Skip to main content
Breach Signal

Breach report

Telecom

AT&T

AT&T Says Data on 73 Million Customers Leaked on Dark Web

A dataset containing Social Security numbers and account passcodes for roughly 73 million current and former AT&T customers surfaced on a hacking forum, forcing the carrier to reset millions of passcodes after years of denials.

Reported by SecurityWeek

Records exposed

73M

About 73 million current and former account holders

Scale vs. largest on file

When
2024 (data dates to 2019 or earlier; first advertised 2021)
How they got in
Data theft of undetermined origin (AT&T or vendor), later leaked on dark web
Sector
Telecom

On March 30, 2024, AT&T confirmed that a dataset circulating on the dark web contained personal information tied to about 73 million current and former account holders, including roughly 7.6 million active customers and 65.4 million former ones. The data had been posted publicly on a hacking forum about two weeks earlier, and AT&T said it appeared to date from 2019 or earlier.

The disclosure reversed years of denials. In 2021, a well-known hacking group had advertised what it said was AT&T customer data for sale, and the company maintained at the time that the records did not come from its systems. When the full dataset was dumped in March 2024, researchers were able to match entries to real customers. AT&T said it still could not determine whether the data originated from its own systems or from one of its vendors, and it reported no evidence of unauthorized access leading to the theft.

The exposed fields varied by person but included names, email and mailing addresses, phone numbers, dates of birth, AT&T account numbers and, for many victims, Social Security numbers. The leak also contained account passcodes, the numeric codes used to authenticate customers, prompting AT&T to reset passcodes for all 7.6 million affected active accounts. The company said the data did not include financial information or call history, and it offered credit monitoring where applicable.

The incident drew multiple class-action lawsuits, which were later consolidated with litigation over a separate 2024 AT&T breach involving call records stored on the Snowflake cloud platform. In 2025, AT&T agreed to a combined settlement of about $177 million covering both incidents, with the larger share earmarked for victims of the 73 million-record leak.

The case illustrates how a breach can remain unresolved for years. Data first advertised in 2021 stayed in criminal circulation until it resurfaced in full, and customers were not notified in the meantime. It also shows the lasting value of static identifiers: records several years old still carried Social Security numbers that could fuel identity fraud. For consumers, the episode reinforced the case for credit freezes and for changing carrier passcodes periodically.

More from the wire

More in Telecom.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.