AT&T confirms data dumped online appears to be from 2019 or earlier and has personal data of 7.6M current and 65.4M former account holders, resets passcodes
US telco giant takes action after 2019 data breach — Phone giant AT&T is reseting customer account passcodes after a huge cache …
TechCrunchZack Whittaker
Context & Ripple Effects
The episode moved from a breach seller’s public release of a purported 73M-customer AT&T dataset to the carrier’s acknowledgement that the material is tied to older customer information. That confirmation turns a disputed leak into an active account-security and customer-support event.
Related coverage later tracks a separate AT&T notification involving phone records of nearly all customers, making this incident part of a broader run of exposure disclosures rather than an isolated reputational issue.
First-order effects
AT&T must reset passcodes and handle the resulting access, authentication and support burden for affected current account holders.
Current and former customers whose personal information appears in the dump face elevated phishing and impersonation risk, even where a reset limits direct account misuse.
Second-order effects
Other carriers face pressure to review legacy-data stores and account-recovery controls, since old customer records can remain useful to fraudsters long after collection.
The reset shifts friction onto customers and contact centers, while increasing the value of stronger authentication that does not rely solely on static personal details.
Third-order effects
If repeated telecom disclosures persist, competitive trust will increasingly depend on data-retention discipline and resilient identity controls, not just network coverage and price.
The pattern could strengthen scrutiny of how large carriers retain, secure and disclose access to historical customer data, though the corpus does not establish any resulting policy action.
The trend: Telecom security is becoming a lifecycle-data problem: historical customer records can create present-day account and trust risks years after a breach.
Great story by @zackwhittaker and nice research by @chick3nman. PSA: don't use deterministic hashing/encryption schemes to hide sensitive data on low-cardinality fields. — Shorter version: don't try to protect critical national infrastructure without consulting a cryptography …
More: Security researcher Sam “Chick3nman” Croley told TechCrunch how he figured out that the encrypted records in the 73 million AT&T leaked data set were customer account passcodes. — Croley said it was not necessary to crack the encryption cipher to unscramble the passcode d…
AT&T reported today that the data of 73 million current and former customers has leaked on the dark web • AT&T reset passcodes of current customers • info leaked included names and SSNs • data was from 2019 or earlier AT&T said there was no evidence of a system breach
NEW SCOOP: AT&T has reset millions of customer account passcodes after a huge cache of data containing customer records was dumped online this month. AT&T said breach impacted ~7.6 million current customers and ~65.4 million former customers. https://techcrunch.com/...
The data dumped earlier this month is from 2021, and was initially dismissed by AT&T as not a data breach. But a security researcher who analyzed the leaked data told us the encrypted account passcodes are easy to decipher. Now AT&T has taken action. https://techcrunch.com/...
Major scoop here from @zackwhittaker resets account passcodes after millions of customer records leak online. This is the first time that AT&T has acknowledged that the leaked data belongs to its customers. https://techcrunch.com/... via @techcrunch tip @techmeme