AT&T to Pay $177 Million to Settle Two Data Breaches Affecting Over 100 Million Customers

The CyberSec Guru

AT&T to Pay $177 Million for Data Breaches

If you like this post, then please share it:

Buy me A Coffee!

Support The CyberSec Guru’s Mission

🔐 Fuel the cybersecurity crusade by buying me a coffee! Why your support matters: Zero paywalls: Keep the main content 100% free for learners worldwide.

“Your coffee keeps the servers running and the knowledge flowing in our fight against cybercrime.”☕ Support My Work

Buy Me a Coffee Button

AT&T has agreed to pay $177 million to resolve consolidated class-action lawsuits over two customer data breaches disclosed in 2024. U.S. District Judge Sidney A. Fitzwater of the Northern District of Texas granted final approval on October 2, 2026, as Bloomberg Law first reported. It is one of the largest telecom data breach payouts in U.S. history. The two incidents exposed personal information, Social Security numbers, and call-and-text metadata for well over 100 million current and former subscribers. AT&T settled without admitting liability or wrongdoing, which is standard, and which also means no trial where its internal security practices would have been examined under oath.

The $177 million splits into two funds. The first, $149 million, covers legacy account records that surfaced on the dark web. The second, $28 million, covers call-detail records stolen from a Snowflake cloud workspace. Legal fees, administrative costs, and claims processing come out of the same pools, so consumers will receive materially less than the headline number.

The first breach: 73 million records with SSNs, passcodes, and billing data

AT&T confirmed on March 30, 2024 that a dataset of customer information was for sale on dark-web forums. Its forensic assessment found about 7.6 million current account holders and roughly 65.4 million former account holders affected, around 73 million people in total. The records appeared to date from 2019 or earlier. That means the data may have sat in an unauthorized environment for years, possibly exfiltrated long before it surfaced, without anyone detecting or disclosing it.

Depending on the record, the leaked fields included full names, residential and mailing addresses, email addresses, phone numbers, dates of birth, AT&T account passcodes (the numeric PINs customers use to authenticate with support agents), billing account numbers, and for some people, Social Security numbers. The SSNs are what make this breach dangerous. Unlike a password, an SSN cannot be rotated. Once it circulates on criminal marketplaces, the owner faces synthetic identity fraud, tax fraud, medical identity theft, and unauthorized credit applications for decades.

AT&T’s early statements were cautious. The company said it had “no evidence” the dataset came from unauthorized access to its own systems, and that it was still investigating whether the data came from AT&T infrastructure or from a third-party vendor. That ambiguity matters from an architecture standpoint. Telecom operators work with contractors, billing processors, marketing analytics partners, and legacy system integrators, and any of them could be an exfiltration path. The data was already years old at disclosure, which makes attribution harder: log retention at AT&T or a vendor may have cycled out the relevant access records long before the dataset appeared.

The second breach: Snowflake workspace compromise exposes call and text metadata

AT&T disclosed the second incident on July 12, 2024. Attackers got into a dedicated AT&T workspace on Snowflake’s cloud data platform and exfiltrated records of calls and texts for nearly all of AT&T’s cellular customers. The access window was short, April 14 through April 25, 2024, but the workspace held an enormous amount of data. The stolen records cover May 2022 through October 2022, plus a smaller subset from January 2, 2023.

The extracted fields include the phone numbers involved in each interaction, the number of calls and messages, total call durations, and in some records the cell tower identifiers that can approximate where a subscriber was during a call. According to AT&T, the data did not include Social Security numbers, call audio, or message text. Researchers and privacy advocates pointed out that missing content does not mean missing harm. Metadata often reveals more than content does. Repeated late-night calls to one number, combined with tower data, can reconstruct relationship graphs, medical consultations, contact with lawyers, political organizing, and journalist-source relationships, with a precision that content-based surveillance often cannot match.

AT&T acknowledged that readily available online tools could map the exposed phone numbers to the people behind them. It also confirmed, as Cyber Security News first reported, that it paid about $370,000 to a threat actor to delete the stolen records. Incident responders disagree about paying for deletion. It may shrink the pool of records on criminal forums, but nothing verifies that destruction is complete, and copies or derivative datasets can persist across dark-web marketplaces, Telegram channels, and private criminal networks. I would treat the payment as harm reduction, not remediation.

