The AT&T data leak highlights the importance of protecting your data

A black AT&T sign with its logo in bright blue hanging outside a shop
(Image credit: Getty Images)

AT&T has acknowledged a data leak impacted 73 million of its current and former customers. News of the data leak was made public in March of this year, after a hacker using the alias ShinyHunters posted an archive of the stolen data to BreachForums, a notorious data leaks site.

AT&T said it is unclear whether the data, which appears to be from 2019 at the latest, originated from AT&T or one of its vendors. It has also not yet been made public how the data was accessed.

The information posted to BreachForums includes customers’ full names, email addresses, phone numbers, Social Security numbers, and AT&T account numbers and passcodes. In light of this, AT&T has reset all passcodes. The telecoms company has said it will be contacting those affected via email or letter, as well as providing complimentary identity theft protection and credit monitoring services if personal info was leaked.

User’s financial information or call history was not included in the leak.

How public is the AT&T data leak? 

Despite AT&T saying that the data was leaked on the dark web, web security consultant and owner of HaveIBeenPwnd.com, Troy Hunt, explained to What The Tech? that the data is on the “clear web”. This means that it is on sites that can be accessed via your regular browser, giving “thousands if not tens of thousands of people” access to the data.

This means that, for the 73 million people affected by the breach, their personal information is easily accessible. Troy Hunt empathized with this struggle, noting: “We cannot go and change our date of birth, changing a social security number is an absolute nightmare. So we have to work on the fact that the data is out there and we’re never going to get it back.” 

Unfortunately, as many people do not take steps to protect their sensitive information until it has been breached, this can be an arduous process. Hunt suggests using identity theft and fraud protection services—something that AT&T has offered the victims of the data breach.

Where was the AT&T data leaked from? 

There is evidence on BreachForum that the data leaked in March 2024 is a repost of a leak shared in 2021. In 2021, AT&T did not confirm whether or not this data was legitimate, and denied that the data came from AT&T, saying that the data posted “d[id] not appear to have come from our systems”.

Despite this, ShinyHunters continued to make claims about the legitimacy of the data posted, saying that they “d[id]n’t care if they d[id]n’t admit”, referring to AT&T.

How to protect your personal data  

As Troy Hunt said, one of the issues with data breaches is the fact that people don’t protect their data until it’s too late. We’ve all done it—most people don’t assume that their personal information will be accessed by hackers and sold to other bad actors on the internet. Unfortunately, with the rate and scale of cyber attacks, your data being leaked has become less of and if and more of a when.

Take me for example—I used Troy Hunt’s own HaveIBeenPwned.com to find out what information about me has been posted on the internet, and found out that my phone number was exposed in a data breach, and my email address has been exposed in two. 

So, with this in mind, it’s important to take steps to protect your identity and data online, including:

Using multi-factor authentication—this can help prevent hackers from gaining access to your accounts, even if your email address is made public.

Not reusing passwords and resetting your passwords if they are exposed in a data breach—this means that even if your username and password is exposed, hackers cannot access any other accounts you use, and even the account that has leaked details.

Investing in identity protection, whether this is on its own or part of an internet security suite—identify protection software can scour the web for data breaches you were involved in, allowing you to take further steps to protect your identity.

Olivia Powell
Commissioning Editor for Tech Software

Olivia joined TechRadar in October 2023 as part of the core Future Tech Software team, and is the Commissioning Editor for Tech Software. With a background in cybersecurity, Olivia stays up-to-date with all things cyber and creates content across sites including TechRadar Pro, TechRadar, Tom’s Guide, iMore, Windows Central, PC Gamer and Games Radar. She is particularly interested in threat intelligence, detection and response, data security, fraud prevention and the ever-evolving threat landscape.

Read more
Illustration of a thief escaping with a white fingerprint
5 massive privacy scandals that rocked the world – and made millions of victims
Someone holding a passport with two boarding passes inside it
Top digital loan firm security slip-up puts data of 36 million users at risk
Cartoon Phishing
One of the largest data leaks ever sees info on 1.5 billion people leaked online
How to prevent cyberattacks
NTT admits hackers accessed details of almost 18,000 corporate customers in cyberattack
An illustration of a hooded hacker with an obscured face holding a large fingerprint against a red background.
ID theft – what happens when someone steals your identity
A man looking at a tablet with a brown Best Buy package on the desk in front of him
Huge Christmas data breach - 14 million shipping records leaked, putting shoppers at risk
Latest in Cyber Security
Dark Web monitoring
How users benefit from Dark Web monitoring
The X logo next to a silhouette of Elon Musk
Who was really behind the massive X cyberattack? Here’s what experts say about Elon Musk’s claims
A person holding a phone looking at a scam text with warning signs around
A massive SMS toll fee scam is sweeping the US – here’s how to stay safe, according to the FBI
View on National Assembly building in Paris, France, with French and European flags flying.
France rejects controversial encryption backdoor provision
ignal messaging application President Meredith Whittaker poses for a photograph before an interview at the Europe's largest tech conference, the Web Summit, in Lisbon on November 4, 2022.
"We will not walk back" – Signal would rather leave the UK and Sweden than remove encryption protections
Man uses a laptop in a hotel room
4 ways to avoid misinformation on social media and retain control of your newsfeed
Latest in Features
inZOI.
inZOI early access is the most disappointed I’ve been with a game in years
A close up of a xenomorph with Earth reflected on its head in the Alien: Earth TV show teaser
Disney+ celebrates 5 years of streaming with 2025 lookahead – here are 3 movies and shows I can't wait to watch
Samsung Galaxy Z Fold 6 in Paris in front of the Louvre pyramid
I switched to a Samsung Galaxy Z Fold 6 five months ago and I haven’t looked back – here are five things you need to know before buying a foldable phone
iPhone 16 Pro Desert Titanium in hand
I think the rumored iPhone 17 Pro redesign looks great – but is it Apple enough?
AI quantization
What is AI quantization?
Hume AI
What is Hume: Bring emotional understanding to AI-generated voices