U.S. Army Soldier Sentenced to 70 Months for AT&T, Verizon Extortion Hacks
What happened
According to KrebsOnSecurity, a U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies was sentenced to 70 months in federal prison and ordered to pay nearly $300,000 in restitution to victims. The intrusions reportedly involved theft of mobile call and text metadata belonging to more than 100 million AT&T customers in 2024, with Verizon also named among the affected carriers.
Why it matters for defenders
This case underscores that telecom infrastructure remains a high-value target for insiders and individual attackers, not just nation-state groups. Call detail records (CDRs) and text metadata — even without message content — can reveal sensitive relationship, location, and communication-pattern data at massive scale. Breaches of this size at carriers have downstream implications for any organization whose employees or executives are customers of the affected providers, since metadata can enable social engineering, SIM-swap targeting, or further extortion attempts.
What defenders should watch for
- Telecom and MSP security teams should review access controls and audit logging around systems that store or export bulk subscriber call/text metadata.
- Monitor for anomalous large-volume data exports or API queries against customer metadata stores, especially from privileged or internal accounts.
- Organizations should assume telecom metadata about their personnel may have been exposed in prior incidents and factor that into phishing/social-engineering awareness training.
- Where extortion is involved, incident response teams should have playbooks ready for handling threat-actor contact and coordinating with law enforcement, rather than negotiating unilaterally.
Developing story
This is based on reporting from a single source and details of the underlying intrusion techniques were not disclosed in the summary available to us. For the full story, see the original report at KrebsOnSecurity.