The AT&T data breach settlement is a $177 million class action deal that would compensate tens of millions of current and former customers for two separate 2024 breaches. A federal judge in Texas gave preliminary approval in June 2025 and held the final approval hearing on January 15, 2026, but as of the settlement administrator’s April 23, 2026 update, no ruling has been issued and no payments have gone out.1
Who Is Covered
The settlement resolves claims from two incidents, and the fund is split accordingly. Roughly 6.2 million people were affected by both, and those overlap class members could file two separate claims.
The AT&T 1 Fund holds $149 million and covers the March 2024 dark web leak, which exposed data on about 73 million current and former account holders. Claimants break into two tiers. Tier 1 covers people whose Social Security numbers were exposed and pays five times the Tier 2 rate. Tier 2 covers people whose other personal data was exposed but whose Social Security numbers were not. Anyone with documented financial losses traceable to the breach could instead claim up to $5,000.
The AT&T 2 Fund holds $28 million and covers the July 2024 Snowflake breach, which affected roughly 36.4 million people whose call and text metadata was stolen. Account owners qualify for a Tier 3 pro rata payment, or they could seek up to $2,500 for documented losses incurred on or after April 14, 2024.
Overlap class members who filed both claims with unique documentation could receive up to $7,500 combined.
How Much Individual Payments Will Be
By the December 30, 2025 reporting deadline, Kroll Settlement Administration had received approximately 4.38 million claims, a 4.8 percent claim rate. Plaintiffs’ attorneys described that rate as higher than the majority of data breach class actions Kroll has administered, but with roughly 57 million people eligible for the AT&T 1 class and 36.4 million for the AT&T 2 class, the share of people claiming is still small enough that per-person payouts could be meaningful.
Exact amounts are not yet known. They depend on how many of the 4.38 million claims survive Kroll’s review, how many are documented-loss claims versus tier claims, and whether the court approves the deal in the form the parties submitted.
The Claim Deadline Has Passed
If you didn’t already file, you cannot join the settlement now. The deadlines set under the amended scheduling order were:
- November 17, 2025: opt out or file objections.
- December 18, 2025: submit claims online or by mail.
- January 15, 2026: final approval hearing.
Kroll is reviewing submitted claims while the court considers final approval.
What Still Has To Happen Before Payments Go Out
The six-hour final approval hearing took place as scheduled on January 15, 2026. According to reporting by the Greenwich Time and New Haven Register, it included debate over the different settlement classes, the opt-out policy, and the attorneys’ fee requests. As of April 23, 2026, Judge Ada Brown has not ruled, and the settlement administrator has said it does not know how long the court will take.
Three things must happen before money moves:
- Judge Brown grants final approval.
- The appeals period expires without a successful challenge.
- Kroll finishes processing all claims.
AT&T originally expected final approval by the end of 2025 with payments in early 2026. That timeline has already slipped once, and there is no new projected payment date.
One boundary worth knowing: this settlement is purely monetary. AT&T is not required to make any cybersecurity improvements or policy changes as part of the deal. A separate $13 million FCC consent decree, announced September 17, 2024, addresses a different January 2023 breach and imposes security requirements on the company, but it is not part of this class action and does not pay affected customers.
Attorneys’ Fees Still Pending
Plaintiffs’ counsel requested approximately $59 million in fees, roughly one-third of the total settlement. The Lanier Law Firm, lead counsel for the larger AT&T 1 case, sought $49.67 million in fees plus up to $564,792 in litigation costs. Kopelowitz Ostrow Ferguson Weiselberg Gilbert, lead counsel for the AT&T 2 class, sought $9.33 million in fees plus up to $231,438 in costs. Attorneys argued in filings that the case was highly complex and that fees of 25 to 35 percent of a settlement fund are standard in class action litigation. Whether those fees are approved is part of Judge Brown’s pending decision, and the outcome affects how much of the $177 million is left for claimants.
What Happened in Each Breach
Understanding which fund applies to you starts with what was taken.
The March 2024 Dark Web Leak
On March 30, 2024, AT&T confirmed that a dataset containing customer information had surfaced on the dark web. The data appeared to date from 2019 or earlier and affected roughly 73 million people: about 7.6 million current account holders and 65.4 million former ones. Exposed information included names, email addresses, mailing addresses, phone numbers, dates of birth, Social Security numbers, AT&T account numbers, and account passcodes.
The dataset had been circulating among hackers for years. A user calling themselves “MajorNelson” posted a 5GB archive on a public hacking forum in March 2024, and a group called ShinyHunters had reportedly been auctioning similar records as far back as 2021. AT&T initially denied the information came from its systems, then reversed course after an independent researcher confirmed the files contained legitimate AT&T passcodes. AT&T said it did not have evidence that anyone had broken into its own systems, and the company never publicly identified whether the data originated from AT&T or from a vendor. It reset passcodes for all 7.6 million affected current customers and offered credit monitoring.
The July 2024 Snowflake Breach
The second breach was disclosed on July 12, 2024. Hackers accessed an AT&T workspace on Snowflake, a third-party cloud data platform, between April 14 and April 25, 2024, and downloaded records of customer calls and texts spanning roughly May through October 2022 plus a single day in January 2023. The stolen data included phone numbers, the numbers customers interacted with, call counts, total call durations, and for some records, cell site identification numbers that can indicate a caller’s general location. The content of calls and texts was not taken, and Social Security numbers were not part of this breach.
The attackers did not exploit a flaw in Snowflake itself. They used credentials stolen through malware infections on third-party systems, and the affected Snowflake accounts lacked multi-factor authentication. Security firm Mandiant reported that AT&T was one of at least 100 companies targeted in the same wave.
AT&T learned of the intrusion on April 19, 2024, and notified the SEC. The Department of Justice asked the company to delay public disclosure, citing national security concerns, which is why the announcement did not come until July.
Checking Your Status
If you filed a claim, watch the official settlement website for updates from Kroll and any ruling from Judge Brown. Until the court approves the deal and any appeals conclude, no payments will be issued.