.

  • @MakeAstand5
    @MakeAstand5 Місяць тому +6

    Remember this. These corporations have more money than governments. And somewhat more Powerful.

  • @EricGranata
    @EricGranata Місяць тому +9

    If it were one of our businesses disclosing like this, we’d be toast.

  • @40arpent
    @40arpent Місяць тому +16

    confirmed my info was on there. I was a long time wireless and wired customer until this year. I have not received any communication from them except the refund from my cancellation.

    • @abakedpotato1486
      @abakedpotato1486 Місяць тому +4

      How did you confirm?

    • @40arpent
      @40arpent Місяць тому

      @@abakedpotato1486 Google one dark web monitoring. Have I been pwned has the email dataset too. I checked LastPass and it did not have the dataset. Capital one was the original one to alert me the other night but just mentioned my email address.

    • @tinafatbottom8069
      @tinafatbottom8069 Місяць тому

      norton contacted me not att bums

  • @DT-dc4br
    @DT-dc4br Місяць тому +16

    Y'all need GDPR. Mandatory reporting of data breaches, fines for each occurrence. Obligations for companies to protect their data.Edit: protect *your* data.

    • @dirtcache6128
      @dirtcache6128 Місяць тому +1

      We have laws for this they just aren’t properly enforced

    • @VRTIXE
      @VRTIXE Місяць тому +2

      ​@@dirtcache6128 so basically you dont have laws for it then

    • @ShadowOfTheSPQR
      @ShadowOfTheSPQR 28 днів тому

      @@VRTIXE We have defunded government agencies that don't have the teeth to enforce what little weak laws do exist.

  • @DaRealWuXiit
    @DaRealWuXiit Місяць тому +4

    When your maximum is 9999, I remember a graph from a lecture that over 85% of people's PINs are below 5000.

  • @scottwheaton6610
    @scottwheaton6610 Місяць тому +3

    "Maybe if we close our eyes, it will go away.."
    -AT&T

  • @InfoRanker
    @InfoRanker Місяць тому +4

    I just got an alert from Lifelock and they said that I was one of the people who's data was leaked. Including name, email and SSN. No idea how they got the SSN, I don't typically give that out to anyone, certainly not something like AT&T.

  • @bradley144
    @bradley144 Місяць тому +8

    Explains all the scams I've been getting recently with my PII told to me. Shame that I wasn't notified!!

  • @souta95
    @souta95 Місяць тому +4

    (former) ATT customer here... No notification from them at all.

  • @zaper2904
    @zaper2904 Місяць тому +7

    Four numbers is not enough entropy no matter what kind of encryption you use.

  • @themiddleman5357
    @themiddleman5357 Місяць тому +4

    Most banks don’t allow you to use a special character. Yikes

  • @Iog
    @Iog Місяць тому +11

    AT&T needs correction 💢

    • @freakyjim2131
      @freakyjim2131 Місяць тому +3

      Damn bratty telecom companies…. Releasing personal information…

  • @AmonGus-hw6sp
    @AmonGus-hw6sp Місяць тому +32

    and they're slow

  • @91thewatcher23
    @91thewatcher23 Місяць тому +3

    Key point, if you WERE an att customer in the last decade, you should probably be on guard too. Not just if you ARE an att customer currently.

  • @gfxv5893
    @gfxv5893 Місяць тому +13

    im not just cooked im boiled

  • @n.g.l.
    @n.g.l. Місяць тому +59

    Ain’t this the same company that said that it’s reading your text messages to fine you for not being politically correct?

    • @Octaviu5
      @Octaviu5 Місяць тому +19

      Unbelievable, they deserve to go under just for that.

    • @commonsense5555
      @commonsense5555 Місяць тому +13

      I’d absolutely sue them if they tried to fine me and I’d publicize it as much as possible to do the most damage possible to the company!

    • @R3TR0R4V3
      @R3TR0R4V3 Місяць тому +2

      Nah, or else I would been canceled ages ago. 😅

    • @viceroybolt3518
      @viceroybolt3518 Місяць тому

      Less "fine you for not being PC" more "rat on you to the FBI for organizing a terror cell"
      On text, like in email, don't write anything you wouldn't be fine with having read back to you in a court of law with your name on it.

