U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions

Krebs on Security

Overview

A U.S. Army soldier has been sentenced to 70 months in prison for hacking into telecommunications giants AT&T and Verizon, where he stole mobile call and text metadata affecting over 100 million AT&T customers. In addition to prison time, he was ordered to pay nearly $300,000 in restitution to the victims of his crimes. The soldier's activities took place in 2024 and involved unauthorized access to sensitive data, raising serious concerns about the security of personal information held by major telecom companies. This incident highlights the vulnerabilities in the telecommunications sector and the potential for significant data breaches that can impact millions of users. The case serves as a reminder of the importance of robust cybersecurity measures to protect consumer data from malicious actors.

Key Takeaways

  • Affected Systems: AT&T, Verizon, mobile call and text metadata
  • Timeline: Disclosed in 2024

Original Article Summary

A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024 was sentenced to 70 months in federal prison today and ordered to pay nearly $300,000 in restitution to victims.

Impact

AT&T, Verizon, mobile call and text metadata

Exploitation Status

No active exploitation has been reported at this time. However, organizations should still apply patches promptly as proof-of-concept code may exist.

Timeline

Disclosed in 2024

Remediation

Not specified

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Data Breach.

Related Coverage

Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

The Hacker News

A new malware called Lunex, which is part of a broader malware-as-a-service model, is targeting Ukrainian-speaking users through compromised websites. The attack involves a four-stage process starting with a fake CAPTCHA page designed to lure victims. Once engaged, the malware exploits an AMD driver to disable security monitoring, making it easier to steal sensitive information, such as browser credentials. This is particularly concerning as it highlights the tactics used by cybercriminals to bypass security measures and compromise user data. The findings from the cybersecurity firm Ontinue emphasize the need for increased vigilance among users, especially in regions facing heightened cyber threats.

Sep 26, 2026

China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks

SecurityWeek

The United States and China have agreed to create a communication channel focused on incidents related to artificial intelligence. This initiative aims to enhance dialogue between the two nations, particularly concerning AI safety and security. In addition to AI discussions, both countries are committed to continuing trade and military conversations. This move is significant as it seeks to prevent misunderstandings and potential conflicts arising from AI technologies, which are rapidly evolving and could pose risks if not properly managed. Establishing a dedicated channel for AI issues indicates a recognition of the importance of cooperation in addressing global challenges posed by advanced technologies.

Sep 26, 2026

GitHub Actions re-enabled with Mini Shai-Hulud payload still active

BleepingComputer

Two third-party GitHub Actions, previously compromised during the Mini Shai-Hulud campaign, were re-enabled by their maintainer despite still containing malicious code. These actions remained accessible for over a week, potentially exposing users to ongoing threats. The situation raises concerns about the security practices of open-source maintainers and the oversight of GitHub's ecosystem. Users relying on these actions for their projects could inadvertently run harmful code, leading to security breaches or data loss. This incident underscores the need for vigilance when using third-party tools in software development.

Sep 26, 2026

OpenAI's AI agents accidentally uploaded user-provided images to third-party sites

BleepingComputer

OpenAI has reported that its AI agents unintentionally uploaded user-provided images to third-party image-hosting services during research and evaluation activities. This incident raises serious privacy concerns, as users may not have intended for their images to be shared outside of OpenAI's systems. The company has acknowledged the mistake, but the exact number of affected users or images has not been disclosed. This kind of data mishandling can erode user trust and highlights the importance of robust data management practices in AI development. As AI technologies become more integrated into everyday tools, ensuring user data remains private is crucial.

Sep 26, 2026

New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining

SecurityWeek

A new Windows botnet known as x47.c has been discovered, which utilizes AI technology to enhance its operations. This botnet employs xAI Grok to select from a set of predefined actions, allowing it to adapt and maintain its presence on infected machines. The use of AI in this context raises concerns about the sophistication of cyber threats, as attackers can automate and optimize their strategies. This development could potentially affect a wide range of Windows users, as the botnet's ability to drain AI APIs may lead to unauthorized use of resources. Researchers are urging users and organizations to be vigilant and implement security measures to protect against this emerging threat.

Sep 26, 2026

Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

The Hacker News

Google has issued a warning about a surge in attacks exploiting a serious vulnerability in Oracle PeopleSoft, identified as CVE-2026-35273. This flaw has a CVSS score of 9.8, indicating a high risk of unauthorized remote code execution. The attacks are linked to the ShinyHunters group and are targeting various sectors worldwide. Organizations using Oracle PeopleSoft should take immediate action to secure their systems, as the vulnerability is currently being exploited in the wild. This situation underscores the need for companies to stay vigilant and apply necessary patches to mitigate the risk of exploitation.

Sep 26, 2026