AT&T will pay $177 million to settle lawsuits over two major customer data breaches disclosed in 2024, after a federal judge granted final approval on October 2, 2026. The agreement covers separate incidents that exposed personal details and call records, creating lasting privacy risks for millions of current and former customers.
Judge Sidney A. Fitzwater of the U.S. District Court for the Northern District of Texas approved the settlement, according to Bloomberg Law. AT&T settled without admitting liability or wrongdoing. The deal creates a $149 million fund for the first incident and a $28 million fund for the second, with legal fees and administrative costs also paid from those funds.
Two Breaches Exposed Different Customer Data
The first incident was announced on March 30, 2024, after customer information appeared on the dark web. AT&T’s initial assessment identified approximately 7.6 million current account holders and 65.4 million former account holders, totaling 73 million. The company said the records appeared to date from 2019 or earlier.
The exposed information varied by person and could include names, addresses, email addresses, phone numbers, birth dates, account passcodes, billing account numbers, and Social Security numbers. AT&T initially said it had no evidence that the dataset resulted from unauthorized access to its systems and was still investigating whether the information came from the company or a vendor.
The second breach, announced on July 12, 2024, involved records stolen from an AT&T workspace on Snowflake’s cloud platform. As previously covered in Cyber Security News’ report on the AT&T call-record breach, attackers accessed the workspace between April 14 and April 25, 2024. The incident affected nearly all AT&T cellular customers.
Those records covered calls and texts from May through October 2022, plus some records from January 2, 2023. They included phone numbers, interaction counts, total call durations, and some cell tower identifiers. Unlike the first incident, this breach did not expose Social Security numbers or the actual content of calls and messages.
The distinction is important because communication records can reveal relationships even without message content. AT&T acknowledged that public online tools could connect phone numbers to names. Cyber Security News also previously reported that AT&T paid approximately $370,000 to have stolen records deleted, although fragments could still remain elsewhere.
Under the official settlement terms, eligible claimants from the first incident can receive up to $5,000 for documented losses linked to that breach. Those affected by the second can receive up to $2,500. Customers affected by both may qualify for both payments, but must provide separate evidence and cannot claim the same loss twice.
These maximum amounts are not automatic payouts. Standard cash payments are expected to be much smaller, with reported estimates ranging from $6.50 to $40 depending on the payment tier. Claimants whose Social Security numbers were exposed qualify for a higher tier than those whose other details were leaked.
The claim deadline passed on December 18, 2025, so customers cannot submit new claims through the closed process. Payments depend on claim review and the appeals process, with no confirmed distribution date reported. Customers should follow official updates, monitor their accounts, and remain alert to phishing messages that exploit the leaked information.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC

