Millions of AT&T customers affected by two major data breaches in 2024 may soon be eligible for financial compensation, following a sweeping settlement that aims to resolve allegations over the company’s handling of customer information. The telecommunications giant has agreed to a $177 million class-action settlement, a significant move in response to legal claims that it failed to properly secure sensitive user data. Although AT&T continues to deny wrongdoing, the settlement provides a path for customers to recover losses connected to the incidents.
Two Separate Breaches Combine Into One Major Legal Battle
The settlement addresses the fallout from two different data breaches that occurred just months apart. Both incidents exposed personal information for millions of customers, leading to multiple lawsuits that were later consolidated into a single case.
These lawsuits argued that AT&T did not implement sufficient protections to guard the massive amount of user information stored across its systems and third-party platforms. As more companies rely on cloud services and large-scale data storage, breaches like these underscore the increasing risks consumers face when their data is compromised.
Despite agreeing to the settlement, AT&T maintains that the breaches were the result of criminal activity rather than internal lapses.
March 2024 Breach: Sensitive Personal Data Posted Online
The first breach came to light in March 2024, when customer data surfaced on the dark web. The information included full names, physical addresses, email addresses, dates of birth, phone numbers, and in many cases, Social Security numbers—one of the most serious forms of personal data exposure.
AT&T reported that the breach impacted around 7.6 million current customers and more than 65 million former customers whose information was stored in records dating back several years. For many, the involvement of Social Security numbers heightened fears of identity theft and long-term financial harm.
July 2024 Breach: Call and Text Records Illegally Accessed
Just months later, a second breach was announced in July 2024. This incident did not involve Social Security numbers but instead allowed unauthorized actors to download call and text metadata stored on a third-party cloud workspace. While less sensitive than full identity information, the exposure of communication logs raised serious concerns about privacy and the security of cloud-based customer service tools.
Legal filings later revealed that this breach may have affected nearly all of AT&T’s 110 million wireless customers, based on data from 2022 to 2023.
How the Settlement Compensates Customers
Because the two breaches involved different types of data and affected customers differently, the settlement creates two separate compensation categories:
- March 2024 breach class
- July 2024 breach class
Some customers may fall into both categories depending on the extent of their data exposure.
Compensation for March Breach Victims
Those impacted by the March breach may receive up to $5,000 in compensation. The amount varies depending on the type of information exposed and whether the customer can demonstrate financial losses stemming from the breach.
Customers whose Social Security numbers were compromised may qualify for significantly larger pro-rata payments—up to five times the amount available to others in the same category.
Compensation for July Breach Victims
Customers affected by the July breach may receive up to $2,500, with similar criteria for documented and undocumented losses.
Two Ways to File: Proving Losses or Claiming Tiered Payments
The settlement offers two main routes to compensation:
1. Documented Financial Losses
Customers can submit evidence of expenses related to the breach. These may include money spent on identity protection services, reimbursement for fraudulent charges, or compensation for time spent addressing security concerns.
2. Tiered Payments for Customers Without Proof of Loss
Customers who cannot provide documentation still have the option to receive a payment through a tiered pro-rata system. This ensures that even individuals who cannot show direct financial harm can receive compensation for the exposure of their personal information.
How to Submit a Claim
Customers who believe they were affected must submit their claims by December 18, 2025. They can file online or through the mail.
Online Claims:
Available at the official settlement website: www.telecomdatasettlement.com
Mail-In Claims:
AT&T Data Incident Settlement
c/o Kroll Settlement Administration LLC
P.O. Box 5324
New York, NY 10150-5324
AT&T has reiterated that it does not accept fault for the breaches, characterizing them as criminal acts carried out by outside parties. The company’s decision to settle was made to avoid extended litigation and the substantial costs associated with a prolonged legal fight.
Before customers receive any payments, the settlement must be approved by the court. A final approval hearing is scheduled for January 15, 2026, at 9:00 a.m. CT. If approved, funds will be distributed after the claims process is completed and the final number of eligible claimants is determined.




