Hacker Found Guilty of Breaching AT&T Site to Obtain iPad Customer Data
A hacker charged with federal crimes for obtaining the personal data of more than 100,000 iPad owners from AT&T's website was found guilty on Tuesday. — Andrew Auernheimer, 26, of Fayetteville, Arkansas …
Context & Ripple Effects
The verdict closes a loop that opened in June 2010, when AT&T confirmed that its own servers had handed out iPad owners' e-mail addresses to anyone who guessed device identifiers — the company's explanation of the breach framed it as a server misconfiguration, not an intrusion. Andrew Auernheimer and a collaborator then published what they had scraped, more than 100,000 addresses, drawing federal charges instead of a thank-you.
Same-day coverage like MIT Technology Review's 'Jail Looms' piece framed the trial as a test of whether touching an open door is a crime, and the jury's answer — guilty — landed with unusual breadth: the story ran across CNET, Computerworld, SiliconANGLE, Betabeat and TechNewsDaily within a day.
First-order effects
- Auernheimer, 26, now moves from trial to sentencing, with prison time on the table for conduct that began with data AT&T's website served up unsolicited.
- AT&T's 2010 lapse gets re-litigated in public as a hacker's conviction rather than a carrier's disclosure failure, shifting the story's blame away from the company whose servers leaked the data.
Second-order effects
- Security researchers who find data exposed on public web servers face a concrete precedent: reporting or publishing it can be prosecuted as unauthorized access, raising the personal cost of disclosure over quiet silence.
- Carriers and consumer-device makers get cover to treat externally visible flaws primarily as legal threats to be pursued against finders, rather than engineering failures to be fixed and disclosed.
Third-order effects
- If the pattern holds, the Computer Fraud and Abuse Act becomes the default instrument for converting embarrassing corporate data exposures into criminal cases against the people who exposed them — a structural chill on independent vulnerability research.
- Disclosure norms split: researchers who cannot afford legal risk go dark or sell findings, while companies lose the free external auditing that public-spirited discovery provided.
The trend: US prosecutors are using the CFAA to criminalize access to data companies leave exposed on their own websites, putting independent security research on trial alongside the hackers.