Contact Us
Cart
Item added Item updated Item removed No more products on stock You entered wrong value.

No products in the cart.

Cart
Item added Item updated Item removed No more products on stock You entered wrong value.

No products in the cart.

Blog

AT&T Breach: 3 Human Factors Exposed

July 29, 2024
Posted by Andre Marion
AT&T Breach

According to Gartner, global security and risk management spending is expected to grow 14% this year to $215 billion, catapulted by recent changes worldwide: continuous hybrid workforce, the rapid ascension of generative AI, and the rising necessity to adopt cloud services to accommodate modern workplaces. And yet, a string of cyber attacks (including the AT&T breach) this summer have caused significant damage to several enterprises and are likely to cause another spike in cyber insurance rates. 

One of the most prominent corporate weak spots hackers look for is their employees, where companies are spending an average $3,000 each for cyber training and resilience.

AT&T Breach: What Happened?

The AT&T breach on June 24 resulted from a more significant internet breach, the Snowflake breach, a “coordinated campaign targeting multiple organizations using Snowflake’s cloud storage services. At least 165 organizations were potentially affected by unauthorized access to their Snowflake customer instances,” as provendata.com reports.

AT&T stated that the compromised data includes the telephone numbers of nearly 110 million of its mobile customers and the customers of wireless providers that used its network between May 1, 2022, and October 31, 2022, including a record of every number these customers called or texted.

Although AT&T clarified that the exposed data did not include the content of calls or texts, nor did it contain sensitive personal information such as Social Security numbers or birth dates, in a different statement, it was said that the records could potentially be linked to individuals through publicly available tools, raising concerns about privacy and security.

Three Basic Human Factors That Largely Contributed to the AT&T Breach

Several companies, including Ticketmaster, Santander, and Advance Auto Parts, were affected by this attack. The fact is, simple password/authentication hygiene could've prevented much of it

These were three main factors that the crooks leveraged to gain access:

1 - Lack of Multifactor authentication (MFA):

One of the most critical vulnerabilities in the Snowflake breach was the lack of multi-factor authentication on the impacted accounts. This extra layer of security could have significantly reduced the likelihood of unauthorized access, even if attackers have obtained valid login credentials.


2 - Use of Outdated Credentials that had been previously stolen

Old, weak credentials made it much easier for criminals to access users’ accounts, leading to the data breach. Regular credential updates and rotation are a must for companies. By not doing so, paired with the lack of MFA, companies create a recipe for disaster.


3 - The absence of a network allows lists

Allow lists restrict access to trusted locations, ensuring that only authorized devices and IP addresses can access sensitive systems. AT&T's failure to implement network allow lists allowed attackers to access the network from untrusted locations, exacerbating the breach's impact.


How can Cybersecurity Personnel Close the Gap?

After all, much of the damage could’ve been avoided by starting with the basics: effective password hygiene

Ineffective password practices stem from inadequate training and awareness: most employees have been trained on it but they are not disciplined. Cybersecurity is not on top of their minds — getting their jobs done is #1.

In a previous post, we explored the five reasons cybersecurity training falls short. As mentioned in that article, most cybersecurity training sessions are:

  • Repetitive
  • Boring
  • Unrelatable
  • Irrelevant and
  • Lack immediate application

If your cybersecurity awareness team isn’t integrating strong content and promoting continuous learning, your company might be on the path to joining the dire statistics.

Can Aware Force make me a hero and promote massive employee engagement in cybersecurity?

We have the perfect solution if you’re committed to taking cybersecurity to a new level in your organization.

Our offer is simple:

  • Massive employee readership of Aware Force content makes you the hero
  • Real-time metrics dashboard, generating amazing ROI
  • Insanely easy to implement and cost-effective
  • Everything we do is branded for your organization — not for us

Our team is standing by to show you some of the innovative ways organizations use Aware Force to engage their employees. (And the employees let them know how much it’s appreciated!)

Get in touch with us here at https://awareforce.com/contact-us/ :

Sources:

Get the latest insights in cybersecurity. Subscribe to the Aware Force Cyber Blog
Insightful cyber news, fresh ideas for engaging your employees and more.
Let's connect!
Learn innovative ways organizations are using Aware Force.
Phone
(470) 448-3887
Email
cutrisk@awareforce.com
Contact US

usercartmagnifiercross linkedin facebook pinterest youtube rss twitter instagram facebook-blank rss-blank linkedin-blank pinterest youtube twitter instagram