AT&T believes the February 22 outage “was caused by the application and execution of an incorrect process as we were expanding our network, not a cyber attack”
AT&T says they have “restored wireless service to all our affected customers.”
Context & Ripple Effects
The incident first surfaced as widespread customer reports, while other major US carriers said their networks were not affected. AT&T’s restoration notice and explanation recast the event as a network-change failure rather than an intrusion.
The later record raised the stakes: an FCC investigation into the February outage found that it disrupted more than 92 million voice calls and impeded 25,000 attempts to reach 911. That makes the company’s process-level attribution consequential beyond a routine service restoration.
First-order effects
- AT&T can focus its immediate incident response on the process used for network expansion—its execution, controls, and rollback path—rather than on cyber containment.
- Affected customers regain wireless service, but the outage’s documented disruption to calls and emergency-call attempts makes reliability remediation a priority for AT&T.
Second-order effects
- The scale established by the subsequent FCC findings increases scrutiny of how carriers test and deploy network changes, particularly where a single process can affect nationwide service.
- Interconnection reliability also becomes a broader concern: AT&T later resolved a separate cross-carrier calling outage, underscoring that restoration at one network layer does not eliminate call-completion risks.
Third-order effects
- If major carrier outages continue to trace back to operational changes, network expansion will increasingly be governed as critical-service change management, with stronger safeguards around validation, staged deployment, and recovery.
- The pattern points to resilience oversight that treats operational mistakes and cyber incidents as distinct causes but similarly serious threats to communications continuity.
The trend: Telecom resilience is shifting from a cybersecurity-only framing toward tighter control of the operational processes used to evolve live networks.