AT&T Agrees to $177 Million Settlement Over Two Major 2024 Data Breaches
AT&T will pay $177 million to settle lawsuits stemming from two significant customer data breaches in 2024 that exposed personal details and call records for millions.

AT&T has reached a $177 million settlement to resolve lawsuits arising from two major customer data breaches that occurred in 2024. The final approval for the settlement was granted by a federal judge on October 2, 2026, addressing privacy risks and potential financial harm to millions of current and former customers.
The settlement, approved by Judge Sidney A. Fitzwater of the U.S. District Court for the Northern District of Texas, allocates $149 million for the first incident and $28 million for the second. AT&T has not admitted any liability or wrongdoing as part of the agreement. These funds will also cover legal fees and administrative expenses associated with the settlement process.
The first breach, disclosed on March 30, 2024, involved customer information that appeared on the dark web. AT&T's investigation indicated that approximately 73 million individuals were affected, including 7.6 million current account holders and 65.4 million former account holders. The exposed data, which appeared to date from 2019 or earlier, could include names, addresses, phone numbers, birth dates, account passcodes, billing account numbers, and Social Security numbers.
At the time of the initial disclosure, AT&T stated it was still investigating the origin of the data, noting it had no immediate evidence of unauthorized access to its own systems and was exploring whether the information originated from a vendor. The scope of exposed data varied significantly among affected individuals.
The second breach, announced on July 12, 2024, stemmed from unauthorized access to an AT&T workspace hosted on Snowflake's cloud platform. This incident, which occurred between April 14 and April 25, 2024, impacted nearly all of AT&T's cellular customers. The compromised data included call and text records from May through October 2022, and some records from January 2, 2023.
While this second breach did not expose Social Security numbers or the content of communications, it did include phone numbers, interaction counts, call durations, and cell tower identifiers. AT&T acknowledged that this information could potentially be used to identify individuals through publicly available tools.
Under the terms of the settlement, eligible claimants from the first breach could receive up to $5,000 for documented losses, while those affected by the second breach could claim up to $2,500. Customers impacted by both incidents may be eligible for both, provided they can substantiate separate losses. Standard cash payments are estimated to be significantly lower, ranging from $6.50 to $40, with higher amounts reserved for those whose Social Security numbers were exposed.
The claim submission deadline has passed, and customers are advised to remain vigilant against phishing attempts that might leverage the leaked information and to monitor their accounts for any suspicious activity.