AT&T has agreed to a $177 million class-action settlement following two significant data breaches that exposed sensitive customer information. The first breach, involving account files from 2019 or earlier, compromised data such as Social Security numbers, passcodes, and other identifiers for millions of current and former customers, with the stolen data later surfacing on the dark web. The second breach, attributed to a compromise of a third-party cloud platform hosted by Snowflake in 2022 and early 2023, exposed call and text metadata, including numbers contacted and cell site information, but not the content of communications. Both incidents affected tens of millions of users, and AT&T has notified those impacted.
The settlement is divided into two funds: $149 million for victims of the first breach and $28 million for those affected by the Snowflake-related incident. Eligible customers can claim up to $5,000 for the first breach and $2,500 for the second, with a maximum of $7,500 for those impacted by both. Higher payouts are reserved for individuals who can provide documentation of out-of-pocket losses, while others will receive a share of the remaining funds. The deadline to file a claim is December 18, 2025, and both current and former AT&T customers are encouraged to review their eligibility and submit claims online or by mail.

See attribution, scope, and your downstream exposure.
2 events from the most recent confirmed update back to the earliest known activity.
By mid-November 2025, public reporting said the deadline to file claims in the AT&T data breach settlement was nearing and that eligible customers could still apply for payouts of up to $7,500. The reports focused on how to submit claims rather than disclosing a new breach-related development.
AT&T reached a proposed $177 million settlement to resolve claims tied to a data breach affecting customers. The settlement created a process for eligible people to seek compensation, including reimbursement for documented losses.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.