← Blog

AT&T Data Breaches: Full Timeline Through 2026

Share on X

People search AT&T data breach timeline because the brand sits on billions of accounts, credentials, and cloud workloads. BreachHistory indexes 15 AT&T-linked incidents, with headline counts up to 176M+ in catalog rows. This page maps every attested event through 2026 with internal links to canonical records.

Why AT&T breach history matters

AT&T operates in Technology (United States). Across indexed rows, recurring themes include credential theft and social engineering. Understanding the chronological pattern helps security teams, customers, and regulators separate confirmed disclosures from forum marketing.

Full timeline through 2026

2026 — 176M records resurfaced with decrypted SSNs

Cataloged incident. Dataset of ~176M AT&T records began circulating on dark web Feb 2, 2026. Repackaged from 2024 breaches; 148M SSNs now fully decrypted (previously encrypted). Includes names, addresses, phones, DOB, emails. Data merged and enriched from multiple sources. Significantly more dangerous for identity theft than original leak. Exposed categories include SSNs, names, addresses, phones, DOB, emails. BreachHistory cites approximately 176M+ affected records in this row. See the att2026-resurfacing and canonical BreachHistory entry.

2024 — 110M

Cataloged incident. Call and text records of nearly all AT&T cellular and landline customers stolen from Snowflake cloud. Hackers accessed data April 14–25 via credential stuffing. Records from May–Oct 2022; phone numbers, call/text metadata, cell site IDs. AT&T delayed disclosure at DOJ request. Exposed categories include Phone numbers, call and text records, interaction details, cell site identification. BreachHistory cites approximately 110M+ affected records in this row. See the att2024snowflake and canonical BreachHistory entry.

2024 — 73M

Cataloged incident. Historical dataset containing sensitive PII leaked on the dark web. Approximately 7.6M current and 65.4M former account holders. Data included names, addresses, SSNs, account numbers, and passcodes. AT&T reset passcodes and offered identity protection. Exposed categories include Names, addresses, phone numbers, SSNs, account numbers, passcodes. BreachHistory cites approximately 73M+ affected records in this row. See the att2024dw and canonical BreachHistory entry.

2023 — full timeline

Cataloged incident. AT&T has experienced multiple data breaches affecting customer and account data. Full timeline through 2023. Exposed categories include Details not publicly disclosed. No attested victim count is published for this row yet. See the attx and canonical BreachHistory entry.

2021 — — 72M records

Cataloged incident. Unknown. 72M records. Exposed categories include Names, emails, addresses, and other PII. BreachHistory cites approximately 720 affected records in this row. See the at-t-20212021 and canonical BreachHistory entry.

2014 — — AT&T: name, ssn, dob Location of breached information:…

Cataloged incident. name, ssn, dob Location of breached information: Desktop Computer Business associate present: No Exposed categories include Personal information. BreachHistory cites approximately 3 affected records in this row. See the att2014 and canonical BreachHistory entry.

2011 — — AT&T: Some of AT&T's customers experienced coordinated…

Cataloged incident. Some of AT&T's customers experienced coordinated hacking attacks. The hackers were trying to gain customer account information and appear to have used auto script technology to determine if AT&T telephone numbers were linked to online AT&T accounts.  Fewer than 1% of customers were affected.  No accounts were successfully breached. Exposed categories include Personal information. No attested victim count is published for this row yet. See the att2011 and canonical BreachHistory entry.

2010 — — AT&T: A former employee of an unknown service provided…

Cataloged incident. A former employee of an unknown service provided for AT&T removed documents that contained customer credit card information.  The information may have also included Social Security numbers, driver's license numbers, names and addresses. Exposed categories include Personal information. No attested victim count is published for this row yet. See the att2010 and canonical BreachHistory entry.

2010 — Unknown

Cataloged incident. A laptop was stolen from a car containing unencrypted Social No attested victim count is published for this row yet. See the attu and canonical BreachHistory entry.

2010 — — AT&T: Details of iPad 3G users hacked from AT&T website,…

Cataloged incident. Details of iPad 3G users hacked from AT&T website, thought to include those of White House chief of staff Rahm Emanuel. BreachHistory cites approximately 114K+ affected records in this row. See the attu1 and canonical BreachHistory entry.

2010 — — AT&T: Data breach reported, 100K records

Cataloged incident. Data breach reported. Reference: http://www.guardian.co.uk/technology/2010/jun/10/apple-ipad-security-leak?INTCMP=SRCH BreachHistory cites approximately 100K+ affected records in this row. See the at-t2010 and canonical BreachHistory entry.

2009 — — AT&T: A temporary employee for AT&T was arrested today on…

Cataloged incident. A temporary employee for AT&T was arrested today on charges she stole personal information on 2,100 co-workers and then pocketed more than $70,000 by taking out short-term payday loans in the names of 130 of them. Exposed categories include Personal information. BreachHistory cites approximately 2K+ affected records in this row. See the att2009 and canonical BreachHistory entry.

2008 — — AT&T: A laptop was stolen from a car containing…

Cataloged incident. A laptop was stolen from a car containing unencrypted Social Security numbers and bonus/salary info of AT&T employees. BreachHistory cites approximately 113K+ affected records in this row. See the att2008 and canonical BreachHistory entry.

2008 — — AT&T: Data breach reported, 100K records

Cataloged incident. Data breach reported. Reference: http://www.idtheftcenter.org/artman2/publish/lib_survey/ITRC_2008_Breach_List.shtml BreachHistory cites approximately 100K+ affected records in this row. See the at-t2008 and canonical BreachHistory entry.

2007 — — AT&T: A laptop containing unencrypted personal data on…

Cataloged incident. A laptop containing unencrypted personal data on current and former employees of the former AT&T Corp. was stolen recently from the car of an employee of a professional services firm doing work for the company. That theft prompted the company to notify an unspecified number of individuals about the potential compromise of their Social Security numbers, names and other personal details. Exposed categories include Personal information. No attested victim count is published for this row yet. See the att2007 and canonical BreachHistory entry.

Patterns and analysis

  • Credential theft and social engineering — appears across multiple AT&T catalog entries; prioritize controls that address this class of failure.
  • Record-count hygiene — BreachHistory indexes actor-cited figures separately from company-confirmed totals; read each row's technicalWriteup before treating counts as fact.
  • 2026 monitoring — New disclosures roll into this timeline as they are verified or labeled unverified per catalog policy.

What to do if you may be affected

  1. Step 1: Enable phishing-resistant MFA on every account tied to this brand.
  2. Step 2: Use unique passwords and a password manager—breach rows often involve credential reuse.
  3. Step 3: Monitor official company breach notices and regulator filings, not dark-web downloads.
  4. Step 4: Review OAuth app permissions and revoke unused third-party integrations.
  5. Step 5: Bookmark the AT&T company page for new 2026+ disclosures.

Canonical BreachHistory hub

Explore every indexed row: breachhistory.com/att · Latest: att2026-resurfacing.

Sources: BreachHistory catalog (15 rows for AT&T), company and regulator disclosures cited in individual breach records.