AT&T Settlement: Claims Closed, Up to $7.5K Combined
Updated:
September 28, 2026
AT&T’s proposed $177,000,000 data breach settlement remains pending final court approval as of September 20, 2026. The combined class action covers two data incidents announced in 2024 involving personal information and customer call and text metadata.
AT&T Settlement Status — September 20, 2026
- Final approval: Pending. Judge Ada E. Brown held the final approval hearing on January 15, 2026. The case was reassigned to Senior District Judge Sidney A. Fitzwater on August 17, 2026.
- Claim window: Closed December 18, 2025.
- Deficiency response deadline: Passed on September 8, 2026. This deadline applied only to claimants who received a deficiency or settlement-class membership verification notice from Kroll.
- Payment date: Not announced. Payments remain dependent on final court approval.
Eligible class members who submitted claims by December 18, 2025 could receive compensation for documented losses or tiered cash payments. Final payouts will depend on court approval, claim validation, legal fees, and the number of approved claims.
The first incident affected approximately 7.6 million current customers and 65.4 million former customers. The second exposed call and text interaction records for nearly all AT&T wireless customers, and AT&T said it would notify around 110 million customers.
This article covers the settlement status, payout structure, breach timeline, affected data, attack methods, customer risks, AT&T’s response, government scrutiny, legal costs, and the remaining uncertainty around payment dates.
Bright Defense helps organizations reduce similar breach risks through Penetration Testing, Continuous Compliance, and Security Assessments focused on cloud security, access controls, and sensitive data protection.

What Happened in the Breach
AT&T disclosed on March 30, 2024 that “AT&T data specific fields” appeared in a data set posted on the dark web. AT&T said the source was still under assessment and that it did not yet know whether the data originated from AT&T or a vendor. The company said preliminary analysis showed the data appeared to be from 2019 or earlier and affected about 7.6 million current AT&T account holders and about 65.4 million former account holders.
AT&T then disclosed on July 12, 2024 that threat actors illegally accessed an AT&T workspace on a third-party cloud platform and exfiltrated files containing customer call and text interaction records. AT&T’s SEC filing said the records covered nearly all of its wireless customers and customers of mobile virtual network operators using its network; an AT&T spokesperson said the company would notify around 110 million customers. The second incident later became part of the combined settlement.

AT&T Settlement Update As Of September 2026
AT&T’s proposed $177 million class action settlement covering two data incidents announced in 2024 is still awaiting final court approval as of September 20, 2026.
Eligible class members who filed claims by December 18, 2025 could receive up to $5,000 for documented losses linked to the first incident and up to $2,500 for losses linked to the second.
People who qualify under both incidents could receive up to $7,500 in total, which combines the maximum amounts available under each incident rather than creating a separate payment tier.
Kroll Settlement Administration is reviewing and processing submitted claims. The official settlement site states that the January 15, 2026 final approval hearing has been held, but the court has not approved the settlement. Benefit distribution will begin only after final approval, the applicable appeal period, and claim review are complete. No payment date has been announced.
The September 8, 2026 deficiency response deadline has passed. It applied only to claimants who received a Notice of Deficient Claim Form or a request to verify settlement-class membership from Kroll. Claimants who received these notices were required to respond using the instructions provided by the Settlement Administrator.
How to Check Your AT&T Settlement Claim Status
The official settlement website provides case-wide updates, but it does not currently list a public self-service tracker for individual claims. For questions about a submitted claim, use Kroll’s official Contact Us form or call the Settlement Administrator at (833) 890-4930. Have your Class Member ID available if you have one.
If Kroll sent you a deficiency notice, follow the instructions in that notice. Use the portal link in an emailed notice or the mailing instructions in a paper notice; do not email supporting documents. The response deadline is September 8, 2026.
The official FAQ says not to contact the court, the clerk of court, or AT&T for settlement information.
AT&T Data Breach Settlement Payout Per Person
The AT&T data breach settlement has no fixed per-person payout as of September 2026. The $177 million fund is split into two pools: $149 million for the first breach and $28 million for the second. Class members in the first breach could claim up to $5,000 for documented losses occurring in 2019 or later, or a pro rata share of the net fund, with Social Security number exposure earning five times the standard share. Claims closed on December 18, 2025. The final approval hearing took place on January 15, 2026, and the court has not yet issued a final approval ruling. On August 17, 2026, the case was reassigned to Senior District Judge Sidney A. Fitzwater. No settlement payments have been distributed because final court approval remains pending.
Timeline: From First Access To Latest Update

The personal data tied to the first incident was described in reporting as originating from 2019 or earlier, while the call and text interaction data tied to the second incident covered May 1, 2022 through October 31, 2022, plus a smaller subset dated January 2, 2023.
AT&T announced the first incident on March 30, 2024, and said threat actors accessed the cloud workspace and exfiltrated files between April 14, 2024 and April 25, 2024, with the second incident publicly announced on July 12, 2024.
Lawsuits after the first incident were consolidated in June 2024 before Judge Ada E. Brown in the Northern District of Texas, and the parties later agreed in March 2025 to settle both incidents together in that court.
The official settlement website lists the claim deadline as December 18, 2025 and says the final approval hearing was held on January 15, 2026 at 9:00 a.m. CT. As of September 20, 2026, the court has not issued a final approval decision, and the Settlement Administrator continues to review and process claims.

