According to the report, the defendant pleaded guilty to breaking into telecom companies and obtaining call and message metadata for more than 100 million AT&T customers in 2024. Such metadata can include originating and receiving numbers, times, and communication duration. The sentence was 70 months in federal prison and $294,978 in restitution to victims.
The article says the defendant used exposed credentials on customer accounts at a cloud storage service that lacked multi-factor authentication. It also reports claims of intrusions at more than a dozen companies, including Verizon’s Push-to-Talk service, and extortion attempts. The article notes that the cloud company later required multi-factor authentication on all accounts.
The report mentions an alleged accomplice who prosecutors said helped with extortion, and two other defendants in related cases. It says one pleaded guilty in August 2026 and another was wanted in connection with an earlier breach. The article attributes data postings and threats to the defendant; distinguish those claims from the reported court proceedings.
To verify the case, consult the original KrebsOnSecurity article and compare its account with cited court records and official statements. If using AI to study the incident, do not submit customer data, credentials, or internal documents: work from an anonymized summary and check responses against primary sources.