AT&T
Disclosed Mar 19, 20242 years ago110,000,000 affectedConfirmed
Call and text records of nearly all AT&T wireless customers stolen via Snowflake
AT&T disclosed that attackers accessed its workspace on a third-party cloud platform between April 14 and 25, 2024 and exfiltrated records of calls and texts from May to October 2022 and January 2, 2023 for nearly all of its wireless and MVNO customers. The Justice Department approved delaying the disclosure twice; AT&T said it would notify about 110 million customers.
What is known
| People affected | 110,000,000 (as reported by the organization) |
|---|---|
| Disclosed | Mar 19, 2024 |
| Discovered | Mar 26, 2024 |
| Happened | Mar 26, 2024 |
| Attack | Credential stuffing |
| Data exposed | Names, Dates of birth, Emails, Government IDs, Phone numbers, Addresses, Location, Other |
| Sector | Telecom · US |
| Status | Confirmed |
| Lawsuit or fine | $177M class action settlement covering this and the March 2024 dataset incident (preliminary approval June 2025) |
| Part of | Snowflake (2024) |
| Check your email | Have I Been Pwned |
Sources
| Source | |
|---|---|
| California Attorney General breach notice: AT&Toag.ca.gov · Official notice | Official notice |
| Washington Attorney General breach notice: AT&Tatg.wa.gov · Official notice | Official notice |
| Notice letter filed with the Delaware DOJ: AT&Tattorneygeneral.delaware.gov · Official notice | Official notice |
| Oregon DOJ breach notice: AT&Tjustice.oregon.gov · Official notice | Official notice |
| AT&T Inc. Form 8-K, Item 1.05 (2024-07-12)sec.gov · SEC filing | SEC filing |
| Have I Been Pwned: AT&Thaveibeenpwned.com · Aggregator | Aggregator |
| AT&T says criminals stole phone records of 'nearly all' customers in new data breachtechcrunch.com · News | News |
| Indiana Attorney General 2024 data breach report: AT&Tin.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| Have I Been Pwnedaccounts in the data | Mar 19, 2024 | 49,102,176 |
| California AGresidents of CA | Apr 9, 2024 | |
| Indiana AGresidents of IN | Apr 9, 2024 | 1,437,078 |
| Washington AGresidents of WA | Apr 10, 2024 | 378,471 |
| Oregon DOJresidents of OR | Apr 10, 2024 | 51,226,382 |
| Delaware DOJresidents of DE | Apr 25, 2024 | 50,469 |
| SEC 8-Ktotal | Jul 12, 2024 | |
| Researchtotal | Jul 12, 2024 | 110,000,000 |
Same campaign
Other breaches at AT&T
| Breach | Affected | ||||
|---|---|---|---|---|---|
| Dark web data set covers 73 million current and former AT&T account holdersJul 13, 20233 years ago | Jul 13, 20233 years ago | Not stated | Telecom | Confirmed | 73M |
| Disclosed Jun 11, 2014Jun 11, 201412 years ago | Jun 11, 201412 years ago | Not stated | Tech | Confirmed | Unknown |
| AT&T website flaw leaks email addresses of 114,000 iPad 3G ownersJun 9, 201016 years agoHackingUnverified | Jun 9, 201016 years ago | Hacking | Telecom | Unverified | 114K |
History of this record
- 2026-09-25 · notice_affected: empty to or-doj: 51226382 (restored: the portal's own figure) · correction source
- 2026-09-25 · notice_affected: or-doj: 51226382 to · correction source
- 2026-09-25 · source: empty to https://www.in.gov/attorneygeneral/consumer-protection-division/id-theft-prevention/files/DB-Year-to-Date-Reportdec-2024.pdf · backfill source
- 2026-09-25 · campaign: empty to snowflake-2024 · seed source
- 2026-09-25 · lawsuit: empty to $177M class action settlement covering this and the March 2024 dataset incident (preliminary approval June 2025) · seed source
- 2026-09-25 · sector: tech to telecom · seed source
- 2026-09-25 · attack: lost-device to credential-stuffing · seed source
- 2026-09-25 · data_types: ["names","dob","emails","government-id","phone","addresses"] to ["names","dob","emails","government-id","phone","addresses","location","other"] · seed source
- 2026-09-25 · records: 51226382 to 110000000 · seed source
- 2026-09-25 · summary: In March 2024, tens of millions of records allegedly breached from AT&T were posted to a popular hacking forum . Dating back to August 2021, the data was originally posted for sale before later being freely released. At the time, AT&T maint to AT&T disclosed that attackers accessed its workspace on a third-party cloud platform between April 14 and 25, 2024 and exfiltrated records of calls and texts from May to October 2022 and January 2, 2023 for nearly all of its wireless and MV · seed source
- 2026-09-25 · title: Material cybersecurity incident reported to the SEC (8-K Item 1.05) to Call and text records of nearly all AT&T wireless customers stolen via Snowflake · seed source
- 2026-09-25 · hibp: empty to AllegedATT · backfill source
- 2026-09-25 · data_types: ["names"] to ["names","dob","emails","government-id","phone","addresses"] · backfill source
- 2026-09-25 · disclosed: 2024-04-09 to 2024-03-19 · backfill source
- 2026-09-25 · summary: empty to In March 2024, tens of millions of records allegedly breached from AT&T were posted to a popular hacking forum . Dating back to August 2021, the data was originally posted for sale before later being freely released. At the time, AT&T maint · backfill source
- 2026-09-25 · title: empty to Material cybersecurity incident reported to the SEC (8-K Item 1.05) · backfill source
- 2026-09-25 · data_types: [] to ["names"] · backfill source
- 2026-09-25 · records_basis: empty to organization · backfill source
- 2026-09-25 · records: empty to 51226382 · backfill source
- 2026-09-25 · attack: unknown to lost-device · backfill source
- 2026-09-25 · discovered: empty to 2024-03-26 · backfill source
- 2026-09-25 · occurred: empty to 2024-03-26 · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.