Connect with us
Tech
>

AT&T DATA BREACH: What, How and What to Do

Published

on

at&t data breach settlement

Two data breaches occurred in 2024 — each resulting in the exposure of data from over 100 million customers. The first breach involved AT&T, but the details are unclear because those logs were deleted after a judicial ruling stating that they should be preserved for one year as evidence in an unrelated case. Find out what was stolen, who committed the crime and how to find out if you were a victim.

Navigate to:

AT&T is the second largest telecommunications company in America, so what occurred in 2024 was impressive. During the year, the company reported two different data breaches affecting more than 100 million cFront and ex-owners. The first was highly sensitive information like Social Security numbers languishing on the dark web for years until AT&T finally admitted it. And the other, it shows, exposes to some degree all of the call and text records for almost every wireless customer that company has.

If you are or were an AT&T customer, there is a good possibility your information was sucked into at least one of these breaches. Here’s what we know about both breaches, who took what and from where and what you can do with that information.

The Data Breach: Two Data Breaches in 2024

The 2024 AT&T story is effectively two stories running in parallel. They are also separate because they involved different data, different timelines and different risk levels which makes understanding them as a whole or individually the important part.

The Dark Web Breach (Revealed in March 2024)

March 2024: A dataset of more than 73 million records with personal information was available for sale on a dark web forum. Among them were 7.6 million current AT&T account holders, plus 65.4 million former customers. The data contained various combinations of Social Security numbers, dates of birth, account passcodes, full names, email/mailing addresses, phone numbers and AT&T account numbers.

AT&T initially said the data was not from its systems, a claim it made since a hacker widely known as “ShinyHunters” first claimed to have obtained it in 2021. Although AT&T had failed to react until it was direct with the proof, on April 2, 2024 AT&T confirmed that a data breach took place even though passcodes in the leak dataset were encrypted using an “easily long term” sustap as demonstrated by seasoned security researcher after which all affected current customers opposed to timely cleanup and updated their passcodes.

The data this breach has compromised are all from 2019 or before. AT&T said the source of the data, whether it was from its servers or that of an unnamed third-party vendor, remains unproven.

If on the other hand, you find it hard to get a fresh password Pro Tip: The random password generator generates something strong that’s difficult to crack.

The Snowflake Breach (Reported July 2024)

The second breach, reported on July 12, 2024, was broader than the first at least in terms of how many people were affected. AT&T announced that hackers had illegally downloaded records from the US telecom firm’s workspace on third-party cloud data platform Snowflake over a period of time between April 14 and April 25, 2024. Exfiltrated data spanned the calls and texts of almost all (109 to 110 million) U.S. wireless customers who used AT&T during a six-month period from May 1 through October 31, 2022, with some records extending to January 2, 2023.2

The data in this breach are of a different kind than that in the first. Names, Social Security numbers and any financial information were not included. This wasn’t content, it was metadata: the numbers called or texted, the duration of such calls and, in some cases even before a lesson learned from Google Maps, identifiers for cell towers recording locations within.

AT&T discovered the breach on April 19 of this year. It was not disclosed to the public until July 12 as the Department of Justice deemed national security concerns necessitated a delay in announcing a breach [0]. Officials were especially worried about the sensitivity of call log data. One cybersecurity expert pointed out that knowing to whom government officials or military personnel are contacting is just as revealing as what those calls contain.

Who Was Responsible?

The hack an attack has been assigned the code UNC5537, which refers to the group perpetrated as Scattered Spider and previously known as ShinyHunters. The attackers utilized no flaw in the Snowflake platform itself. Instead, they stole the login credentials of Snowflake customer accounts using infostealer malware and then logging in directly with those handover credentials — often because accounts had not been secured with multi-factor authentication.

