Back to Blog
Breach Alert

AT&T Data Breach 2024: What 73 Million Customers Need to Know

April 2, 2024 6 min readBy David S. Harris, Esq.

In early 2024, AT&T confirmed one of the most significant data breaches in U.S. telecom history — affecting approximately 73 million current and former customers. If you received an AT&T data breach notification letter, you are likely among those affected. This article explains what happened, what data was exposed, and how you can protect yourself and pursue compensation.

What Happened in the AT&T Data Breach?

AT&T disclosed that a dataset containing personal information of approximately 7.6 million current account holders and 65.4 million former account holders was released on the dark web in March 2024. The data appeared to be from 2019 or earlier. AT&T launched an investigation to determine whether the breach originated from AT&T itself or one of its vendors.

The company confirmed the data was authentic but had not been able to determine the precise origin of the leak at the time of initial disclosure. This kind of ambiguity is unfortunately common in large telecom breaches — it doesn't reduce your legal rights.

What Data Was Exposed?

According to AT&T's own notification, the compromised data included some or all of the following categories depending on the individual:

  • Full name
  • Home address
  • Phone number
  • Date of birth
  • AT&T email address
  • Social Security numbers (for a subset of affected accounts)
  • AT&T account numbers
  • AT&T passcodes (encrypted, but potentially decryptable)

The exposure of Social Security numbers and passcodes in the same dataset is particularly serious. These two pieces of information together give criminals the tools to commit financial fraud, open new accounts in your name, and access your existing telecom services without your knowledge.

How AT&T Responded

AT&T reset the passcodes for all affected current customers and began notifying affected individuals by letter. The company stated it was working with cybersecurity experts to investigate the scope of the breach. AT&T also said it would reach out to all 73 million customers whose data appeared in the dataset.

While these are reasonable steps, a passcode reset does not undo the damage already done by the exposure — particularly for customers whose Social Security numbers were included in the leak.

Immediate Steps If You Received an AT&T Breach Letter

  1. Place a fraud alert or credit freeze with all three major bureaus — Equifax, Experian, and TransUnion. A freeze is free and prevents new credit lines from being opened in your name.
  2. Change your AT&T passcode if you haven't already, and update your PIN on your AT&T account.
  3. Review your AT&T bill for unauthorized charges or new lines added to your account.
  4. Monitor your credit reports at AnnualCreditReport.com for any accounts or inquiries you don't recognize.
  5. Keep the notification letter. It documents your status as an affected individual, which is relevant to any legal claim.

Your Legal Rights After the AT&T Breach

The scale of this breach — 73 million people — makes it a strong candidate for class action litigation. When a company the size of AT&T fails to protect data of this sensitivity, federal and state consumer protection laws may entitle affected customers to compensation beyond what the company voluntarily offers.

Compensation in data breach class actions typically includes reimbursement for out-of-pocket costs related to the breach, compensation for time spent dealing with its consequences, and in some states, statutory damages — meaning a set dollar amount per affected consumer regardless of actual losses.

You do not need to prove you were a victim of identity theft to participate in a class action. The unauthorized exposure of your personal data itself is the harm the law recognizes.

Frequently Asked Questions

I'm a former AT&T customer — am I affected?

Yes. Of the 73 million affected accounts, approximately 65.4 million belong to former customers whose data was held in AT&T's systems even after they closed their accounts. If you received a notification letter at any address associated with a former AT&T account, you are likely included.

AT&T offered me free identity monitoring — should I accept?

Accepting any free monitoring offered by AT&T does not waive your legal rights to pursue a claim. Take the monitoring if it's available to you — it's a useful protective measure. It does not substitute for a formal legal remedy for the exposure itself.

What if I didn't receive a letter but think I was affected?

Check your email (including spam) for AT&T communications. You can also contact AT&T directly to ask whether your account was among the affected. If you were a customer any time before 2019, there is a meaningful chance your data was in the exposed dataset.

Related: Search the Breach Registry · What Is a Breach Notification Letter? · Get a Free Case Review

Think You May Have a Claim?

The Law Office of David S. Harris offers free consultations — no fee unless we win.

Made with AI in Macaly