    • @EricGranata
      @EricGranata Місяць тому +1

      Say what now?

  • @Skilital
    @Skilital Місяць тому +38

    This is informative and unfortunate.

    • @nuhuh144
      @nuhuh144 Місяць тому +6

      louis reference

  • @Epic_C
    @Epic_C Місяць тому +3

    This reminds me of the bad security of the Sony Playstation data breach from like 15 years ago. I guess they never learned from the bad database security from 15 years ago!

  • @galaxia_fe
    @galaxia_fe Місяць тому +1

    I was already contacted by scammers calling me saying that I had placed an order on ATT for 2 iPhone 15’s and that they’re being delivered to an address that wasn’t matching their records. I obviously knew it wasn’t ATT, but I played along to figure out their plan. It’s just a simple get info type of scam. Either way I’m pissed because they shouldn’t have any of my info. Definitely not going to remain a customer after this.

  • @heretichazel
    @heretichazel Місяць тому +2

    I use at&t and this is my first time hearing about this

  • @joegru7280
    @joegru7280 Місяць тому +4

    thank you for this video. as an att user i feel fucked

  • @l-l
    @l-l Місяць тому +3

    No notification from AT&T. How can they get away with not notifying affected customers

  • @darkguardian1314
    @darkguardian1314 Місяць тому +14

    Four pin digits are useless.
    I would have to change them weekly at a minimum.

  • @seniorchonkza997
    @seniorchonkza997 Місяць тому +6

    My email came up in the public leak but I don't recall ever being an at&t customer so idk if I should be concerned

  • @mdog6726
    @mdog6726 Місяць тому +2

    The only thing worse than this is their customer service.

  • @acidlaek
    @acidlaek Місяць тому +1

    Yeah a month after this breach I was a victim of id theft. It was really nefarious. They used my ssn to buy phones hoping I wouldn’t notice until it hit collections. No they haven’t said anything.

  • @staplesinc.9111
    @staplesinc.9111 Місяць тому +14

    My service is under AT&T towers bruh

    • @HarambeeOffical
      @HarambeeOffical Місяць тому +3

      Same :(

    • @787310
      @787310 Місяць тому +17

      brb bout to post yalls social security numbers

  • @sobertillnoon
    @sobertillnoon Місяць тому +2

    As an att customer this is the first im hearing of this. This makes sense why my account got a little weird last year.

  • @ianbelletti6241
    @ianbelletti6241 Місяць тому +1

    The one thing that I think of whenever I see stories like this is that it's better to eat crow when it's young and tender. Many companies for legal liability reasons forget this simple tact of life. Now, AT&T is going to owe more than if they headed it off early. Even if they thought it was possibly fake it's much better to inform customers early that they are investigating a possible data breach in order to make as much of the data leak as useless as possible.

  • @cariyaputta
    @cariyaputta Місяць тому +1

    Authority and monopoly go hand in hand. Nothing can be done about it.

  • @lookinaturmom
    @lookinaturmom Місяць тому +3

    I should’ve been born a company.

  • @FyingfoxGaming
    @FyingfoxGaming 22 дні тому

    I always hated AT&T but hearing about how they tried to deny their data breach confirms it how embarrassing their company is.

  • @ZeldagigafanMatthew
    @ZeldagigafanMatthew 27 днів тому +1

    they sat on this information for three years??? The punishment must be severe, judicial dissolution must be on the table.

  • @mskiptr
    @mskiptr Місяць тому +6

    Wouldn't brute-forcing 4 digit passcodes be super easy even if they were salted? Sure you can't create rainbow tables, but 10000 possibilities is still not that much. Especially if you want to target individual people and not just crack everything there is

    • @Knirin
      @Knirin Місяць тому

      The salt is generally the same length as the digest size of the hash. 160 bits in the case of sha1.

