---
title: "AT&T outage sparks hacking claim, but here’s what really happened"
type: "News"
locale: "en"
url: "https://longbridge.com/en/news/298508407.md"
description: "AT&T attributes a major Texas outage to cable theft, refuting claims by the pro-Iran group APT IRAN. While AT&T resolved the service disruption and offers credits, the incident highlights broader vulnerabilities as Iran-linked actors target US infrastructure. Concurrently, the Cybersecurity Information Sharing Act faces expiration, raising concerns about legal protections for sharing threat data on critical systems like water utilities."
datetime: "2026-09-09T21:36:27.000Z"
locales:
  - [zh-CN](https://longbridge.com/zh-CN/news/298508407.md)
  - [en](https://longbridge.com/en/news/298508407.md)
  - [zh-HK](https://longbridge.com/zh-HK/news/298508407.md)
generator: "portal-rs"
---

# AT&T outage sparks hacking claim, but here’s what really happened

AT&T says there is no evidence supporting that claim. The company’s internal assessment points to attempted cable theft as the cause of Monday’s fiber outage, which knocked out internet, TV and phone service for more than 7,000 Dallas area families and caused issues for some Houston customers as well. The claim came from a group calling itself APT IRAN, which posted on Telegram Tuesday saying it had attacked telecommunications and other critical infrastructure across Texas and vowed to keep escalating through Friday, September 11, the 25th anniversary of the September 11 attacks.

### **How bad was the AT&T outage, and is it over now**

Downdetector tracked an initial spike in reports around 2:15 a.m. Monday, followed by a much larger surge near 2:17 p.m. that topped 5,900 reports at its peak. AT&T posted on X that engineering teams were working to restore service, and the outage was largely resolved by 6 p.m. that evening. The company is offering bill credits to customers who experienced at least 20 minutes of qualifying downtime, with details available through its customer service channels.

### **What actually happens during a copper cable theft**

AT&T says copper remains an attractive target for thieves because it can be sold to scrap metal recyclers for cash, even though the metal itself is not scarce. Fiber optic lines, which carry most modern internet traffic, have essentially no resale value since they are made of glass, but thieves sometimes cut them by mistake while trying to reach copper, causing exactly the kind of disruption seen in Dallas.

AT&T’s spokesperson described thieves using tools to cut cable directly off utility poles or climbing into manholes to wrap chains around underground lines and pull them free with vehicles, a practice that has become common enough that AT&T now offers a 10,000 dollar reward for tips leading to an arrest in the Dallas-Fort Worth area.

### **Is this part of a bigger pattern beyond one outage in Texas**

Yes, and this is where the story gets more serious than a single cable cut. APT IRAN has ties to CyberAv3ngers, a hacking persona linked to Iran’s Revolutionary Guard Corps that has been targeting American water utilities, energy systems and now telecommunications networks since a campaign accelerated following February’s U.S. and Israeli strikes on Iran.

Federal officials say at least 12 states have reported water system intrusions this year alone, with some incidents causing real operational problems like pressure loss and flooding, even though drinking water itself has remained safe throughout. The FBI, CISA, EPA and NSA have issued multiple joint advisories warning that Iran affiliated actors are exploiting internet exposed industrial control equipment, the same category of infrastructure APT IRAN claims to have hit in Texas.

### **Why does a law expiring this month matter here**

The Cybersecurity Information Sharing Act of 2015, which gives utilities and companies legal protection to share threat information with the FBI and CISA without fear of liability, is set to expire September 30 unless Congress renews it.

The law has already lapsed twice in the past year, briefly during last fall’s government shutdown and again in January, and a coalition of more than a dozen trade associations is now pushing Congress to act before the deadline hits again. Critics also point out the law’s current language does not explicitly cover the operational technology, industrial control systems and PLCs that run water treatment plants and similar infrastructure, exactly the equipment this ongoing campaign keeps targeting.

### **What should people in North Texas actually take from this**

For now, AT&T’s own investigation points to a mundane explanation, cable theft rather than a nation state cyberattack, and the company says its network is back to normal. But the claim landing amid a documented, monthslong campaign against American infrastructure means it deserves scrutiny rather than dismissal, especially with a key information sharing law hanging in the balance just weeks away from expiring. Whether this specific outage turns out to be criminal or geopolitical, the broader vulnerability federal agencies keep warning about is not going away on its own.

### Related Stocks

- [T.US](https://longbridge.com/en/quote/T.US.md)
- [T-A.US](https://longbridge.com/en/quote/T-A.US.md)
- [TBB.US](https://longbridge.com/en/quote/TBB.US.md)
- [T-C.US](https://longbridge.com/en/quote/T-C.US.md)

## Related News & Research

- [BREAKINGVIEWS-SpaceX gives wireless industry rude wake-up call](https://longbridge.com/en/news/299179109.md)
- [Iran conflict could drive US household energy costs up by $860](https://longbridge.com/en/news/299114274.md)
- [Skyrocketing fuel prices spark protests around the globe](https://longbridge.com/en/news/299101925.md)
- [X2M Connect Confirms Shareholder-Approved Securities Issue](https://longbridge.com/en/news/298999351.md)
- [India Hardens Its Cyber Defenses](https://longbridge.com/en/news/299012276.md)

---
> **Disclaimer: This article is for reference only and does not constitute any investment advice.**