AT&T confirmed data on 73 million current and former customers leaked online
- Organization
- AT&T
- Exploit
- Hacking
- Industry
- Telecommunications
AT&T said on March 30, 2024 that a large dataset released on the dark web roughly two weeks earlier contained personal information belonging to about 73 million current and former account holders.
The telecommunications company put the split at 7.6 million current customers and 65.4 million former customers. The exposed fields varied by record but could include full names, email and postal addresses, phone numbers, dates of birth, Social Security numbers, AT&T account numbers and account passcodes. AT&T said the data appeared to date from 2019 or earlier and did not contain financial information or call history.
The company did not say where the data came from. AT&T stated that it had not determined whether the information originated with AT&T or with one of its vendors, and that it had no evidence of unauthorized access to its own systems resulting in exfiltration of the dataset. It said a robust investigation was under way.
AT&T reset account passcodes for the 7.6 million affected current customers and said it would contact everyone whose sensitive personal information appeared in the set, offering credit monitoring where appropriate. Malwarebytes noted that the company had initially disputed that the data belonged to its customers before revising that position, and that the seller had claimed the records were taken several years earlier.