AT&T agreed to pay $177 million to resolve a class action lawsuit over two data breaches disclosed in 2024, with $149 million set aside for customers whose Social Security numbers and other personal data leaked to the dark web and $28 million for customers whose call and text records were stolen through a cloud vendor. The AT&T data breach settlement received final court approval in January 2026, but the deadline to file a claim has already passed, and the administrator was still reviewing claims and had not yet distributed payments as of mid-2026.
If you did not file by December 18, 2025, you are no longer eligible to receive money from this settlement. If you did file, the sections below explain what you signed up for and where things stand.
What the Settlement Covers
The lawsuit consolidated dozens of cases into a single multidistrict litigation in the Northern District of Texas, In Re: AT&T Inc. Customer Data Security Breach Litigation, MDL Docket No. 3:24-md-03114-E, before Judge Ada Brown.1U.S. District Court, Northern District of Texas. MDL 3:24-md-03114 Two separate incidents drove the case.
The first was disclosed on March 30, 2024, when AT&T confirmed that a dataset with customer information had surfaced on the dark web. Roughly 73 million people were affected — about 7.6 million current account holders and 65.4 million former customers. The exposed information included names, email addresses, mailing addresses, phone numbers, dates of birth, Social Security numbers, AT&T account numbers, and account passcodes.26ABC Philadelphia. AT&T Data Breach $177 Million Settlement The data appeared to date from 2019 or earlier.3AT&T. Addressing Data Set Released on Dark Web
The second was disclosed on July 12, 2024. Hackers had illegally downloaded call and text records for nearly all of AT&T’s wireless customers, plus customers of mobile virtual network operators that use AT&T’s network and some landline customers. About 110 million customers were affected. The stolen records covered May 1 through October 31, 2022, and a single additional day, January 2, 2023, and included the phone numbers customers called or texted, the number of interactions, and aggregate call durations. For a subset of records, cell site identification numbers were also taken, which can reveal a customer’s general location. The actual content of calls and texts was not exposed, and neither were names, Social Security numbers, or credit card numbers.4Cybersecurity Dive. AT&T Cyberattack Snowflake Environment The breach happened through AT&T’s workspace on Snowflake, a third-party cloud storage platform, between April 14 and April 25, 2024.5Computer Weekly. AT&T Loses Nearly All Phone Records in Snowflake Breach
Who Was Eligible
The settlement created two classes. The AT&T 1 class covered all living U.S. residents whose personal data was included in the March 2024 dark web breach. Within that class, Tier 1 members were those whose Social Security numbers were exposed. Tier 2 members had other personal information exposed but not their Social Security numbers.
The AT&T 2 class covered account owners, line users, and end users whose call and text records were part of the Snowflake breach. Account owners could submit claims on behalf of their line users and end users.6Telecom Data Settlement. Telecom Data Settlement
Anyone who qualified for both classes was considered an “overlap” member and could file claims under each.7CCH Cybersecurity Privacy. AT&T Settlement Agreement
How Much Claimants Could Get
Claimants in each class could choose between two payment types.
If you could document specific financial losses traceable to the breach, such as identity theft costs or fraudulent charges, you could claim up to $5,000 for the first breach and up to $2,500 for the second. Overlap members with documented losses from both incidents could potentially recover up to $7,500 combined.8Time. AT&T Data Breach Settlement: How to File a Claim
The alternative was a flat cash payment drawn from each fund’s remaining balance after administrative costs and attorneys’ fees. For the first breach, Tier 1 members with exposed Social Security numbers were set to receive five times the amount paid to Tier 2 members, reflecting the higher identity theft risk that comes with a Social Security number leak. For the second breach, account owners could claim a Tier 3 payment, a pro rata share of the AT&T 2 fund.6Telecom Data Settlement. Telecom Data Settlement Actual per-person amounts depend on how many valid claims are approved, so final figures were not known at the time claims were filed.
Deadlines and Current Status
Judge Brown granted preliminary approval on June 20, 2025.9U.S. District Court, Northern District of Texas. Preliminary Approval Order Kroll Settlement Administration began mailing notices to class members in August 2025.10CPM Legal. CPM Announces Settlement of AT&T Data Breach The claims deadline was originally November 18, 2025, and the court later extended it to December 18, 2025. The deadline to opt out or object was November 17, 2025.11Pensacola News Journal. Deadline AT&T Data Breach Settlement Application
The final approval hearing was held on January 15, 2026. The settlement has received full and final court approval, and all court proceedings are complete.12AT&T Mobility Settlement. AT&T Mobility Settlement As of mid-2026, the settlement administrator was still reviewing claims, and payments had not yet been distributed to class members.6Telecom Data Settlement. Telecom Data Settlement
One outstanding wrinkle: before preliminary approval was granted, three individuals named Osa Massen, Audrey Jones, and Susan Savala filed a motion to intervene and oppose the settlement. Judge Brown denied the motion without prejudice on June 20, 2025, and the trio filed a notice of interlocutory appeal to the Fifth Circuit on July 21, 2025.13CourtListener. In Re AT&T Inc. Customer Data Security Breach Litigation Docket
The Separate FCC Penalty Is Not This Settlement
A common source of confusion: in September 2024, AT&T agreed to pay a $13 million civil penalty to settle a Federal Communications Commission investigation into a January 2023 vendor breach that affected approximately 8.9 million AT&T Mobility customers. That money went to the U.S. Treasury as a civil penalty, not to consumers, and the FCC required AT&T to appoint a compliance officer, implement an information security program aligned with the NIST Cybersecurity Framework, tighten vendor oversight, and conduct annual audits.14FCC. In the Matter of AT&T Services Inc., Consent Decree The FCC action was a separate incident from the two breaches in this class action, and no customer claim process came out of it.