  • @pinstripecool34
    @pinstripecool34 22 дні тому

    3 YEARS?!? Jesus. Thats very concerning.

  • @mistersir3020
    @mistersir3020 Місяць тому +3

    ultra lol
    How is this not going to be on the news for 30 days and how are the whole IT team at AT&T not going to be fired and criminally charged?? 😂

  • @PanicOregon
    @PanicOregon Місяць тому +8

    Well... -_- this is the first i'm hearing of this, as an ATT customer.
    Now i'm gonna have to get this Fucking database and see if i'm stuff is in it

    • @MentalOutlaw
      @MentalOutlaw  Місяць тому +10

      It's 5GB compressed. Better download before bed

    • @thejhonnie
      @thejhonnie Місяць тому

      ​@@MentalOutlawwhere is it hosted?

    • @mjtoranneto4934
      @mjtoranneto4934 Місяць тому

      it's in haveibeenphoned, if you know your AT&T email

    • @BlooD3vour3r
      @BlooD3vour3r Місяць тому

      Internet's bottom of the barrel is the place.​@@thejhonnie

  • @Mr.Riojas
    @Mr.Riojas Місяць тому +2

    ... wishing AT&T was still broken up. Way too many eggs in one basket.

  • @OVERKILL_PINBALL
    @OVERKILL_PINBALL Місяць тому +3

    Why on earth did anyone give a phone company their SS# in the first place?

    • @poorly_dressd
      @poorly_dressd Місяць тому

      they literally have to in order to get the cell service. it’s dumb as hell

    • @rizzlybear-ff1sn
      @rizzlybear-ff1sn 17 днів тому

      @@poorly_dressdyou don’t need an ssn unless you want a pp plan

  • @WholeKernelCheetoPuffs
    @WholeKernelCheetoPuffs Місяць тому +1

    Literally anything ATT has done that has affected me has affected me negatively. I’ve never had a single positive experience with ATT

  • @konstidee
    @konstidee Місяць тому +7

    Still waiting for the video that starts with 'Ohhh Boy'

  • @seinfan9
    @seinfan9 Місяць тому +1

    This is goong to be a thing for everyone eventually. This is at least the third time I got notified that a company I did business with had shit security. Yeah, I saw this and was basically thinking just another day in this stupid digital gulag.

  • @TheIcenero
    @TheIcenero Місяць тому +1

    I use AT&T and I’ve received not a single email notifying me of any of this. Had you not reported on this I’d have no idea. I thought there was a strange crazy uptick in scam calls

  • @dillanteagle3726
    @dillanteagle3726 Місяць тому

    I agree with this. I saw a lot of signs of man in the middle attacks right before the outages

  • @ProfessionalBoxer
    @ProfessionalBoxer Місяць тому +1

    smartest telecom company

  • @tristen_grant
    @tristen_grant Місяць тому +1

    If they can, everyone should cancel their AT&T accounts.

  • @AzureUnlinked
    @AzureUnlinked Місяць тому +11

    How the hell do you even suck *this* bad at protecting your customer data as a multi-million dollar company?

    • @trog871
      @trog871 Місяць тому +23

      its because they never cared about the customers, some exec probably ran the numbers and decided paying to upgrade their systems to be more secure would hurt their stock price that quarter so they just said fuck it and didn't

    • @godhimself9396
      @godhimself9396 Місяць тому +1

      Protecting properly costs money

    • @SylveonMujigae
      @SylveonMujigae 22 дні тому

      @@trog871Oh really? Well that means someone in charge is quite incompetent…

  • @ld2048
    @ld2048 Місяць тому +1

    when the government doesn't listen (why would they, the lobbyists pay them too much) the people need to force justice.
    Either mass boycotts or lawsuits will be needed, they only care about money, so take it from them.

  • @goofballbiscuits3647
    @goofballbiscuits3647 Місяць тому +1

    AT&T waited until St Patty's 😅 "Hope they're drunk enough to forget about how fukn inept we are 🎉"

  • @pauljs75
    @pauljs75 Місяць тому

    A lot of databases are exposed to the lowest paid employees in regards to information services (like customer service reps), and then they wonder why the stuff keeps leaking. Hackers likely put a bounty on getting passwords to access that stuff, that would be months or even a whole year of wages to somebody at a temp agency with no loyalty to their employer. Sure there are other methods if they're looking for "street cred", but social engineering the way around corporate does things seems the easiest way in.