The Snowflake angle deserves a closer look. Snowflake is a widely used cloud data warehouse that enterprises use to consolidate and query large structured and semi-structured datasets. The AT&T compromise happened during a broader 2024 campaign against multiple Snowflake customers, which relied on stolen credentials rather than a zero-day in Snowflake’s platform code. In May 2024, Snowflake disclosed that a “small number” of customer accounts had been accessed with previously compromised credentials, and it later required multi-factor authentication on all accounts. AT&T’s timeline matches that campaign. That points to credential stuffing or infostealer-harvested logins, though this is my inference. In this case the perimeter was the identity layer, and one compromised credential with enough privilege can open petabytes of structured customer data.

Settlement structure: who gets what

Judge Fitzwater’s approval creates two compensation tracks. Claimants affected by the first breach can receive up to $5,000 in documented out-of-pocket losses attributable to that incident. Those affected by the second can receive up to $2,500. People hit by both, a large overlap given AT&T’s customer base, can file under both tracks. They need separate evidence for each and cannot claim the same documented loss twice.

📬 Stay Ahead of Cyber Threats

Get the latest cybersecurity news, critical vulnerabilities, threat intelligence, tutorials, and exclusive giveaways delivered straight to your inbox. No spam. Unsubscribe anytime.

Subscribe to the Newsletter →

Those figures are ceilings, and nobody receives them automatically. The maximum goes to claimants who can document financial harm, such as identity-theft remediation costs, unauthorized charges traced to the breach, or credit-freeze fees. Claimants who filed without documented losses are expected to receive far less. Legal analysts tracking the settlement estimate typical payments of $6.50 to $40, tiered by data sensitivity. Claimants whose SSNs were in the leaked dataset fall in a higher tier than those whose exposure was limited to names, addresses, or phone numbers.

The claim-filing deadline passed on December 18, 2025. The settlement is now in claims review and adjudication, followed by any appeals. No distribution date has been announced. Timing will depend on claim volume, how complicated the loss documentation is, and whether objectors appeal the terms. Affected consumers should watch official settlement communications and the AT&T settlement website, and ignore third-party notifications. Phishing operators routinely pose as settlement administrators.

Why these breaches matter beyond AT&T

Both incidents reflect weaknesses common across telecom and any industry that aggregates personal data and behavioral metadata in centralized cloud environments. Carriers hold billing records, real-time communication patterns, location histories, and social-graph data, all of which intelligence agencies, law enforcement, and criminal groups value. The FCC’s Customer Proprietary Network Information rules set obligations for carriers on subscriber data. Cloud migration, third-party analytics integrations, and legacy system decommissioning still create a sprawling attack surface that is very hard to secure completely.

The first breach is a retention problem. Records from 2019 or earlier raise the question of why such data was still accessible and exfiltratable years after the accounts were closed or changed. Data minimization, keeping personal information only as long as operationally or legally necessary, is central to the EU’s GDPR and appears in U.S. state laws such as the CCPA. Every retained record is a liability that grows over time.

The second breach reinforces what the industry has said since at least SolarWinds in 2020: identity is the perimeter. Multi-factor authentication, hardware security keys, just-in-time privileged access, and continuous authentication telemetry are baseline hardening for any organization holding sensitive customer data. The Snowflake campaign succeeded mainly through credential theft, which suggests the weak point was endpoint hygiene and credential management at the customer organizations, not Snowflake’s engineering. Enterprises assessing their own exposure should audit every cloud-platform account, enforce phishing-resistant MFA, review data-access logs for anomalous bulk exports, and ask whether the volume and sensitivity of data in any single workspace is justified.

What affected AT&T customers should do now

The claim window has closed, but the security work for affected people has not. For the 73 million in the first breach, especially those whose SSNs were included, a credit freeze with Equifax, Experian, and TransUnion is the most effective step against unauthorized credit applications. A fraud alert is weaker but adds a verification layer that can slow opportunistic identity theft. Enrolling in the IRS Identity Protection PIN program also helps. It issues a unique six-digit number required to file a federal tax return, which limits tax fraud built on stolen SSNs.

