Skip to content
Data breachResolved

AT&T data breach (2021)

A dataset dating to August 2021 — names, addresses, phone numbers, and encrypted SSNs and dates of birth — resurfaced in March 2024 and was leaked for free, with AT&T eventually confirming ~73 million current and former customers were affected.

Victim
AT&T
records
73.0M
users
73.0M

In March 2024, a dataset originally tied to an August 2021 incident resurfaced and was dumped for free on a cybercrime forum. After initially disputing its origin, AT&T confirmed the data was genuine and that it affected roughly 73 million current and former account holders, making it one of the largest telecom data exposures on record.

What happened

The data first appeared in August 2021, when the prolific data-trading group ShinyHunters advertised a trove of about 70 million AT&T records on RaidForums. At the time, AT&T stated it found "no indication" its systems had been compromised and declined to claim the data.

The dataset went quiet until March 2024, when another actor re-released the entire trove for free, attributing it to the 2021 ShinyHunters breach. This time the data was independently verified, and on 30 March 2024 AT&T reversed its position, confirming the records were authentic and affected approximately 73 million people.

What was exposed

The leaked records included full names, mailing addresses, phone numbers, email addresses, and — critically — encrypted Social Security numbers and dates of birth. The most damaging element was that the leak shipped with companion files mapping the encrypted SSNs and DOBs to their plaintext values, effectively neutralising the encryption and exposing decrypted SSNs and birth dates for millions of customers. AT&T stated it did not believe the data had been taken directly from its own systems and noted it could not determine whether the source was AT&T or a vendor.

Impact

  • Approximately 73 million current and former account holders were affected; Have I Been Pwned indexed a deduplicated subset of around 49 million unique records.
  • Exposed decrypted SSNs and dates of birth create a durable, long-tail risk of identity theft and synthetic-identity fraud that password resets cannot mitigate.
  • AT&T reset account passcodes for affected active customers and notified impacted individuals; class-action litigation followed.

Why it matters

The AT&T case demonstrates the long half-life of leaked data: a dataset dismissed in 2021 became a major incident three years later once it was verified and freely distributed. It also highlights the danger of encryption applied without protecting the keys or mappings — encrypted SSNs offered no protection once the plaintext lookup tables were bundled alongside. For consumers, exposure of immutable identifiers like SSNs and birth dates is far more consequential than a leaked password, underscoring the value of credit freezes and long-term identity monitoring.

Timeline

  1. ShinyHunters advertises a trove of roughly 70 million AT&T records on RaidForums; AT&T says it finds no indication its systems were compromised.

  2. A threat actor re-releases the full dataset for free on a cybercrime forum, attributing it to the 2021 ShinyHunters breach.

  3. AT&T publicly confirms the data is genuine and impacts roughly 73 million current and former account holders.

  4. AT&T resets passcodes for affected active accounts and begins notifying impacted customers.

  5. Have I Been Pwned indexes the dataset; decrypted SSNs and dates of birth are confirmed within the leaked files.

Sources

  1. haveibeenpwned.comhttps://haveibeenpwned.com/PwnedWebsites#AT&T
  2. cnn.comhttps://www.cnn.com/2024/03/30/tech/att-data-leak/index.html
  3. bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/old-atandt-data-leak-repackaged-to-link-ssns-dobs-to-49m-phone-numbers/
  4. security.orghttps://www.security.org/identity-theft/breach/att/

Related incidents