Updated:
July 15, 2026
AT&T Data Breach Settlement Offers Up To $5k in Claims – (Updated July 2026)
AT&T’s proposed $177,000,000 data breach settlement remains pending final court approval as of July 2026. The combined class action covers two separate 2024 incidents involving personal information and customer call and text metadata. Eligible claimants may seek compensation for documented losses, though final payouts will depend on court approval, claim validation, legal fees, and the number of approved claims.
The incidents affected approximately 7.6 million current customers and 65.4 million former customers, while the second breach exposed records from an AT&T cloud workspace. This article covers the settlement status, payout structure, breach timeline, affected data, attack methods, customer risks, AT&T’s response, government scrutiny, legal costs, and the remaining uncertainty around payment dates.
Bright Defense helps organizations reduce similar breach risks through Penetration Testing, Continuous Compliance, and Security Assessments focused on cloud security, access controls, and sensitive data protection.

What Happened in the Breach
AT&T disclosed on March 30, 2024 that “AT&T data specific fields” appeared in a data set posted on the dark web. AT&T said the source was still under assessment and that it did not yet know whether the data originated from AT&T or a vendor. The company said preliminary analysis showed the data appeared to be from 2019 or earlier and affected about 7.6 million current AT&T account holders and about 65.4 million former account holders.
AT&T then disclosed on July 12, 2024 that threat actors illegally accessed an AT&T workspace on a third party cloud platform and exfiltrated files containing customer call and text interaction records. The second incident later became part of the combined settlement.

AT&T Settlement Update As Of July 2026
AT&T’s proposed $177,000,000 class action settlement over two 2024 data incidents remains pending final court approval as of early July 2026. Eligible claimants may seek up to $5,000 for documented losses tied to the first incident and up to $2,500 for documented losses tied to the second incident. People eligible under both incidents may claim up to $7,500 combined, but that figure is the sum of the two per incident maximums rather than a separate benefit tier.
Kroll Settlement Administration is the settlement administrator reviewing and processing claims. The official settlement site says the January 15, 2026 final approval hearing has already been held, the court has not yet approved the settlement, and benefit distribution will begin only after court approval, the appeal period, and claim review are complete. No payment date has been announced.
AT&T Data Breach Settlement Payout Per Person
The AT&T data breach settlement has no fixed per-person payout as of July 2026. The $177 million fund is split into two pools: $149 million for the first breach and $28 million for the second. Class members in the first breach could claim up to $5,000 for documented losses occurring in 2019 or later, or a pro rata share of the net fund, with Social Security number exposure earning five times the standard share. Claims closed on December 18, 2025. The final approval hearing took place on January 15, 2026, and Judge Ada Brown has not yet issued a ruling, so no payments have been distributed
Timeline: From First Access To Latest Update
The personal data tied to the first incident was described in reporting as originating from 2019 or earlier, while the call and text interaction data tied to the second incident covered May 1, 2022 through October 31, 2022, plus a smaller subset dated January 2, 2023.
AT&T announced the first incident on March 30, 2024, and said threat actors accessed the cloud workspace and exfiltrated files between April 14, 2024 and April 25, 2024, with the second incident publicly announced on July 12, 2024.
Lawsuits after the first incident were consolidated in June 2024 before Judge Ada E. Brown in the Northern District of Texas, and the parties later agreed in March 2025 to settle both incidents together in that court.
The official settlement website now lists the claim deadline as December 18, 2025 and says the final approval hearing was held on January 15, 2026 at 9:00 a.m. CT. As of July 1, 2026, the court has not decided whether to approve the settlement, and the Settlement Administrator is reviewing and processing claims.
What Data Or Systems Were Affected
Reporting on the first incident said the leaked data included sensitive personal information such as Social Security numbers and account passcodes, along with contact details, affecting about 7.6 million current customers and 65.4 million former customers.
AT&T’s SEC disclosure for the second incident said files contained records of customer call and text interactions, and other reporting described risks of re identification even without message content.
Who Was Responsible (Confirmed Vs Alleged)
AT&T said it determined AT&T specific fields were in the dark web data set for the first incident, but it did not publicly identify a responsible actor and said the source was still being assessed, including whether a vendor was involved.
For the second incident, AT&T said threat actors unlawfully accessed an AT&T workspace on a third party cloud platform, and settlement materials describe the platform as hosted by Snowflake, with broader public reporting linking the event to the wider Snowflake related wave of intrusions in 2024.
How The Attack Worked
For the first incident, AT&T framed the event as the appearance of AT&T specific fields inside a larger data set posted on the dark web roughly two weeks before the March 30, 2024 announcement, and said investigators were still assessing the origin.
For the second incident, AT&T told investors that threat actors accessed the cloud workspace and exfiltrated files during the April 14, 2024 to April 25, 2024 window, and the stolen files contained call and text interaction records from the 2022 period described in its filing.

