The AT&T Data Breach Lawsuit concerns consolidated federal litigation over two separate 2024 data security incidents at AT&T, which together are alleged to have exposed personal information belonging to tens of millions of current and former customers. The cases were centralized in the U.S. District Court for the Northern District of Texas and resulted in a proposed class action settlement, which as of the most recent official update was still awaiting a decision from the court on final approval.
The litigation traces back to two distinct events. AT&T announced the first incident on March 30, 2024, involving a dataset that appeared to date from 2019 or earlier and reportedly included sensitive information such as Social Security numbers for millions of current and former account holders. AT&T disclosed the second incident on July 12, 2024, involving unauthorized access to a third-party cloud workspace that reportedly exposed call and text metadata, such as phone numbers and interaction records, for a much larger group of customers.
According to court filings and the official settlement website, the two incidents combined potentially affected up to approximately 182 million people, though some individuals were affected by both and the number of unique claimants is smaller.
This litigation continues to attract attention because of its scale, the sensitivity of the information reportedly involved, and because the proposed $177 million settlement remains in a holding pattern. The final approval hearing took place on January 15, 2026, but as of the settlement website’s most recent posted update, the court had not yet decided whether to approve the agreement. This article explains what the litigation involves, what the settlement covers, and what affected consumers should understand now that the claim deadline has passed.
Table of Contents
Overview of the AT&T Data Breach Lawsuit
This litigation is not a single case but a consolidated set of claims brought together in a multidistrict litigation, formally captioned In re: AT&T Inc. Customer Data Security Breach Litigation, MDL No. 3:24-md-03114-E, before Judge Ada E. Brown in the Northern District of Texas. Plaintiffs alleged that AT&T failed to adequately safeguard customer data, resulting in exposure connected to the two 2024 incidents described above.
Rather than proceeding to trial, the parties reached a proposed class action settlement. According to the official settlement website, the agreement is intended to resolve claims arising from both the March 2024 incident and the July 2024 incident under a combined $177 million fund. It is important to understand that a proposed settlement is not the same as a final court judgment. The settlement must still receive final approval from the court before any distribution of funds can occur, and that approval has not yet been granted as of the most recent posted update.
What Happened in the AT&T Data Breaches?
Two separate incidents underlie this litigation, and it is important not to confuse them with unrelated AT&T cybersecurity matters that have surfaced in other contexts.
- The first incident, announced by AT&T on March 30, 2024, involved a dataset that surfaced on the dark web. According to AT&T’s public statements, the data appeared to originate from 2019 or earlier and affected approximately 7.6 million current account holders and roughly 65.4 million former account holders.
- The second incident, disclosed by AT&T on July 12, 2024, involved what AT&T described as unauthorized access to a workspace on a third party cloud platform. According to court filings, this incident exposed records reflecting calls and texts, including phone numbers, for nearly all AT&T cellular customers and customers of certain other carriers using the AT&T network during a defined period in 2022.
Both incidents were the subject of separate customer notifications and became the basis for numerous individual lawsuits, which were later consolidated into the multidistrict litigation referenced above.
What Information Was Reportedly Exposed?
According to the complaint and the official settlement website, the categories of information reportedly involved varied by incident. In the first incident, plaintiffs allege that exposed data elements could have included full names, mailing addresses, Social Security numbers, dates of birth, and account related information. Social Security number exposure is treated as a more serious harm category under the settlement’s compensation framework, discussed further below.
In the second incident, the exposed information reportedly centered on call and text metadata, such as telephone numbers customers communicated with and the frequency or duration of those interactions, rather than the content of calls or texts themselves. This distinction matters because the type of personal information breach involved shapes both the legal theories asserted and the compensation tiers built into the settlement.
Why Were Lawsuits Filed Against AT&T?
Lawsuits were filed against AT&T after both breaches became public, with plaintiffs alleging that the company failed to implement reasonable data security measures to protect customer information. The complaint alleges claims including negligence, breach of contract, and violations of various state consumer protection and data privacy statutes, arguing that AT&T knew or should have known about vulnerabilities that allowed unauthorized parties to access customer data.