What Data Or Systems Were Affected
Reporting on the first incident said the leaked data included sensitive personal information such as Social Security numbers and account passcodes, along with contact details, affecting about 7.6 million current customers and 65.4 million former customers.
AT&T’s SEC disclosure for the second incident said the files contained call and text interaction records for nearly all of its wireless customers and customers of mobile virtual network operators using its network. AT&T said it would notify around 110 million customers. The records did not include message content, but other reporting described re-identification risks.
Who Was Responsible (Confirmed Vs Alleged)
AT&T said it determined AT&T specific fields were in the dark web data set for the first incident, but it did not publicly identify a responsible actor and said the source was still being assessed, including whether a vendor was involved.
For the second incident, AT&T said threat actors unlawfully accessed an AT&T workspace hosted on Snowflake. Connor Riley Moucka pleaded guilty on August 5, 2026 to charges involving a wider cloud-hacking campaign that compromised more than 165 organizations. Federal court records and reporting have linked Moucka and co-defendant John Erin Binns to the Snowflake campaign that included AT&T, although the Justice Department’s guilty-plea announcement did not name AT&T. Moucka is scheduled to be sentenced on October 27, 2026.
How The Attack Worked
For the first incident, AT&T framed the event as the appearance of AT&T specific fields inside a larger data set posted on the dark web roughly two weeks before the March 30, 2024 announcement, and said investigators were still assessing the origin.
For the second incident, AT&T told investors that threat actors accessed the cloud workspace and exfiltrated files between April 14 and April 25, 2024. Federal prosecutors later said the wider cloud-hacking campaign involved stolen login credentials used to access customer environments hosted by a U.S. software-as-a-service provider. The stolen AT&T files contained call and text interaction records from the 2022 period described in its filing.

