What's funny is that it wasn't an attack by anyone, Goatse Security discovered a vulnerability, notified AT&T of it, and when AT&T ignored the information (possibly trying to hide the breach), after a few days Goatse prodded AT&T to react by publishing the details.
http://security.goatse.fr/a-response-to-atts-letter
Now they're calling them "malicious hackers"... the idiocy.