HackingStolen CredentialsData ExfiltratedData PublishedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTCREDENTIALSMediumContained
AT&T INC.
bd_5109fdbae81c1550 · schema v1 · pii pii-v1
Full breach record for AT&T INC. →AT&T notified customers that their personal information (names, SSNs, DOBs, account numbers, passcodes) was found in a dataset released on the dark web on March 17, 2024. The data originated from June 2019. AT&T reset affected passcodes and offered one year of credit monitoring via Experian. The incident status is contained.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_79d7d9a7036db0e9New Hampshire State AGfiled 2024-04-15(10d gap)Verified
- bd_2c04c4a158e44fd2Washington State AGfiled 2024-04-10(15d gap)Verified
- bd_7534be63ba9185ecOregon State AGfiled 2024-04-10(15d gap)Verified
- bd_962bc7783c26b345California State AGfiled 2024-04-09(16d gap)Verified
Show 3 more filings ↓Show fewer ↑up to 16d gap
- bd_9c10bf1a6486d810Montana State AGfiled 2024-04-09(16d gap)Candidate
- bd_ae9a0cefc958af77Vermont State AGfiled 2024-04-09(16d gap)Verified
- bd_ff7d944ebd2888c9Indiana State AGfiled 2024-04-09(16d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2024/04/ATT-Customer-Notification-Letter-Template.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 25, 2024
- Raw hash
- 196b2b2a8ea4441224fd09b7bb7233681f7920c0aadde0b2516d463ee77f3eeb
Reporting entity
- Name
- AT&T INC.norm: at t
Victim entity
- Name
- AT&T INC.norm: at t
Incident
- Discovered
- Mar 26, 2024
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTCREDENTIALS
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 4 weeks(30 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.