Nearly 6,000 outage reports hit AT&T as hackers claimed a Texas attack – Automated Home

A routine infrastructure failure left thousands of AT&T customers without internet, television, and phone service across North Texas on September 7, 2026. Downdetector reports climbed sharply, reaching 5,990 shortly before 3 p.m. across the Dallas-Fort Worth area, while service was largely restored by about 6 p.m.

The outage became more complicated when an Iran-linked hacking group claimed responsibility for attacking telecommunications and critical infrastructure in Texas. AT&T rejected that explanation, saying its investigation found attempted copper cable theft and no evidence of a cyberattack.

The disruption also exposed how dependent modern households have become on continuous connectivity. Smart-home devices, remote work systems, security cameras, and internet-based phone services can all be affected when a major carrier experiences a prolonged local outage.

AT&T outage disrupted North Texas

AT&T customers experienced several hours of disruption on September 7, with a major fiber outage affecting Dallas-Fort Worth. AT&T said more than 7,000 families were affected in the Dallas area, while users in Houston and several other Texas cities also submitted problem reports.

Downdetector reports began rising shortly after 2:15 a.m. and surged again later in the morning, eventually reaching 5,990 shortly before 3 p.m. Reports fell sharply by about 6 p.m., and AT&T later said Dallas-area internet service was operating normally.

More than 40% of the broader Downdetector reports involved 5G home internet, with broadband and Wi-Fi accounting for much of the remaining activity. The Dallas-area fiber outage affected internet, television, and some phone services.

Source: T.Schneider/Depositphotos

What caused the service failure?

AT&T initially described the Dallas-area disruption as a fiber-related problem before giving a more specific explanation. The company later said its assessment indicated that attempted cable theft caused the outage and that it had no evidence of a cyberattack.

Copper theft has become a persistent problem for telecommunications operators because stolen metal can be sold for scrap. In North Texas, thieves have targeted cables on utility poles and wiring in underground vaults and manholes.

Fiber and copper cables can also run alongside each other. AT&T says attempts to steal copper can therefore damage nearby fiber infrastructure and disrupt internet, telephone, and other communications services even though fiber itself has little value as scrap.

Source: YouTube

Hackers claimed responsibility online

A group using the name APT IRAN later claimed on Telegram that it had attacked telecommunications and other critical infrastructure in Texas. It specifically claimed responsibility for disrupting AT&T internet service in Houston, Dallas, Austin and San Antonio and for breaching an unnamed Texas water utility.

A joint U.S. cybersecurity advisory identifies APT Iran as one of the names used in private-industry and open-source reporting for CyberAv3ngers, an actor affiliated with Iran’s Islamic Revolutionary Guard Corps Cyber Electronic Command. Federal agencies have linked the actor to previous attacks on industrial control equipment.

On August 30, APT IRAN warned that the United States would see “unexpected and critical events” involving energy, water, and telecommunications. In its later AT&T claim, the group said attacks would intensify through September 11.

Little-known fact: APT IRAN publicly claimed “direct responsibility” for a late-July 2026 cyberattack on more than 30 Minnesota water systems, saying the strike was meant only to demonstrate its capabilities.

Is the hacking claim credible?

Security researchers have treated the AT&T claim cautiously because the group has not publicly provided technical evidence showing that it penetrated AT&T’s network. Cybernews researchers said the group may have opportunistically claimed responsibility for an outage that was already publicly visible.

Public outage information can give threat actors an opportunity to claim credit before investigators establish a cause. In this case, the group issued its claim after reports of the disruption had already begun to subside.

No public evidence has confirmed a cyber intrusion connected to the September 7 outage. AT&T specifically said it had no evidence supporting the hacking claim and attributed the disruption to attempted cable theft.

Little-known fact: Threat-intelligence trackers recorded a 133% jump in Iranian APT activity against U.S. critical infrastructure during May–June 2025 alone.

A young male cybersecurity analyst monitors system vulnerabilities and realtime.
Source: Depositphotos

Why physical cable theft still matters

The incident demonstrates that modern connectivity can remain vulnerable to surprisingly basic physical damage. Fiber-optic cables use glass and generally have little scrap value, but they may run alongside copper infrastructure that attracts thieves.

Damage can spread beyond the cable being targeted. Someone attempting to remove copper may cut, pull, or otherwise disturb nearby fiber, potentially disconnecting homes and businesses that depend on the same outside plant.

AT&T offers a $10,000 reward for information leading to the arrest and conviction of people involved in copper cable theft in the Dallas-Fort Worth region. The reward reflects the continuing scale of the problem.

One carrier can create multiple failures

For smart-home households, the outage highlights an important resilience issue. A backup connection provides the most protection when it does not depend on the same provider, physical route, or other infrastructure as the primary connection.

Using the same company for home broadband and cellular backup does not guarantee that both services will fail together, because their network paths can differ. However, shared infrastructure or a broader provider outage can reduce the independence of those connections.

Households that need stronger uptime can consider a secondary provider or backup modem using a different mobile network. Greater diversity between primary and backup connections can reduce the chance that one failure removes every route online.

Iran-linked attacks add wider concern

The hacking claim cannot be confirmed as the cause of the AT&T outage, but it arrives within a broader pattern of Iran-linked activity against U.S. infrastructure. Federal agencies have warned about attacks against internet-exposed equipment used by water utilities.

The Cybersecurity and Infrastructure Security Agency, Environmental Protection Agency, Federal Bureau of Investigation, and National Security Agency have warned that Iran-affiliated actors have targeted industrial control equipment at water facilities.

Earlier incidents have included reported disruptions involving water systems across several states. The broader campaign has raised concerns because attackers can interfere with operational technology without compromising drinking water safety.

Telecom networks face growing pressure

APT IRAN’s August warning specifically named telecommunications alongside energy and water infrastructure. That makes the group’s later AT&T claim relevant to the broader threat environment, even though no public evidence establishes that it caused the September 7 outage.

Federal agencies have warned that Iranian-affiliated actors are actively targeting internet-connected operational technology used across critical infrastructure. Water-sector organizations have also called for stronger threat intelligence, technical support, cybersecurity funding, and information-sharing to help utilities defend these systems.

What connected homes can learn

The outage shows why internet dependence deserves attention when designing a connected home. Cameras, alarms, voice assistants, streaming devices, smart locks, and remote-work equipment can all lose important functions when connectivity disappears.

A resilient setup starts by identifying which devices require the internet and which can continue operating locally. Battery backups can keep networking equipment running temporarily, while a separate carrier can provide another route online during a provider-specific outage.

The event also shows why cyber risk is only one part of connectivity planning. Physical cable damage, construction accidents, equipment failures, severe weather, and theft can produce many of the same symptoms without involving a network breach.

Collection of smart home devices on a table.
Source: Depositphotos

TL;DR

  • AT&T’s September 7 outage affected thousands of North Texas customers. Downdetector user reports peaked at 5,990, while AT&T said its Dallas-area fiber outage affected more than 7,000 families.
  • AT&T says attempted cable theft caused the Dallas-area outage and that it found no evidence supporting claims that a cyberattack was responsible.
  • APT IRAN claimed responsibility online, but no public technical evidence has tied the Iran-linked actor to AT&T’s specific outage.
  • Backup internet connections are more resilient when they do not share the same provider, physical route, or other critical network dependencies.
  • Smart-home owners can improve resilience by using local device controls where available, backup power for networking equipment, and connectivity through independent network paths.

This article was made with AI assistance and human editing.

If you liked this, you might also like:

Source link

spot_img
spot_img

Leave a reply

Please enter your comment!
Please enter your name here