Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Start with any breach email or letter from AT&T, then check notifications in your AT&T account. AT&T said it was contacting people it identified as affected, but the available official information does not establish a public tool that can definitively check whether any individual was included. If you cannot find a notice, contact AT&T through its official website or app using contact details you verify independently.

Check for an official AT&T notice

  1. Search email and physical mail. Look for messages from AT&T about a data incident. Check spam or junk folders, and, if you were a former customer, any older email address or mailing address you may have used.
  2. Check your account notifications. Sign in through AT&T’s known official website or app and review account messages.
  3. Contact AT&T if you are unsure. Use support details found independently on AT&T’s official site. Do not rely on a phone number or link in an unexpected message.

AT&T said it was proactively communicating with impacted people and directed current and former customers with questions to its account-safety page. A general password warning or a published estimate of affected accounts cannot establish whether you personally were included.

The official information reviewed does not establish a universal personal breach-check form. Do not enter your Social Security number, account credentials, or other sensitive details into an unverified breach-search service.

Identify which AT&T incident a notice refers to

There were two distinct AT&T data incidents announced in 2024. A notice about one does not prove that your information was included in the other. Read the notice for the incident date and the specific data types it names.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Incident What the official source says Data described
AT&T 1 AT&T’s March 30, 2024 announcement described a dataset released on the dark web that appeared to be from 2019 or earlier. AT&T estimated it involved approximately 7.6 million current account holders and 65.4 million former account holders; these were company estimates, not a way to identify an individual. AT&T announcement Potentially a mix of identity and account details, including names, contact information, birth dates, account passcodes, billing account numbers, and Social Security numbers. The exact items varied.
AT&T 2 AT&T announced this incident on July 12, 2024. The court-authorized settlement site describes data downloaded from an AT&T workspace hosted on Snowflake. AT&T Data Incident Settlement site Telephone numbers and associated interaction data, including numbers contacted and counts and aggregate duration of calls or texts; cell-site identification numbers were included for a small subset.

In its March 30, 2024 announcement, AT&T said: “Currently, AT&T does not have evidence of unauthorized access to its systems resulting in exfiltration of the data set.” That was the company’s statement about its preliminary analysis at that time; it is not a current forensic conclusion.

What to do if sensitive information was exposed

If your notice identifies a Social Security number or another sensitive identifier, use the FTC’s data-breach recovery guidance, review your credit reports for accounts or activity you do not recognize, and consider a credit freeze or fraud alert.

Credit freeze

A credit freeze is free and restricts creditors’ access to your credit report, which can make it harder for someone to open a new account in your name while the freeze is in place. You must place it separately with Equifax, Experian, and TransUnion. You may need to temporarily lift it when applying for credit.

Fraud alert

An initial fraud alert is free and lasts one year. It asks businesses to take steps to verify your identity before extending credit; unlike a freeze, it does not block access to your credit report. You can request an alert from one of the three bureaus, which must notify the others. The FTC explains both options at its Fair Credit Reporting Act guidance.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Handle compromised-password alerts safely

An AT&T or device alert that says a password may be compromised is not, by itself, confirmation that you were included in either AT&T incident. AT&T says such alerts may relate to a username and password exposed in a non-AT&T breach. Go directly to the relevant service’s official app or website to change the password, and avoid reusing it elsewhere. Do not follow embedded links in an unexpected alert; AT&T’s guidance is on its account-safety page.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Check settlement updates, not claim availability

The court-authorized AT&T Data Incident Settlement site lists December 18, 2025, as the claim deadline and reports that the court granted final approval on October 2, 2026. The deadline has passed, so the listed compensation amounts are not open offers and do not guarantee payment. The site lists ceilings of up to $5,000 for documented losses related to AT&T 1 and up to $2,500 for documented losses related to AT&T 2. Check the authorized site for any later court or distribution updates.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.