This was one of at least 160 organizations attempted by the campaign against AT&T. Other victims were also Ticketmaster, Santander Bank, and Advance Auto Parts and Neiman Marcus. The attackers pulled the records of the calls and texts out of AT&T’s Snowflake environment and contacted AT&T about making a payment for it afterwards. Bloomberg cited its own reporting that AT&T paid due to the stolen data being deleted, paying around $370,000 in Bitcoin. 3

Since then, two people have been arrested accused of running the Snowflake campaign. On 28 November, a man from Ontario, Canada was arrested — this suspect, Connor Moucka (26 years trold), is not to be confused with the next suspect. The other individual, 24-year-old John Erin Binns of Turkey who was arrested in a different case and charged with multiple counts associated with the 2021 T-Mobile breach The two are accused of having accessed billions of private client records across at least dozens of companies inquiring $2.5 million each from the victims.

Note: The March 2024 dark web leak is not confirmed as having been released yet. AT&T has not to identify an attacker by name and said it has also have not determined definitively that the data resided within its infrastructure or with a third-party vendor.

How the Breaches Were Discovered and Resolved

The dark web dataset was first recorded publicly in March 2024 when it appeared on a criminal forum, although the breach reportedly occurred as far back as 2021 or even earlier. Security researcher Jon Callas explained that AT&T’s account passcodes were encrypted but used a scheme so weak they could be quickly reversed. That discovery accelerated AT&T’s response. The company reset the passcodes of all affected current customers and began to notify those impacted within days.

On April 19, 2024, AT&T discovered an internal breach of its Snowflake database connected to the threat actor saying that it had stolen customer call logs. The company quickly initiated its incident response process and engaged third-party cyber security experts. AT&T also locked down the point of unauthorised access to its Snowflake environment after confirming the breach. An investigation began at the Federal Communications Commission and the FBI and Department of Justice were involved “from an early point,” with the Justice Department deciding on two occasions that delaying public disclosure was in the interest of national security until AT&T filed its SEC disclosure July 12, 2024.

The $177 Million Settlement and the Lawsuits

Each data breaches led to a barrage of class action lawsuits filed in state and federal courts around the country. The lawsuits were later consolidated into two multi-district proceedings.

AT&T consented to a $177 million settlement in 2025, resolving both lawsuits. The settlement consisted of two pools – $149 million for dark web breach customers (announced March 2024) and $28 million for Snowflake breach customers (announced July 2024). Preliminary approval was given by a federal judge on June 20, 2025.

Customers can get up to $5,000 in losses from the first hack as well as $2,500 in losses from the second. A total of $7,500 available for those affected by both breaches. Deadline for claims: November 18, 2025 AT&T denied wrongdoing in the settlement, saying the data breaches were criminal acts committed against the company.

Note that the stolen data kept to bumble about. Repackaged copies of the original breach records were sold once more on dark web marketplaces in June 2025, with sellers merging data from different breaches to make more complete and usable profiles. A spokesperson for AT&T said that the 2025 entries looked like resold data sets from earlier leaks, not evidence of a new hack.

Please, keep your personal data out of the Internet

Incogni is a data removal service that tracks your personal information online and sends automated takedown requests on your behalf.

What Can You Do to Know Whether or not You Were Affected

Check Your AT&T Account Directly

AT&T customers can go online to check if their data was part of either leak, as long as they are using an AT&T account. Anyone who was a customer when Snowflake breached should have received an AT&T text, email or mail which included their account number and case number to enroll in the free years of monitoring.

Use Have I Been Pwned

My only caution with the free tool Have I been pwned (haveibeenpwned. com) features a box where you can type your email address to see if it has been found in any of the databases for known breaches, including that of AT&T. It won’t reveal the details behind each individual data breach and which records have been indexed, but it will let you know whether your address was found in any breaches.

The password manager we ranked as one of the best in our tests, RoboForm also has you covered—you can scan login credentials against a listing from Have I Been Pwned to see if they have been breached.

Monitor Your Credit Reports

Because Social Security numbers were exposed in the March 2024 breach, one of the most important steps you should take is to monitor your credit. All three major bureaus will let pull free reports at AnnualCreditReport. com. Search accounts or requests not recognized.

Consider a Credit Freeze

It keeps new credit from being set up in your name without your say-so. It’s completely free to place and lift at any of the three major bureaus (Equifax, Experian, or TransUnion), a simple and powerful way to help prevent identity theft following exposure of your Social Security number.

