Skip to main content
Incident intelligence/SS-IR-043CASE FILE OPEN
Symbolic editorial illustration for SS-IR-043SERVANTSTACK // INCIDENT INTELLIGENCEFORENSIC IMAGE // VERIFIED FRAME
SS-IR-043 // INCIDENT REPORTReported

AT&T / Snowflake

110 Million Customer Records Exposed via Automated Pipeline

EXECUTIVE BRIEF

Attackers accessed AT&T's data stored on Snowflake's cloud platform and exfiltrated call and text records for nearly all 110 million AT&T customers spanning May through October 2022.

FAILURE CHAINTRACE COMPLETE
  1. 01TRIGGERAttackers accessed AT&T's data stored on Snowflake's cloud platform and exfiltrated call and text records for nearly…
  2. 02MACHINE ACTIONOperational automation
  3. 03MISSING GATETrust boundaries, least privilege, and output approval
  4. 04IMPACTData security
01 // INCIDENT SUMMARY

The short version

Attackers accessed AT&T's data stored on Snowflake's cloud platform and exfiltrated call and text records for nearly all 110 million AT&T customers spanning May through October 2022.

02 // KEY FACTS

Case telemetry

INCIDENT
SS-IR-043
DATE
July 12, 2024
SYSTEM
AT&T / Snowflake
LOCATION / SCOPE
United States
EVIDENCE
Reported
AI ROLE
Operational automation
HARM
Data security
SOURCES
2 cited records
03ENTRY POINT // WHAT HAPPENED

The event

Attackers accessed AT&T's data stored on Snowflake's cloud platform and exfiltrated call and text records for nearly all 110 million AT&T customers spanning May through October 2022. The breach was part of a campaign targeting multiple Snowflake clients - Ticketmaster, Santander Bank, Advance Auto Parts, and others were also compromised. The common vector: automated cloud data pipelines connected to Snowflake accounts that lacked multi-factor authentication.

04CAUSAL TRACE // AI'S ACTUAL ROLE

What the machine did

The Snowflake data pipeline was fully automated - ingesting, processing, and making available massive datasets without human review of access patterns. The accounts used single-factor authentication. No human monitored for anomalous data access volumes. The automated pipeline treated a bulk exfiltration of 110 million records the same as a routine analytics query. The breach was so sensitive the Department of Justice requested AT&T delay its SEC disclosure - a first in U.S. cybersecurity history.

Operational automationAutomation was a causal participant—not a decorative label for the system around it.
05BLAST RADIUS // CONSEQUENCES

Where the failure landed

110 million customers' call and text metadata exposed. AT&T paid a reported $370,000 ransom. The DOJ took the unprecedented step of requesting delayed SEC disclosure due to national security concerns. A separate March 2024 breach exposed SSNs, addresses, and passcodes for 73 million current and former customers, triggering multiple class-action lawsuits.

06 // EVIDENCE STATUS

Reported

Documented in the cited public record. Follow the sources for the precise evidentiary posture.

SOURCE RECORD UPDATED 2026-07-09

07 // SOURCE LEDGER

2 cited records

  1. 01
  2. 02
    Primary / officialAT&T SEC 8-K Filing
08CONTROL FAILURE // MISSING GOVERNANCE

Trust boundaries, least privilege, and output approval

The failure pattern in this case: Untrusted input crossed a privileged boundary.

09INTERVENTION POINT // HUMAN IN THE MIDDLE

The moment the path could change

A security owner approves credential scope and externally visible actions before the agent can cross a trust boundary.

AI PROPOSESHUMAN OWNS THE DECISIONSYSTEM EXECUTES
10CONTROL DEPLOYMENT // AUTHORITYGATE

Trust boundary policy · output approval

AuthorityGate mandates human review of data access patterns for sensitive datasets. An analyst reviewing Snowflake access logs would have flagged the bulk exfiltration immediately - no legitimate query needs 110 million records at once. The framework also requires MFA on all automated pipelines accessing PII, and anomaly thresholds that alert a human when data access exceeds normal volumes.

RELEVANT GOVERNANCE FRAMEWORKAgentic AI GovernanceThe governance model for autonomous systems, Zero Trust verification, SME approval, and accountable execution.
12 // THE ALTERNATIVE

Autonomy is a design choice.

See the operating model that keeps AI useful while preserving human authority at consequential moments.

Compare AgenticAI and AugmentedAI →