  • @quinnmaillot3882
    @quinnmaillot3882 Місяць тому +1

    No dice for me. My dad as well seems to also have recieved many scam calls

  • @NoahGooder
    @NoahGooder Місяць тому +1

    im happy i left ATT back when they really were screwing me hard because i was attempting to use an out of carrier phone that had the same hardware as an incarrier phone.

  • @holetarget4925
    @holetarget4925 Місяць тому +2

    American are the kings of reframing. so instead of saying a BREACH, the reframed it to a RELEASE...

  • @wannabelikegzus
    @wannabelikegzus Місяць тому

    I dropped AT&T in October, and I did not hear squat from them about this. Definitely going to be paying attention to the lawsuits.

  • @ramycardo
    @ramycardo Місяць тому +1

    Im a current att customer and have not been contacted by them about this situation

  • @Clanps
    @Clanps Місяць тому +4

    Thankfully I don't have AT&T anymore, I have google fiber but I don't think that's any better for me 😭

    • @L-ananas-De-Fete
      @L-ananas-De-Fete Місяць тому

      You should still be careful. Most of the stolen data came from former AT&T customers.

    • @Clanps
      @Clanps Місяць тому +1

      @@L-ananas-De-Fete Yeah, other than my name and address I don't have any of the same credentials for payments or anything like that. It's been about 8 years since we've had AT&T.

    • @beadoll8025
      @beadoll8025 Місяць тому

      ​@@ClanpsThere are customers who had at&t over 10-15 years ago and they have received notifications from their credit monitoring company's that their information was compromised.

  • @starting5524
    @starting5524 Місяць тому +2

    Bottom line, if they can't secure the data, they shouldn't have the data.

  • @pictotalk
    @pictotalk Місяць тому +1

    didnt know about this until now

  • @fixitman2174
    @fixitman2174 Місяць тому +1

    They don't care, and they won't suffer any significant loss for it. Any company losses will look big to the average person, but will be a drop in the bucket for AT&T. That's the way mistakes have been handled for centuries-smoke and mirrors.

  • @ast12321
    @ast12321 Місяць тому +2

    Imagine not seasoning your passcodes. Gotta use that dawn+Lawrys on your chicken and your passwords.

  • @Hello-bg8hv
    @Hello-bg8hv Місяць тому +3

    @Mental Outlaw can you make a video on how to check if your info is apart of one of these data bases. What to do about it

  • @storm61479
    @storm61479 Місяць тому +4

    AT&AT first in the alphabet, and nothing else

  • @fokyewtoob8835
    @fokyewtoob8835 19 днів тому

    Bro thats damn near half the country social security numbers breached....

  • @battokizu
    @battokizu Місяць тому +15

    So att finally will be dethroned

    • @HarambeeOffical
      @HarambeeOffical Місяць тому +2

      Rest in peace all my homies who use ATT Fiber

    • @MushookieMan
      @MushookieMan Місяць тому +4

      No it won't. Judge will get a payday

    • @ICE0124
      @ICE0124 Місяць тому +2

      sadly like 99.9% of people dont really care and will continue using at&t anyways

  • @AKawaiiDragon
    @AKawaiiDragon Місяць тому +8

    Ditched AT&Terrible as I call it finally and they continue screwing me even after I left. What a bunch of clowns

  • @tanchwa3740
    @tanchwa3740 Місяць тому

    I hope the lawyers on the class action are able to use the actual numbers people lost by getting scammed as a result of the leak. It's usually hard to put a dollar sign on stuff like this, but they actually have a good chance to make it a good stick to ATT. Imagine if they come up with like 5 to 10 cases of real people being scammed $500 to $30000 and they used that for their entire settlement amount.

  • @ktg5
    @ktg5 Місяць тому

    someone i know got mail sent to them from another company that wasn't involved with AT&T saying that their data was leaked. AT&T can't even notify their customers correctly...

  • @chanerubin2287
    @chanerubin2287 Місяць тому +2

    4 digit pass code encryption is useless. Even if it's an extremely slow encryption to crack, it'll take a second or 2. If it's something like an md5, you can crack all 70M in a few minutes with a 4090.