HackingStolen CredentialsData ExfiltratedData PublishedIDENTITY_BASICIDENTITY_GOVERNMENTCREDENTIALSMediumContained
AT&T INC.
bd_ae9a0cefc958af77 · schema v1 · pii pii-v1
Full breach record for AT&T INC. →AT&T notified consumers of a data breach where customer information was found in a dataset released on the dark web on March 17, 2024. The data, originating from June 2019 or earlier, included names, contact info, SSNs, and account credentials. AT&T reset passcodes for affected accounts and offered one year of credit monitoring via Experian.
Vermont clock✓ VT AG ≤14 bday14 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_962bc7783c26b345California State AGfiled 2024-04-09Verified
- bd_9c10bf1a6486d810Montana State AGfiled 2024-04-09Candidate
- bd_ff7d944ebd2888c9Indiana State AGfiled 2024-04-09Verified
- bd_2c04c4a158e44fd2Washington State AGfiled 2024-04-10(1d gap)Verified
Show 3 more filings ↓Show fewer ↑up to 16d gap
- bd_7534be63ba9185ecOregon State AGfiled 2024-04-10(1d gap)Verified
- bd_79d7d9a7036db0e9New Hampshire State AGfiled 2024-04-15(6d gap)Verified
- bd_5109fdbae81c1550Delaware State AGfiled 2024-04-25(16d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-04-09-att-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 9, 2024
- Raw hash
- bc60650b13e49585725e3e72fd6c333226ab565a91c21b1662a939a45243a33f
Reporting entity
- Name
- AT&T INC.norm: at t
- Domain
- att.com
- Industry
- telecom_media
Victim entity
- Name
- AT&T INC.norm: at t
- Domain
- att.com
- Industry
- telecom_media
Incident
- Discovered
- Mar 26, 2024
- Materiality determined
- —
- Notification sent
- Apr 9, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTCREDENTIALS
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 14 days(14 days from discovery to filing)
- Compliance flags
- VT AG ≤14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.