AT&T has denied wrongdoing and liability throughout the litigation. According to the official settlement website and public statements, the settlement was reached without any admission of fault, and AT&T has stated that it agreed to resolve the case to avoid the cost and uncertainty of prolonged litigation rather than because it concedes the allegations. These are allegations raised in a civil complaint, not findings by a court, and no judge has ruled that AT&T is liable for the alleged data privacy or cybersecurity lawsuit claims.
Current Settlement Status
As of the most recent update posted to the official settlement website, dated April 23, 2026, the court had not yet decided whether to approve the settlement. The final approval hearing was held on January 15, 2026, but Judge Ada E. Brown had not issued a ruling as of that update, and the settlement administrator stated that it did not know how long the court’s decision would take.
This means the AT&T Data Breach Lawsuit settlement remains in an unresolved, pending status. A proposed settlement, even after a final approval hearing has taken place, is not binding or final until the presiding judge issues an approval order. If the court approves the settlement, there may also be an appeal period, and resolving any appeals can extend the timeline further. Readers should treat any specific payout date circulating online with caution unless it is confirmed directly by the official settlement website or the court docket, since no such date had been announced as of the most recent verified update.
Who Was Included in the Settlement?
According to the official settlement website, the proposed settlement covers individuals in the United States whose personal information was involved in the AT&T 1 data incident announced on March 30, 2024, and or the AT&T 2 data incident announced on July 12, 2024. Notice of the proposed AT&T settlement was sent to potentially eligible class members, generally by email or postcard, based on AT&T’s records of who was affected.
Individuals who wished to exclude themselves from the class action settlement were required to submit a request for exclusion by the applicable deadline, after which they would retain the right to pursue their own individual legal action against AT&T rather than being bound by the settlement’s terms. Class members who did not opt out and did not object are generally bound by the outcome of the settlement, whether or not they submitted a claim for payment.
What Compensation May Be Available?
According to the official settlement website, the proposed settlement establishes separate compensation structures for the two incidents. Individuals affected by the first incident may be eligible to claim documented losses up to a stated cap, or a pro rata share of the net settlement fund allocated to that class, with claims involving Social Security number exposure eligible for a larger share than claims without it. Individuals affected by the second incident may be eligible for a separate, generally smaller documented loss cap, or a pro rata share of the fund allocated to that class. Individuals affected by both incidents may be eligible to combine documented loss claims across both categories, subject to the settlement’s overall terms.
Because final amounts depend on factors such as the total number of valid claims submitted, court approved attorney fees and administrative costs, and whether any objections or appeals affect the settlement, the exact data breach compensation any individual claimant will receive cannot be confirmed until the court approves the settlement and distribution begins. Readers should rely on the official settlement website or their own claim confirmation materials for figures specific to their situation rather than unofficial estimates.
What Happened to the Claim Deadline?
The deadline to submit a claim form in the AT&T settlement was December 18, 2025. According to the official settlement website, that deadline has passed, and claim forms are no longer being accepted. This is an important point for anyone who has not yet filed: it is not currently possible to submit a new or original AT&T settlement claim, regardless of eligibility, because the claims window has closed.
Individuals who submitted a claim before the deadline do not need to take further action to preserve their claim while the court considers the settlement. The settlement administrator, identified on the official website as Kroll Settlement Administration, has stated that it continues reviewing and processing claims that were already submitted while the court’s decision remains pending.
How the Court Approval Process Works
Understanding how class action settlements move toward final resolution helps explain why the AT&T Data Breach Lawsuit settlement has not yet resulted in payments. The general sequence includes:
- Preliminary approval. The court reviews the proposed settlement terms and, if satisfied they are fair enough to proceed, grants preliminary approval so that notice can be sent to the class.
- Notice and claims period. Eligible class members are notified and allowed to submit a claim, request exclusion, or file an objection by set deadlines.
