Gift your grad endless possibilities. Celebrate right now and connect them to their brightest future.
Need to update email settings?
hcabello's profile

New Member

 • 

1 Message

Monday, March 6th, 2023 10:49 PM

Is this CPNI email a phishing scam?

​I received an email from"AT&T <[email scrubbed]>".  Here is the email and let me know if its legit:​

​ ​​ ​​ ​​ ​​ ​​ ​​ ​

​ ​

​Notice Regarding Customer Proprietary Network Information (CPNI) – Wireless Account Ending in 6811​

​ ​

​ ​

​ ​​ ​​ ​​ ​​ ​​ ​​ ​

​Dear Hugo Cabello,​

​AT&T's commitment to customer privacy and data security is a top priority. We recently determined that an unauthorized person breached a vendor's system and gained access to your "Customer Proprietary Network Information" (CPNI). In our industry, CPNI is information related to the telecommunications services you purchase from us, such as the number of lines on your account or the wireless plan to which you are subscribed. However, please rest assured that no sensitive personal or financial information such as Social Security number or credit card information was accessed. ​

​To address this issue, the following steps have been taken:​

​·        We confirmed with the vendor that the vulnerability has been fixed.​

​ ​
    ​ ​
  • ​We have notified federal law enforcement about the unauthorized access of your CPNI as required by the Federal Communications Commission. Our report to law enforcement does not contain specific information about your account, only that the unauthorized access occurred.​
  • ​ ​

​If you have an existing account with AT&T, you may want to consider adding our "extra security" password protection to the account at no cost. You can learn more at ​​https://www.att.com/support/article/my-account/KM1051397/​​ ​

​Please accept our apology for this incident. If you have further questions, you may visit: ​​https://att.com/data-event/login​​ You will be prompted for your myAT&T login credentials, and if you do not have a myAT&T profile, you can create one using your account information. ​

​Thank you, ​

​AT&T​

​ ​

Clearlyus

New Member

 • 

9 Messages

3 months ago

Nothing in this thread confirmed or denied is the email I got was legit. Will log in to my account and dig around to see what I can find out.

New Member

 • 

3 Messages

3 months ago

The user account portal notifications would be the appropriate place to notify alongside the email. That way safety-concious customers can do the right thing and not click links from unknown senders such as messages dot Mail dash att dot com. This extra step is just smart and a common practice nowadays.

New Member

 • 

5 Messages

3 months ago

I assume it's a scam; no legit company would hide their link behind a fake link, and also if you go to the "support document" KM1051397 you get a 404 error.

JefferMC

ACE - Expert

 • 

32.3K Messages

3 months ago

I assume it's a scam; no legit company would hide their link behind a fake link, and also if you go to the "support document" KM1051397 you get a 404 error.

Assume what you want.  The URL shown for that support article, and the link behind it, both work just fine, thank you very much.

New Member

 • 

5 Messages

3 months ago

You're right, I typed in myatt instead of my-att. Still my point stands. This email is exactly what one would expect from a phishing email.

JefferMC

ACE - Expert

 • 

32.3K Messages

3 months ago

Except all the links are for the "att.com" domain instead of "weebly.com" or "bobsdiscounthosting.info", etc. and those links don't ask you to enter any information at all.

(edited)

New Member

 • 

5 Messages

3 months ago

None of the links are actually att.com.

JefferMC

ACE - Expert

 • 

32.3K Messages

3 months ago

Yes, the href is to ATT-MAIL.COM, which is (as I believe I've already said in this thread) easily verified to be owned by AT&T.

New Member

 • 

5 Messages

3 months ago

Lol, because customers are supposed to look at the URLs beneath faked links and verify the domain info. Go ahead.

JefferMC

ACE - Expert

 • 

32.3K Messages

3 months ago

No, they should really type the visible URL, which uses ATT.COM and works.

Not finding what you're looking for?
New to AT&T Community?
New to the AT&T Community? Start by visiting the Community How-To.
New to the AT&T Community?
Visit the Community How-To.