Impact and Risks for Customers
The first incident raised identity fraud and account takeover risks because exposed data reportedly included Social Security numbers and account passcodes. That type of data can support impersonation, SIM swap attempts, and targeted scams when paired with other available information.
The second incident involved communications metadata rather than message content. AT&T said the data did not include call or text content, but public data sources can sometimes connect phone numbers to names. That makes link analysis, targeted phishing, harassment, and social engineering more practical for attackers.
Company Response And Customer Remediation
After the first incident, AT&T directed customers to account safety resources, reset passcodes for affected users in reporting, and said it would offer credit monitoring where applicable. AT&T continued to assess whether the data originated from AT&T or elsewhere.
After the second incident, AT&T said it activated incident response, retained external cybersecurity experts, took steps to close the illegal access point, and worked with law enforcement. AT&T said it understood that at least one person had been apprehended.
The settlement framework emphasizes documented loss claims and tiered cash payments. Self prepared statements alone are insufficient under the settlement FAQ, and losses must be traceable to the relevant incident.
Government, Law Enforcement, And Regulator Actions
AT&T said it worked with law enforcement after the second incident, and CISA issued an alert the same day as AT&T’s July 12, 2024 disclosure that pointed to official customer guidance.
US senators publicly questioned AT&T’s storage of call records on the third party platform after the July 2024 disclosure, reflecting political scrutiny even as the settlement process moved through federal court.
Financial, Legal, And Business Impact
The proposed settlement totals $177,000,000, split into a non reversionary $149,000,000 fund tied to the first incident and a non reversionary $28,000,000 fund tied to the second incident. Payments come from the net settlement funds after deductions approved by the court.
The “up to” headline numbers are tied to documented loss claims. AT&T 1 claimants may seek up to $5,000 for documented losses, and AT&T 2 claimants may seek up to $2,500 for documented losses. People eligible under both incidents may claim up to $7,500 combined, but that number stacks the two per incident maximums and is not a separate tier.
Many people instead fall into pro rata tiers. AT&T 1 Tier 1 payments are five times AT&T 1 Tier 2 payments when a Social Security number was included, and AT&T 2 offers a Tier 3 pro rata cash payment option for account owners. The actual net amount available depends on settlement administration costs, service awards, attorney fees, costs, taxes, and the number of valid claims.
Pending court approval, the Lanier team would receive $49.67 million in fees plus $564,792 in costs from the AT&T 1 fund. The Ostrow group would receive $9.33 million in fees plus $231,438 in costs from the AT&T 2 fund. Those fee and cost deductions would reduce the net funds available for class member payments, which helps explain why many pro rata payouts will likely fall below the stated maximums.
Recent reporting said more than 99 million notices were sent and about 4.38 million claims were filed. That claim volume means many payouts will likely be far below the maximums after Kroll validates claims and calculates pro rata shares.
What Remains Unclear About the Settlement
As of the latest updates reflected on the settlement site and recent reporting, the timing of payments remains uncertain because benefits generally begin only after final court approval and any appeals window closes, and the administrator still needs to process claim volume and documentation.
The acceptance of late claims also remains uncertain, because the settlement FAQ says it cannot guarantee late claims will be accepted after the deadline, and pro rata results will depend on how many claims survive validation and what the court approves for fees and costs.
Why This Incident Matters
The AT&T incidents show how consumer harm can arise from both direct exposure of sensitive identifiers and indirect exposure of communications metadata, and the combined settlement is an unusually large telecom privacy resolution that will test how courts and administrators value documented losses versus standardized tiered payments.
The episode also highlights enterprise dependence on third party cloud platforms and the downstream legal exposure that follows when high volume customer data sits in environments targeted by credential theft and large scale data extraction. That dependence puts vendor risk management at the center of any plan to limit third party exposure.
How Bright Defense Can Help Reduce Similar Data Breach Risk
Bright Defense can help reduce exposure to data breaches like these through penetration testing that targets the paths attackers use to reach high value data stores, including cloud workspaces, identity and access flows, and third party integrations. Cloud penetration testing is the most direct way to probe the kind of cloud workspace that attackers reached in the second incident.
We typically focus testing on access control failures, credential abuse scenarios, and data exfiltration paths that security teams can miss during routine reviews. Closing those gaps is the core goal of data exfiltration prevention, which pairs detection with controls that stop large file transfers before they leave the network.
Bright Defense’s continuous compliance program can also keep key controls current across systems that store regulated or high sensitivity data, with ongoing evidence collection and control checks that support SOC 2 and similar frameworks while teams ship changes.
Sources
- Telecom Data Incident Settlement — In Re: AT&T Inc. Customer Data Security Breach Litigation, Important Dates (February 9, 2026)
- Telecom Data Incident Settlement — FAQ (February 9, 2026)
- SEC.gov — AT&T Inc. Current Report on Form 8-K (May 6, 2024)
- AT&T Newsroom — AT&T Addresses Recent Data Set Released on the Dark Web (March 30, 2024)
- PR Newswire — AT&T Addresses Illegal Download of Customer Data (July 12, 2024)
- CISA — AT&T Discloses Breach of Customer Data (July 12, 2024)
- AP News — AT&T Notifies Users of Data Breach and Resets Millions of Passcodes (April 3, 2024)
- AP News — AT&T Reaches a $177 million Data Breach Settlement (November 14, 2025)
- Time — What AT&T Customers Impacted by the Major Data Security Breach Should Do Now (July 15, 2024)
- Investopedia — AT&T Says Nearly All Customers Were Affected by April Data Breach (July 12, 2024)
- Business Insider — AT&T Says Hackers Stole the Call and Text Records of Almost All Wireless Customers (July 12, 2024)
- CT Insider — AT&T Data Breach Settlement Nearing Approval, Claims Filed (February 9, 2026)
- CT Insider — AT&T Settlement Nears Approval, Attorney Fees Request (February 9, 2026)
- Business.CCH.com — AT&T Settlement Agreement PDF (May 30, 2025)
Get In Touch


