AT&T inadvertently disclosed tens of thousands of e-mail addresses and ICC-IDs inadvertently disclosed by the company. Attackers can use the information to learn the names and phone numbers of the leaked users. With someone else’s IMSI, an attacker can determine the person’s name and phone number, and even track his or her position. The breach opens the door to active attackscreating fake cell towers that a victim’s phone will connect to, enabling every call and text message to be eavesdropped.”]