- Final approval hearing. The court holds a hearing, as occurred on January 15, 2026 in this matter, to consider whether the settlement is fair, reasonable, and adequate, taking into account any objections raised.
- Final approval decision. The judge issues a ruling on whether to approve the settlement. As of the most recent update, this step had not yet occurred in the AT&T Data Breach Lawsuit.
- Appeal period. If the settlement is approved, there is typically a window during which the ruling could be appealed to a higher court.
- Distribution. According to the official settlement website, distribution of settlement benefits will begin only after the settlement has received court approval, any appeal period has expired, and all claim forms have been reviewed.
Because the AT&T Data Breach Lawsuit settlement is currently between steps three and four, no distribution timeline can be confirmed, and any date suggested elsewhere should be treated as speculative unless it comes from the official settlement website or the court itself.
What Affected Consumers Should Know Now
For consumers who believe they were affected by either AT&T data breach, several points are worth keeping in mind. First, the claim filing window has closed, and it is not currently possible to submit an original claim. Second, no final court approval has been granted, so no settlement payments have been authorized or distributed as of the most recent verified update. Third, AT&T has not admitted wrongdoing, and the settlement resolves the litigation without a finding of liability against the company.
Consumers who already filed a claim generally do not need to do anything further at this stage beyond monitoring the official settlement website for updates. Anyone who receives unsolicited communications claiming to expedite a payment, requesting upfront fees, or asking for sensitive account information in connection with this settlement should treat such contact with caution, since scams frequently follow high profile data breach settlements. The official settlement website and the court docket remain the most reliable sources for confirmed developments in this AT&T litigation update.
Key Takeaways
- The AT&T Data Breach Lawsuit resolves consolidated claims from two separate 2024 incidents that reportedly exposed personal information for tens of millions of customers, including Social Security numbers in the first incident and call and text metadata in the second.
- AT&T agreed to a proposed $177 million settlement without admitting wrongdoing or liability.
- The claim filing deadline of December 18, 2025 has passed, and original claims can no longer be submitted.
- The final approval hearing occurred January 15, 2026, but as of the most recent official update, the court had not yet decided whether to approve the settlement.
- No payment date has been confirmed, and distribution cannot begin until the court grants final approval and any appeal period expires.
- Consumers should rely on the official settlement website, telecomdatasettlement.com, or the court docket for verified developments rather than unofficial payout estimates.
Frequently Asked Questions
-
What is the AT&T Data Breach Lawsuit about?
The AT&T Data Breach Lawsuit is consolidated federal litigation alleging that AT&T failed to adequately protect customer data in two separate 2024 incidents, resulting in a proposed $177 million class action settlement that remains pending final court approval.
-
What happened in the AT&T data breach?
AT&T disclosed two incidents in 2024. The first, announced March 30, 2024, involved an older dataset found on the dark web reportedly including Social Security numbers. The second, announced July 12, 2024, involved unauthorized access to a cloud workspace that reportedly exposed call and text metadata for a much larger group of customers.
-
Was there an AT&T data breach settlement?
Yes. AT&T agreed to a proposed $177 million class action settlement covering both incidents, reached without an admission of wrongdoing. The settlement has not yet received final court approval.
-
Can I still file an AT&T data breach claim?
No. The deadline to submit a claim was December 18, 2025, and that deadline has passed. Claim forms are no longer being accepted, regardless of eligibility.
-
What was the AT&T settlement claim deadline?
The claim filing deadline was December 18, 2025. This deadline has passed, and no new original claims can currently be submitted.
-
When will AT&T settlement payments be sent?
No payment date has been confirmed. According to the official settlement website, distribution can only begin after the court grants final approval, any appeal period expires, and all claim forms are fully reviewed. As of the most recent update, the court had not yet ruled on final approval.
-
Has the AT&T settlement received final court approval?
As of the most recent official update, no. The final approval hearing was held January 15, 2026, but the court had not yet issued a decision on whether to approve the settlement. Readers should check the official settlement website for the latest status.