Beware of phishing and impersonation attacks

The metadata of the calls leaked in Snowflake breach provides criminals with detailed information about who you communicate with, how often and when. Which renders social engineering as much easier. If you receive an unsolicited call or text, even if it claims to be AT&T, your bank or family member, proceed with skepticism — never give a person that called you personal information or one-time codes over the phone.

Reset AT&T Passcode and Account Password

Even if AT&T preemptively reset your passcode after the March 2024 breach, it would be wise to create a new one yourself and also ensure your account password is strong and unique. Many users re-use their credentials on other sites, change those passwords as well.

About Your Data After the Breach

One thing to understand about breaches like this is that the data doesn’t just evaporate into thin air. This is repackaged, sold, bundled with records from other breaches and traded on criminal markets for years. And even customers who have taken steps to safeguard account names and passwords find their data reappearing in new contexts.

That is one of the reasons why reducing your data footprint is important even after a security breach has been solved. Incogni is the process of sending removal requests against data brokers retailers that publish databases with personal information in them It won’t reverse a breach, but it can help keep the amount of your zip that is still accessible to people who want to create a profile of you. It is something to ponder since it has been a while since data on the AT&T breach have come out.

The Bottom Line

Summary of AT&T Breaches from 2024The AT&T breaches were some of largest data security events in the history of the United States. In the time between the two events, data on at least 100 million current and former customers were compromised including everything from Social Security numbers to details on whom people called and texted over a six-month period. Arrests have been made in relation to the Snowflake breach, a $177 million settlement has been reached, and AT&T says it has shut down the access points used in the attack.

However, the data is still available. If your were an AT&T customer before 2020 or had wireless service from May to October 2022 then you should consider your information compromised. None of the above steps requires technical skills to execute, and they all make a good start for execution.

Frequently Asked Questions

If I had no relationship with AT&T, was my data exposed in the breach?

Possibly, yes. Snowflake breach sucked up metadata of calls and texts made to or from AT&T customer numbers which means even non-AT&T users who called or texted someone on the AT&T network within that time frame may also have had their phone numbers stolen as well. They do not contain the contents of calls, but are able to identify number information and timing. Your number is almost certainly listed in the dataset if you typically messaged anyone using AT&T services between May and October 2022.

AT&T data breachWhat information was stolen and who is affected?

They had two breaches of much different types of data. The breach dating back to March 2024 leaked sensitive data for nearly 73 million individuals, including Social Security numbers, dates of birth, account passcodes, full names and email addresses, mailing addresses and AT&T account numbers. The Snowflake breach in July 2024 only consisted of metadata from calls and texts: records of which numbers contacted one another, when, for how long, and sometimes the cell tower used — which gives an approximate location. The breach did not contain names, Social Security numbers or other financial data.

AT&T Data Breach Settlement: Is It Too Late to File a Claim?

If you had $177 million AT&T settlement claim deadline was November 18, 2025 so the time window to file a claim has passed. Impacted customers, however, should stay tuned for settlement administration updates from Kroll Settlement Administration, which is handling settlements. It may be worth consulting a consumer protection attorney about your options if you feel that you were eligible but did not submit a claim.

Was AT&T aware of the data breach?

In both breaches, AT&T promised to inform affected customers by text, email or U.S. mail. Notifications for March 2024 breach started as early as the beginning of April 2024. On July 2024 Snowflake breach, a notification including an account number and a case number was issued to affected customers. If you think you’re impacted and didn’t get a notice, the safest option is logging into your AT&T account to check if your information was exposed.

How can someone with access to stolen call records use them against me?

Call metadata is more sensitive than it may seem. Details of who you phoned and when allow criminals to discover how you relate to each of your employers, family members, financial institutions–and health care providers. The fact is that this information makes social engineering attacked much more convincing – a scammer knowing you spoke with your bank three times last month can make their impersonation far more believable. Some records also contain cell tower data, which can be used to get a rough idea of when and where you were during the time covered in the breach. The caution that experts have exercised has been especially directed at the consequences for those engaged in private or delicate work.

theurbanmatter.com

Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Advertisement