Operation Get JetBlue / The AT&T iPad Breach (2010) - Wikipedia Style Blog

Operation Get JetBlue / The AT&T iPad Breach (2010)

From your cybersecurity history blog, the free encyclopedia

The 2010 AT&T iPad breach (sometimes internally referred to by its perpetrators under monikers like Operation Get JetBlue) was a high-profile data exposure incident involving the extraction of approximately 114,000 email addresses and ICC-ID numbers belonging to early adopters of the Apple iPad 3G.

The extraction was executed by members of the grey-hat hacker collective known as Goatse Security, primarily Andrew "weev" Auernheimer and Daniel Spitler. Instead of breaching a firewall or stealing a database, the group exploited a publicly accessible, unauthenticated web endpoint on AT&T's servers. The subsequent FBI investigation, arrests, and legal battles sparked a massive national debate regarding the limits of the Computer Fraud and Abuse Act (CFAA) and what legally constitutes unauthorized computer access.

The AT&T vulnerability

In early 2010, Apple released the first-generation iPad. At the time, AT&T was the exclusive US carrier providing 3G data services for the device. To make the process of logging into the AT&T network seamless for iPad users, the telecom giant implemented a convenience feature on their web servers.

When an iPad communicated with AT&T's network, it transmitted its ICC-ID (Integrated Circuit Card Identifier), which is essentially the unique serial number of the SIM card. AT&T's servers would receive this ICC-ID and automatically respond by displaying the user's associated email address in plain text on a login page. Goatse Security discovered that this specific web script lacked any form of authentication. Anyone who sent a valid ICC-ID to the AT&T web server would be handed the corresponding customer's email address, no password required.

The "iPad 3G Account Slurper"

To exploit this vulnerability at scale, Daniel Spitler wrote a PHP script that the group dubbed the "iPad 3G Account Slurper." Because ICC-IDs are largely sequential and follow a predictable mathematical pattern, the Slurper script didn't need to guess random strings.

The script was designed to generate thousands of potential ICC-IDs and systematically send HTTP requests to the exposed AT&T URL. Because the endpoint lacked rate-limiting—a standard security practice that prevents a single IP address from making thousands of requests per minute—the script ran unimpeded. Over the course of a few days in June 2010, the group harvested approximately 114,000 paired ICC-IDs and email addresses.

Exposure via Gawker

Unlike traditional cybercriminals who might sell such a database on the black market, Goatse Security chose a different route. Seeking to publicly shame AT&T for their poor security practices, the group packaged the harvested data and shared it with the media outlet Gawker.

On June 9, 2010, Gawker published an explosive article titled "Apple's Worst Security Breach: 114,000 iPad Owners Exposed." The revelation caused an immediate media storm. AT&T swiftly shut down the vulnerable endpoint, but the damage to their reputation—and the perceived security of the newly launched iPad—was already done.

High-profile victims

The story gained massive traction largely due to the list of early iPad adopters. Because the device was expensive and highly sought-after, the exposed list read like a "who's who" of American elite. Gawker noted that the leaked emails included those of then-White House Chief of Staff Rahm Emanuel, New York City Mayor Michael Bloomberg, ABC News anchor Diane Sawyer, film executive Harvey Weinstein, and numerous CEOs and high-ranking military officials.

FBI investigation and CFAA debate

The public exposure triggered an immediate criminal investigation by the FBI. In early 2011, Andrew Auernheimer and Daniel Spitler were arrested and charged with conspiracy to access a computer without authorization under the federal Computer Fraud and Abuse Act (CFAA), as well as identity theft.

The prosecution of Auernheimer became a flashpoint in the cybersecurity community. Legal scholars, digital rights groups like the EFF (Electronic Frontier Foundation), and security researchers argued fiercely that Auernheimer and Spitler had not "hacked" anything in the traditional sense. They had merely sent automated requests to a publicly available URL that AT&T had failed to secure. Critics argued that prosecuting individuals for accessing a public webpage criminalized standard security research and set a dangerous precedent for internet users.

Conviction and vacatur

Despite the widespread controversy regarding the application of the CFAA, Daniel Spitler pleaded guilty in June 2011. Andrew Auernheimer chose to go to trial. In November 2012, a federal jury in New Jersey found Auernheimer guilty on all charges. He was subsequently sentenced to 41 months in federal prison and ordered to pay $73,000 in restitution to AT&T.

Auernheimer appealed the decision. In April 2014, the Third Circuit Court of Appeals officially vacated his conviction. However, the court did not rule on the heavily debated merits of whether accessing a public URL constituted a CFAA violation. Instead, the court vacated the sentence on the grounds of improper venue: Auernheimer was in Arkansas, Spitler was in California, the AT&T servers were in Texas and Georgia, and none of the data extraction actually occurred in New Jersey (where the trial was held). Following the ruling, Auernheimer was released from prison.