Andrew Auernheimer was sentenced to 41 months in federal prison on March 18, 2013, for his role in accessing AT&T’s iPad registration servers and obtaining information tied to approximately 120,000 iPad 3G users. The case involved email addresses paired with ICC-IDs—not passwords or payment-card details—and ended with three years of supervised release and $73,162 in restitution.
Who was the AT&T hacker?
Andrew Auernheimer, 27, of New York, was sentenced in Newark federal court. Prosecutors said he and a partner accessed AT&T servers without authorization and provided the collected information to a Gawker reporter. The FBI’s March 18, 2013 announcement described the case as involving approximately 120,000 Apple iPad users.
What information did the incident expose?
The script collected pairings of users’ email addresses and their iPad 3G ICC-IDs, or Integrated Circuit Card Identifiers. An ICC-ID identifies a SIM card. The exposed information was not described in the official announcement as passwords or financial account data. Gawker published a redacted list after receiving the pairings; the FBI release says the defendants supplied the information to the outlet.
How did the Account Slurper work?
AT&T’s registration system used a web address that included an ICC-ID in plain text and returned the email address associated with that identifier. The defendants’ script, called the “iPad 3G Account Slurper,” mimicked an iPad and tried ranges of ICC-IDs to retrieve matching email addresses.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minute#1 Best Overall
- The script sent requests that appeared to come from an iPad.
- It varied ICC-ID values in the registration-site URL, effectively guessing identifiers in exposed ranges.
- When the system returned an associated email address, the script collected the ICC-ID/email pairing.
- The collection ran from June 5 through June 9, 2010, and produced approximately 120,000 pairings, according to the FBI announcement.
This was web-application enumeration: the system disclosed information in response to predictable identifier values. It was not described as a SIM-swapping attack.
What did the court sentence Auernheimer to?
On March 18, 2013, the court imposed 41 months in prison, followed by three years of supervised release, and ordered $73,162 in restitution. The FBI’s announcement says Auernheimer was convicted of conspiring to access AT&T servers without authorization and disclose information to a Gawker reporter, as well as possessing and transferring means of identification involving more than 120,000 users.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How was the data disclosed, and why did it matter?
The pairings were given to Gawker, which published them in redacted form. At the time, the publication reported that the exposed information could leave users vulnerable to spam and malicious hacking. The case illustrates why predictable identifiers in a web address can become a privacy risk when a service uses them to retrieve personal information without adequate safeguards.
The episode concerns a 2010 intrusion and a 2013 sentence. It should not be confused with later AT&T data incidents or SIM-swapping cases, which involve different methods and facts.
Quick Recap
Best Value
Rank #4
Rank #3
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

