More stories

  • in

    China’s Hacking Reached Deep Into U.S. Telecoms

    The chairman of the Senate Intelligence Committee said hackers listened to phone calls and read texts by exploiting aging equipment and seams in the networks that connect systems.China’s recent breach of the innermost workings of the U.S. telecommunications system reached far deeper than the Biden administration has described, the chairman of the Senate Intelligence Committee said on Thursday, with hackers able to listen in on telephone conversations and read text messages.“The barn door is still wide open, or mostly open,” the Democratic chairman, Senator Mark Warner of Virginia, a former telecommunications executive, said in an interview on Thursday.Mr. Warner said he had been stunned by the scope and depth of the breach, which was engineered over the past year by a group linked to Chinese intelligence that has been named Salt Typhoon by Microsoft, whose cybersecurity team discovered the hack in the summer. Government officials have been struggling to understand what China obtained and how it might have been able to monitor conversations held by a number of well-connected Americans, including President-elect Donald J. Trump and Vice President-elect JD Vance.At first, the F.B.I. and other investigators believed that China’s hackers used stolen passwords to focus mostly on the system that taps telephone conversations and texts under court orders. It is administered by a number of the nation’s telecommunications firms, including the three largest — Verizon, AT&T and T-Mobile. But in recent days, investigators have discovered how deeply China’s hackers had moved throughout the country by exploiting aging equipment and seams in the networks connecting disparate systems.U.S. officials said that since the hack was exposed, the Chinese intruders had seemingly disappeared, suspending their intrusion so their full activity could not be discovered. But Mr. Warner said it would be wrong to conclude that the Chinese had been ousted from the nation’s telecommunications system, or that investigators even understood how deeply they were embedded.“We’ve not found everywhere they are,” Mr. Warner said.The committee has received briefings from the government on the hack, and Mr. Warner has had conversations with telecommunications executives.We are having trouble retrieving the article content.Please enable JavaScript in your browser settings.Thank you for your patience while we verify access. If you are in Reader mode please exit and log into your Times account, or subscribe for all of The Times.Thank you for your patience while we verify access.Already a subscriber? Log in.Want all of The Times? Subscribe. More

  • in

    Are You an AT&T Customer? Here’s What to Know About the Data Breach

    Nearly all AT&T customers were affected by a recent cyberattack.Nearly all customers of the telecommunications company AT&T were affected by a cyberattack that exposed phone records of calls and texts from May 2022 through October 2022, and on Jan. 2, 2023, the company said Friday.Although the company said the breach did not expose the contents of calls or texts or information such as Social Security numbers, passwords or other personally identifiable information, the information that was exposed can still threaten customers’ security.If you are an AT&T customer, here is what you need to know about the breach.How do I know if my records were exposed?AT&T will contact you by text, email or U.S. mail if your account was affected by the cyberattack, the company said.But AT&T also said that “nearly all” customers had been affected by the breach. So if you were a customer from May 1, 2022, to Oct. 31, 2022, or on Jan. 2, 2023, your phone logs were most likely exposed.What was exposed?The phone numbers that you texted and called, as well as how frequently you interacted with them, were exposed by the breach, the company said.Customers’ personal details, such as Social Security numbers and dates of birth, were not exposed. Nor were the contents of the calls and texts. Although customers’ names were not exposed by the breach, “there are often ways to find a name associated with a phone number using publicly available online tools,” AT&T said.We are having trouble retrieving the article content.Please enable JavaScript in your browser settings.Thank you for your patience while we verify access. If you are in Reader mode please exit and log into your Times account, or subscribe for all of The Times.Thank you for your patience while we verify access.Already a subscriber? Log in.Want all of The Times? Subscribe. More

