AT&T call centers sold mobile customer information to criminals

The company will pay a $25 million civil penalty to the FCC in a settlement

Employees at three overseas call centers sold hundreds of thousands of AT&T customer records, including names and Social Security numbers, to criminals who attempted to use the customer information to unlock stolen mobile phones, the U.S. Federal Communications Commission said.

More than 279,000 U.S. customers of AT&T were affected by the data breaches, originating in call centers in Mexico, Colombia and the Philippines, the FCC said. AT&T has agreed to pay a US$25 million civil penalty and create a new data security program in a settlement with the agency, announced Wednesday.

The $25 million settlement is the largest related to a data breach and customer privacy in the FCC's history, the agency said.

More than 290,000 requests to unlock mobile phones connected to the breached customer records were made through AT&T's website, an FCC official said. The data breaches included customer names, partial or full Social Security numbers and some call history and other account information, the FCC said. Unlocking a phone allows it to be used on a new mobile network.

The enforcement action shows the FCC will use its authority against companies that "fail to safeguard" the personal information of customers, FCC Chairman Tom Wheeler said in a statement. The FCC "cannot -- and will not -- stand idly by when a carrier's lax data security practices expose the personal information of hundreds of thousands of the most vulnerable Americans to identity theft and fraud," he added.

The data breaches at the three call centers, operated by contract vendors of AT&T, lasted for months, with sales of customer records at the Mexico call center running from November 2013 to April 2014, the FCC said. The data breach at the Mexico call center affected about 68,000 AT&T customers and the breaches in Colombia and the Philippines affected about 211,000 customers, the agency said.

The data breach in Mexico involved three call center employees, while 40 employees from the Colombia and Philippines call centers were involved, the FCC said.

AT&T has terminated some call center vendor contracts due to the breaches, and it has strengthened some internal data protection processes, the company said. AT&T has "no reason to believe" that the stolen customer records were used for identity theft or financial fraud, the company said in a statement.

"Protecting customer privacy is critical to us," AT&T added. "We hold ourselves and our vendors to a high standard.  Unfortunately, a few of our vendors did not meet that standard."

AT&T will notify all affected customers, will pay for credit monitoring in many cases, and hire a data security compliance manager as part of the settlement with the FCC.

Grant Gross covers technology and telecom policy in the U.S. government for The IDG News Service. Follow Grant on Twitter at GrantGross. Grant's email address is grant_gross@idg.com.

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags governmentregulationat&tU.S. Federal Communications CommissionTom Wheeler

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Grant Gross

IDG News Service
Show Comments

Brand Post

Win pair of MOMENTUM True Wireless

Three PC World readers will be in the running to take home a pair of MOMENTUM True Wireless which are meticulously crafted with every fine listening detail considered. *T&C's Apply

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Jack Jeffries

MSI GS75

As the Maserati or BMW of laptops, it would fit perfectly in the hands of a professional needing firepower under the hood, sophistication and class on the surface, and gaming prowess (sports mode if you will) in between.

Taylor Carr

MSI PS63

The MSI PS63 is an amazing laptop and I would definitely consider buying one in the future.

Christopher Low

Brother RJ-4230B

This small mobile printer is exactly what I need for invoicing and other jobs such as sending fellow tradesman details or step-by-step instructions that I can easily print off from my phone or the Web.

Aysha Strobbe

Microsoft Office 365/HP Spectre x360

Microsoft Office continues to make a student’s life that little bit easier by offering reliable, easy to use, time-saving functionality, while continuing to develop new features that further enhance what is already a formidable collection of applications

Michael Hargreaves

Microsoft Office 365/Dell XPS 15 2-in-1

I’d recommend a Dell XPS 15 2-in-1 and the new Windows 10 to anyone who needs to get serious work done (before you kick back on your couch with your favourite Netflix show.)

Maryellen Rose George

Brother PT-P750W

It’s useful for office tasks as well as pragmatic labelling of equipment and storage – just don’t get too excited and label everything in sight!

Featured Content

Product Launch Showcase

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?