Impact and Risks for Customers
The first incident raised identity fraud and account takeover risks because exposed data reportedly included Social Security numbers and account passcodes. That type of data can support impersonation, SIM swap attempts, and targeted scams when paired with other available information.
The second incident involved communications metadata rather than message content. AT&T said the data did not include call or text content, but public sources can sometimes connect phone numbers to names.
A data exfiltration prevention strategy can detect unusual exports, restrict bulk access and stop sensitive metadata from leaving cloud or internal systems. Without these controls, attackers can use the information for link analysis, targeted phishing, harassment and social engineering.
Company Response And Customer Remediation
After the first incident, AT&T directed customers to account safety resources, reset passcodes for affected users in reporting, and said it would offer credit monitoring where applicable. AT&T continued to assess whether the data originated from AT&T or elsewhere.
After the second incident, AT&T said it activated incident response, retained external cybersecurity experts, took steps to close the illegal access point, and worked with law enforcement. AT&T said it understood that at least one person had been apprehended.
The settlement framework emphasizes documented loss claims and tiered cash payments. Self-prepared statements alone are insufficient under the settlement FAQ, and losses must be traceable to the relevant incident.
Maintaining audit readiness can help organizations preserve incident timelines, access logs, notification records, remediation evidence and other documentation needed during litigation or regulatory review.
Government, Law Enforcement, And Regulator Actions
AT&T said it worked with law enforcement after the second incident, and CISA issued an alert the same day as AT&T’s July 12, 2024 disclosure that pointed to official customer guidance.
US senators publicly questioned AT&T’s storage of call records on the third party platform after the July 2024 disclosure, reflecting political scrutiny even as the settlement process moved through federal court.
Financial, Legal, And Business Impact
The proposed settlement totals $177,000,000, split into a non reversionary $149,000,000 fund tied to the first incident and a non reversionary $28,000,000 fund tied to the second incident. Payments come from the net settlement funds after deductions approved by the court.
The “up to” headline numbers are tied to documented loss claims. AT&T 1 claimants may seek up to $5,000 for documented losses, and AT&T 2 claimants may seek up to $2,500 for documented losses. People eligible under both incidents may claim up to $7,500 combined, but that number stacks the two per incident maximums and is not a separate tier.
Many people instead fall into pro rata tiers. AT&T 1 Tier 1 payments are five times AT&T 1 Tier 2 payments when a Social Security number was included, and AT&T 2 offers a Tier 3 pro rata cash payment option for account owners. The actual net amount available depends on settlement administration costs, service awards, attorney fees, costs, taxes, and the number of valid claims.
Plaintiffs’ attorneys have requested approximately $59 million in combined fees. The request remains pending before Senior District Judge Sidney A. Fitzwater following the case's reassignment on August 17, 2026.
If approved, the Lanier team would receive $49.67 million in fees plus $564,792 in costs from the AT&T 1 fund. The Ostrow group would receive $9.33 million in fees plus $231,438 in costs from the AT&T 2 fund. Those fee and cost deductions would reduce the net funds available for class member payments, which helps explain why many pro rata payouts will likely fall below the stated maximums.
According to a January 2026 court filing cited by CT Insider, approximately 99.7 million settlement notices were sent and about 4.38 million claims had been submitted as of December 30, 2025. Actual payouts will depend on the number of claims Kroll validates and the amounts approved for fees, costs, taxes, and service awards.
What Remains Unclear About the Settlement
Payment timing remains the largest open issue. Distribution of benefits will begin only after the court grants final approval, the period for any appeals ends, and the administrator finishes reviewing the submitted claims. Judge Ada E. Brown held the final approval hearing on January 15, 2026. The case was reassigned to Senior District Judge Sidney A. Fitzwater on August 17, 2026, and the court has not yet issued a final approval ruling.
The earlier interlocutory appeal involving objectors Osa Massen, Audrey Jones, and Susan Savala is no longer pending. The Fifth Circuit dismissed the appeal on October 21, 2025, following a joint stipulation between the parties. A new appeal could still be filed after the district court issues its final approval decision, which could delay the distribution of settlement benefits.
Claim validation remains another unresolved part of the process. Claimants who received a deficiency notice had until September 8, 2026 to provide the requested information. That deadline has now passed.
Claimants asked for additional documented-loss evidence may receive payment only for substantiated losses or an applicable tiered payment. Final pro rata amounts will depend on the number of valid claims and the fees, costs, taxes, and service awards deducted from the settlement funds.
Why This Incident Matters
The AT&T incidents show how consumer harm can arise from both direct exposure of sensitive identifiers and indirect exposure of communications metadata, and the combined settlement is an unusually large telecom privacy resolution that will test how courts and administrators value documented losses versus standardized tiered payments.
The episode also highlights enterprise dependence on third party cloud platforms and the downstream legal exposure that follows when high volume customer data sits in environments targeted by credential theft and large scale data extraction. That dependence puts vendor risk management at the center of any plan to limit third party exposure.
Disclaimer: This Article Is for News and Informational Purposes Only. Bright Defense Is Not Affiliated With or Administering the AT&T Settlement and Does Not Process Claims or Provide Legal Advice.
How Bright Defense Can Help Reduce Similar Data Breach Risk
Bright Defense can help reduce exposure to data breaches like these through penetration testing that targets the paths attackers use to reach high value data stores, including cloud workspaces, identity and access flows, and third party integrations. Cloud penetration testing is the most direct way to probe the kind of cloud workspace that attackers reached in the second incident.
We typically focus testing on access control failures, credential abuse scenarios, and data exfiltration paths that security teams can miss during routine reviews. Closing those gaps is the core goal of data exfiltration prevention, which pairs detection with controls that stop large file transfers before they leave the network.
Bright Defense's continuous compliance program can also keep key controls current across systems that store regulated or high sensitivity data, with ongoing evidence collection and control checks that support SOC 2 and similar frameworks while teams ship changes.
Sources
- Telecom Data Incident Settlement — In Re: AT&T Inc. Customer Data Security Breach Litigation, Important Dates (accessed September 20, 2026)
- Telecom Data Incident Settlement — FAQ (accessed Septemeber 29, 2026)
- SEC.gov — AT&T Inc. Current Report on Form 8-K (filed July 12, 2024; report date May 6, 2024)
- AT&T Newsroom — AT&T Addresses Recent Data Set Released on the Dark Web (March 30, 2024)
- PR Newswire — AT&T Addresses Illegal Download of Customer Data (July 12, 2024)
- CISA — AT&T Discloses Breach of Customer Data (July 12, 2024)
- AP News — AT&T Notifies Users of Data Breach and Resets Millions of Passcodes (April 3, 2024)
- AP News — AT&T Reaches a $177 million Data Breach Settlement (November 14, 2025)
- Time — What AT&T Customers Impacted by the Major Data Security Breach Should Do Now (July 12, 2024)
- Investopedia — AT&T Says Nearly All Customers Were Affected by April Data Breach (July 12, 2024)
- Business Insider — AT&T Says Hackers Stole the Call and Text Records of Almost All Wireless Customers (July 12, 2024)
- CT Insider — AT&T Data Breach Settlement Nearing Approval; 4.38 Million Claims Filed (January 22, 2026)
- CT Insider — AT&T Data Breach Settlement Nears Approval; Attorneys Seek $59 Million in Fees (updated February 6, 2026)
- Business.CCH.com — AT&T Settlement Agreement PDF (May 30, 2025)
- U.S. Department of Justice — Canadian Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions (August 5, 2026)
- TechCrunch — AT&T Says Criminals Stole Phone Records of Nearly All Customers in New Data Breach (July 12, 2024)
- TechCrunch — Snowflake Hackers Identified and Charged With Stealing 50 Billion AT&T Records (November 12, 2024)


