Did AT&T breach include AweSIM users?

Quoting Krebs On Security:

However, the company said a subset of stolen records included information about the location of cellular communications towers closest to the subscriber, data that could be used to determine the approximate location of the customer device initiating or receiving those text messages or phone calls.

“While the data does not include customer names, there are often ways, using publicly available online tools, to find the name associated with a specific telephone number,” AT&T allowed.

So that would definitely be concerning to journalists in particular, as you said. They would want to prevent identifying their sources.

But yes, this breach (if you can believe AT&T’s statement) seems to have occurred prior to AweSIM’s switch from a T-mobile provider to an AT&T one:

See also (re a previous AT&T breach from 2019):

2 Likes