AT&T Outage Disrupts Texas Internet While Hackers Make Unsubstantiated Cyberattack Claims

APT IRAN said on Telegram that it had attacked telecommunications and an unidentified water utility in Texas, and vowed to intensify its attacks through Sept. 11.
Downdetector recorded an initial wave of outage reports around 2:15–2:18 a.m. Monday, followed by a second surge in the afternoon; reports peaked at nearly 6,000 shortly before 3 p.m. and the outage was mostly resolved by about 6 p.m.
AT&T said customers affected by a qualifying outage lasting 20 minutes or more would be eligible for a bill credit.
The disruption affected more than home internet: some customers reported losing cellular data and backup connectivity as well. Denton County resident Terry Snuggs said the outage left him unable to work as a clinical systems engineer supporting hospital diagnostic-imaging systems.
The outage reports were geographically broader than Dallas alone, with large clusters recorded in Houston, Spring, Fort Worth and Austin; Houston customers had also reported service problems as early as Sunday.
An Iranian-linked hacker group called APT IRAN claimed responsibility for a widespread AT&T fiber outage that knocked out internet service for thousands of customers across Texas on Monday. Cybernews reported the group said it had attacked telecommunications and water utilities in the state. AT&T disputed the claim, WFAA reported, saying initial evidence points to attempted cable theft rather than a cyberattack. More than 7,000 households lost service, with outage reports peaking near 6,000 around 3 p.m. before service was mostly restored by 6 p.m.
The outage extended beyond home internet. Fox4News reported that some customers lost cellular data and backup connectivity as well. One Denton County resident, Terry Snuggs, said the disruption left him unable to work as a clinical systems engineer supporting hospital diagnostic-imaging systems. AT&T said customers whose outage lasted 20 minutes or longer would receive bill credits.
Downdetector first recorded outage reports around 2:15 a.m. Monday, WFAA reported. A second wave of complaints surged in the afternoon, with reports peaking at nearly 6,000 shortly before 3 p.m. The disruption affected major Texas cities including Dallas, Houston, Spring, Fort Worth, and Austin. Some Houston customers had already reported service problems as early as Sunday.
APT IRAN, linked to Iran's IRGC-affiliated CyberAv3ngers group, announced on Telegram that it attacked Texas telecommunications and water utilities, Cybernews reported. The group vowed to intensify attacks through September 11. However, CBS19 reported that AT&T said it has no evidence of a cyberattack. AT&T's initial assessment instead points to attempted cable theft as the cause.
The attribution remains disputed and unverified. The group's public claim creates strategic risk even without confirmed technical evidence. APT IRAN has separately threatened attacks on U.S. telecommunications, water, and other critical infrastructure, underscoring broader vulnerability concerns across multiple sectors.
Damaged fiber cables disrupt more than internet. Customers also lost telephone service, television, and cellular backup connectivity simultaneously. This cascading failure happens because modern infrastructure concentrates many services on single routes. Whether caused by cable theft or malicious hacking, the damage to buried or aerial fiber creates identical service collapse.
Critical systems depending on continuous connectivity were directly threatened. Hospital networks, diagnostic equipment, and business operations lost connectivity when backup systems failed. This shows that infrastructure resilience requires protecting both cyber defenses and physical security, plus maintaining true network redundancy.
Public attack announcements before politically significant dates can serve purposes beyond technical operations. Threats attract media attention, pressure operators to divert defensive resources, and amplify fear even when individual incidents remain unverified. Fox4News reported the group's public deadline and escalation language, showing disruption claims function as influence tools.
Organizations cannot rely on temporary vigilance around single dates. Instead, they need sustained monitoring, tested response plans, and coordinated recovery procedures. The AT&T incident illustrates that critical infrastructure depends on continuous security assessment across physical, cyber, and operational-technology layers.
Publishers
13
Articles
15
Reach
28