  • in

    Germany to Strip Huawei From Its 5G Networks

    Major telecom companies agreed to stop using critical components made by Chinese companies in their mobile infrastructure by 2029.The German government said on Thursday that it had reached an agreement with major telecom companies to have them stop using critical Huawei and ZTE components in their 5G mobile infrastructure in five years, the latest step by a European country to ban Chinese companies from critical telecommunications infrastructure.“We are protecting the central nervous system of the German economy — and we are protecting the communication of citizens, companies and the state,” Nancy Faeser, the interior minister, said in a news conference in Berlin on Thursday.The agreement with the telecom companies — Deutsche Telekom, Vodafone and Telefonica — comes in two steps. First, use of Chinese-made critical components will be discontinued from core parts of the country’s 5G networks by the end of 2026. Then, the parts made by Chinese manufacturers will be phased out from antennas, transmission lines and towers by the end of 2029.Huawei and ZTE did not respond to requests for comment.Germany, which accounts for roughly a quarter of mobile customers in the European Union , is highly dependent on the Chinese export market and has long delayed taking such a drastic step against Chinese firms. Instead it has chosen to certify components based on a case-by-case security check.Other European countries such as Britain, Denmark, Sweden, Latvia, Estonia and Lithuania have already instituted bans on Huawei and ZTE components. The United States has restricted the use of Huawei equipment since at least 2019.In presenting the arrangement, Ms. Faeser reiterated that it was based on negotiations with German telecom providers. Those providers had long argued that switching from Huawei and ZTE components too quickly would be complicated and expensive.The question of banning Huawei and ZTE from German mobile infrastructure has been discussed in Berlin since the previous government, headed by Angela Merkel, but the decision announced on Thursday comes after an extensive security assessment, said Ms. Faeser.“The current threat situation underlines the importance of a secure and resilient telecommunications infrastructure, especially in view of the dangers of sabotage and espionage,” she said.Adam Satariano More

  • in

    AT&T Passcodes for Millions Are Reset After Leak of Customer Records

    Nearly eight million customers and 65.4 million former account holders were affected by the data breach, the company said.The telecommunications giant AT&T announced on Saturday that it had reset the passcodes of 7.6 million customers after it determined that compromised customer data was “released on the dark web.”“Our internal teams are working with external cybersecurity experts to analyze the situation,” AT&T said. “To the best of our knowledge, the compromised data appears to be from 2019 or earlier and does not contain personal financial information or call history.”The company said that “information varied by customer and account,” but that it may have included a person’s full name, email address, mailing address, phone number, Social Security number, date of birth, AT&T account number and passcode.In addition to those 7.6 million customers, 65.4 million former account holders were also affected.The company said it would be “reaching out to individuals with compromised sensitive personal information separately and offering complimentary identity theft and credit monitoring services.”AT&T said it reset the passcodes for those affected and directed customers to a site with details about how to reset them. It also said that it was starting a “robust investigation supported by internal and external cybersecurity experts.”A company representative did not address specific questions about how the breach happened or why it went unnoticed for so long.TechCrunch, which first reported on the passcode reset, said it informed AT&T on Monday that “the leaked data contained encrypted passcodes that could be used to access AT&T customer accounts.”TechCrunch said it delayed publishing its article until the company “could begin resetting customer account passcodes.”In its report, TechCrunch said that “this is the first time that AT&T has acknowledged that the leaked data belongs to its customers, some three years after a hacker claimed the theft of 73 million AT&T customer records.”AT&T had previously denied a breach of its systems but how the leak happened was unclear, TechCrunch reported.AT&T said that it did not know whether the leaked data “originated from AT&T or one of its vendors” and that it “does not have evidence of unauthorized access to its systems resulting in theft of the data set.”The episode comes after AT&T customers experienced a widespread outage last month that temporarily cut off connections for users across the United States for several hours. The Feb. 22 outage affected customer in cities including Atlanta, Los Angeles and New York.At its peak, there were around 70,000 reports of disrupted service for the wireless carrier, according to Downdetector.com, which tracks user reports of telecommunication and internet disruptions.A few days later, AT&T offered customers affected by the outage a $5 credit in an effort to “make it right.” More