The second breach carries a different threat. The exposed call and text metadata can feed social engineering, targeted phishing, and pretexting. An attacker who knows which numbers you call most, when you call them, and which towers your phone connected to can write a convincing message posing as a family member, a healthcare provider, or a lawyer. Treat unsolicited messages that reference your call patterns, or that push urgency around account verification, with suspicion.

Everyone affected should also expect secondary phishing. After high-profile breach disclosures, criminals send fraudulent emails, SMS messages, and robocalls impersonating the company or the settlement administrator to harvest more personal information or payments. AT&T has said it will not ask for sensitive information by unsolicited email or text in connection with the settlement. Treat any “breach settlement” message asking for an SSN, bank account number, or payment credentials as fraud.

Privacy advocates and regulators will likely see $177 million as a cost of doing business, given the scale of harm. The FTC has signaled closer scrutiny of data security at major carriers, and the FCC keeps enforcement authority under Section 222 of the Communications Act, which governs the confidentiality of customer proprietary network information. Whether the FCC brings enforcement actions, consent decrees, or further civil penalties is an open question, though the political appetite for telecom accountability has grown since 2024.

At the state level, attorneys general in multiple jurisdictions have pursued independent investigations into large-scale breaches, and the patchwork of state breach-notification and consumer-protection laws means AT&T could face exposure beyond this settlement. The Texas Attorney General’s office, since the case was heard in the Northern District of Texas, and the California Privacy Protection Agency, given the size of AT&T’s California subscriber base and its enforcement powers under the CCPA and CPRA, are both possible sources of further action.

The settlement’s structure reflects how hard it is to resolve two technically distinct breaches in one proceeding. It uses separate funds for separate incidents, tiered payouts by data sensitivity, and separate evidence for overlapping claims. Plaintiffs’ counsel built a framework meant to compensate harm in proportion, without a windfall for claimants whose exposure was limited to a phone number or mailing address. Whether that proportion is adequate given the lifelong risk of SSN exposure will stay debated in privacy circles. Once the settlement is final and distributed, it bars further individual litigation against AT&T over these incidents.

What the settlement shows

The $177 million settlement closes a legal file. It also puts three problems on the record. Telecom’s move to the cloud has outpaced the maturity of the identity and access controls that protect the data stored there. Holding legacy customer data far past its operational use creates a breach surface that can go off years after collection. And attackers have growing reasons to target telecom metadata, as communication-pattern data gains value in both criminal and geopolitical settings.

For consumers, the payout is a modest, delayed acknowledgment of harm that cash cannot fully repair. An SSN exposed in 2024 is still a vulnerability in 2034. A call-log dataset that was exfiltrated may resurface on a dark-web forum in five years, deletion payment or not. The burden of managing that risk falls on the people whose data was exposed, not on the company that failed to protect it.

For the industry, the baseline is clear: cloud-workspace segmentation, zero-trust access, automated data classification and lifecycle management, phishing-resistant authentication at every layer, and rigorous third-party vendor assessments. Any organization holding the communication records and identity documents of tens of millions of people needs them. The $177 million is likely a fraction of the long-term cost of these breaches.

This article will be updated if the distribution timeline, regulatory actions, or related proceedings change. For official settlement status, consult the court-approved settlement website directly, and be cautious with unsolicited communications that mention the AT&T breach.

Buy me A Coffee!

Support The CyberSec Guru’s Mission

🔐 Fuel the cybersecurity crusade by buying me a coffee! Your contribution powers free tutorials, hands-on labs, and security resources.

Why your support matters:
  • Writeup Access: Get complete writeup access within 12 hours
  • Zero paywalls: Keep the main content 100% free for learners worldwide

Perks for one-time supporters:
☕️ $5: Shoutout in Buy Me a Coffee
🛡️ $8: Fast-track Access to Live Webinars
💻 $10: Vote on future tutorial topics + exclusive AMA access

“Your coffee keeps the servers running and the knowledge flowing in our fight against cybercrime.”☕ Support My Work

Buy Me a Coffee Button

If you like this post, then please share it:

News

Discover more from The CyberSec Guru

Subscribe to get the latest posts sent to your email!

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Discover more from The CyberSec Guru

Subscribe now to keep reading and get access to the full archive.

Continue reading