  • in

    Lawsuits Accuse 2 Michigan Jails of Banning Family Visits to Increase Revenue

    The suits contend that two counties entered into agreements with telecommunications companies that would bring more money because of increased use of phone calls and electronic messaging.Two county jails in Michigan banned in-person family visits for inmates several years ago as a way to boost county revenues from the increased number of phone calls and electronic messaging that resulted, a pair of lawsuits filed this month claim.The bans on in-person visits leave “electronic communications — phone and video calls and electronic messaging — as the sole way for the families of people detained in the jail to talk with their loved ones inside,” according to the lawsuits, which were filed on behalf of the families. The suits claim that officials in St. Clair County and Genesee County entered into a “quid pro quo kickback scheme” with Global Tel*Link Corporation and Securus Technologies.Both companies denied any wrongdoing.Jennifer Jackson-Luth, a spokesperson for Securus, called the lawsuit in which that company is named “misguided and without merit.”“We look forward to defending ourselves, and we will not let this suit detract from our successful efforts to create meaningful and positive outcomes for the consumers we serve,” she said.Global Tel*Link, which changed its name to ViaPath Technologies in 2022, said that it “denies the allegations in the complaint and looks forward to the opportunity to defend the claims made against it.”Phone messages left with the Genesee County Sheriff’s Office and to the St. Clair County Sheriff’s Office this week were not returned.We are having trouble retrieving the article content.Please enable JavaScript in your browser settings.Thank you for your patience while we verify access. If you are in Reader mode please exit and log into your Times account, or subscribe for all of The Times.Thank you for your patience while we verify access.Already a subscriber? Log in.Want all of The Times? Subscribe. More

  • in

    Landline Users Remain Proudly ‘Old-Fashioned’ in the Digital Age

    When millions of AT&T customers across the country briefly lost their cellphone service last month, Francella Jackson, 61, of Fairview Heights, Ill., said she picked up her well-worn Southwestern Bell push-button landline phone and called her friends “just so we could laugh at the people who could not use their phones.”“Why, isn’t it great that we can talk and have a great conversation?” she recalled saying. “We had a good laugh.”Derek Shaw, 68, of York, Pa., said he has an Android mobile phone, but prefers talking on his black cordless landline at home. The sound quality is better, he said, and the phone is easier to hold during long conversations. Mr. Shaw said that he also likes talking to people face to face rather than on Zoom and never got rid of his vinyl record collection when CDs got hot in the 1990s.“I’ve never even thought about giving up my landline,” he said. “I’ll go kicking and screaming when I have to.”The fashion designer Adrienne Vittadini in 1984.Susan Wood/Getty ImagesTo many, landline phones have come to seem as essential as steamships and telegrams in the smartphone era. But to those who still use them, they offer distinct advantages. Prompted by the AT&T outage on Feb. 22 and a push by AT&T to phase out traditional landlines in California, those who have them are speaking out in defense of their old phones.We are having trouble retrieving the article content.Please enable JavaScript in your browser settings.Thank you for your patience while we verify access. If you are in Reader mode please exit and log into your Times account, or subscribe for all of The Times.Thank you for your patience while we verify access.Already a subscriber? Log in.Want all of The Times? Subscribe. More

  • in

    AT&T Offers $5 Credit After Widespread Service Outage

    Thousands of customers lost service on Thursday when the telecommunications company ran into problems while trying to expand its network, the company’s chief executive said.AT&T will offer a $5 credit to customers affected by a widespread outage on Thursday that was caused by technical issues the company encountered while trying to expand its network, its chief executive said on Sunday.The outage, which started around 3:30 a.m. Eastern time, temporarily cut off connections for users across the United States.Some of the affected cities included Atlanta, Los Angeles and New York, according to Downdetector.com, which tracks user reports of telecommunication and internet disruptions.At its peak, the site had received about 70,000 reports of disrupted service for AT&T. Service was fully restored after about seven hours.“No matter the timing, one thing is clear — we let down many of our customers, including many of you and your families,” the chief executive of AT&T, John T. Stankey, wrote in a letter dated Sunday. “For that, we apologize.”In an effort to “make it right” AT&T is offering customers a $5 credit on their AT&T Wireless account, according to the company’s website.“For the portion of consumer and small business customers most impacted by the outage, we are automatically applying an account credit to compensate them for the inconvenience they experienced,” the company said.It will take one to two billing cycles for the credit to appear, depending on when a customer’s bill closes, the company said.Prepaid customers will have options available if they were affected, Mr. Stankey wrote, but did not specifically identify those options.AT&T also said it was “working closely” with Mid-Market and Enterprise customers, which are internet plans for businesses, to address their concerns.It was not immediately clear how much the credits would amount to in lost revenue. A company representative could not be reached on Sunday.In a statement, AT&T emphasized that the outage wasn’t caused by a cyberattack.“Our initial review of the cause of Thursday’s outage indicates it was due to the application and execution of an incorrect process used while working to expand our network,” Mr. Stankey wrote in his letter.The credit is meant to refund customers for the day that the service was lost, he wrote.“I believe that crediting those customers for essentially a full day of service is the right thing to do,” Mr. Stankey wrote. More