DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

AT&T Agreed to a $13 Million FCC Penalty Over a Third-Party Cloud Breach

The FCC announced a $13 million AT&T settlement on September 17, 2024, over a January 2023 breach of a vendor’s cloud environment. Here is the verified customer count, exposed data, required remediation and what the penalty means for consumers.
From TheFinanceBase Team5 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

AT&T Services Inc. agreed to a $13 million civil penalty announced by the Federal Communications Commission (FCC) on September 17, 2024. The settlement resolved an FCC Enforcement Bureau investigation into a January 2023 breach of an unidentified vendor’s cloud environment. The vendor had retained AT&T customer information for years after it was supposed to be returned or destroyed. The penalty goes to the United States Treasury; the FCC proceeding did not create a customer compensation fund or claims deadline.

The key facts

Question Answer
Regulator Federal Communications Commission Enforcement Bureau
Company AT&T Services Inc.
Breach January 2023 compromise of a vendor’s cloud environment
Customers involved 8,931,656 AT&T Mobility customers
Penalty $13,000,000 civil penalty
Recipient United States Treasury
Consumer payment None identified in this FCC proceeding

The FCC described the action as a settlement. “Fine” is understandable shorthand, but this was a negotiated civil penalty resolving an investigation, not a court judgment after trial. The FCC announcement and consent decree are the controlling public documents.

What happened in the vendor’s cloud environment

AT&T used an unidentified vendor to create and host personalized billing and marketing videos. To provide that service, AT&T shared customer information, including some Customer Proprietary Network Information (CPNI), reportedly during 2015–2017.

The vendor’s contract required it to return or destroy the information when it was no longer needed. According to the FCC, information remained in the vendor’s cloud environment for years beyond that point. Threat actors accessed the environment and exfiltrated AT&T customer information in January 2023. The vendor is not named in the public FCC materials.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

The vulnerability was fixed on January 6, 2023, and the FCC order says no additional unauthorized activity was identified after January 8. AT&T reported the incident to the FCC on February 7, 2023, and filed a supplemental report on May 15, 2023.

How many customers and what data were involved?

The order identifies 8,931,656 AT&T Mobility customers as involved. That does not mean every person had the same information exposed.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
  • Line-count information was involved for all affected customers.
  • For approximately 1% of affected customers, the identified data also included bill-balance and payment information.
  • For approximately 1%, it included rate-plan names and features.
  • The public order refers to other customer information but does not provide a complete itemized list.

The cited FCC documents do not establish that Social Security numbers, passwords, call contents or text contents were exposed in this January 2023 vendor incident.

Why the FCC investigated AT&T

Section 222 of the Communications Act limits how telecommunications carriers handle customer information, including CPNI. The related rule, 47 C.F.R. § 64.2010(a), requires carriers to take reasonable measures to discover and protect against unauthorized access to CPNI.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

The FCC investigated whether AT&T failed to protect customer information, improperly used or disclosed CPNI, failed to take reasonable safeguards against unauthorized access, or maintained unreasonable privacy, cybersecurity and vendor-management practices. The case illustrates that outsourcing data processing does not outsource the carrier’s responsibility for controlling that data.

What AT&T admitted—and what it did not

AT&T resolved the investigation without a trial. Under the consent decree, it accepted the factual paragraphs describing the investigation as a true and accurate description for purposes of the agreement and FCC civil enforcement. The decree expressly says that no other admissions were made. That is narrower than a general admission of liability or wrongdoing.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

What the settlement required beyond the payment

The FCC agreement required a company-wide compliance program addressing both retained data and third-party access.

Data inventory and retention controls

  • Maintain an inventory of customer information and where it is stored.
  • Set retention limits and require secure return or destruction when a business need ends.
  • Limit unnecessary storage, sharing and access.

Vendor oversight

  • Use written vendor requirements covering security, retention and disposal.
  • Obtain vendor certifications and conduct continuing assessments.
  • Apply sanctions when vendors fail to meet the requirements.

Security governance and response

  • Operate a comprehensive information-security program that considers relevant standards, including the NIST Cybersecurity Framework.
  • Appoint a compliance officer and maintain a compliance plan and manual.
  • Train employees and relevant vendors.
  • Maintain access controls and breach-response procedures.
  • Conduct annual compliance audits.

AT&T had to submit reports six months and 12 months after the decree’s effective date, followed by annual reports. Most requirements expire three years after that effective date unless the decree specifies otherwise. Payment of the $13 million civil penalty was due within 30 calendar days of the effective date.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Yubico - YubiKey 5C - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB, FIDO Certified - Protect Your Online Accounts (5C)
  • POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Did customers receive money?

No customer payment program is identified in this FCC proceeding. The $13 million went to the Treasury, not directly to affected account holders, and the public materials do not establish a claims process or deadline for this settlement. Other AT&T litigation or incidents must be evaluated separately rather than treated as part of this FCC penalty.

What AT&T reported about fraud

According to the FCC order’s account of AT&T’s findings, the company monitored impacted accounts and found no evidence of AT&T account-related fraud or other unlawful or unauthorized activity tied to the breach. The order also says porting, SIM-swap and equipment-fraud rates for impacted customers were consistently lower than rates for AT&T Mobility customers generally. Those are AT&T’s reported monitoring results, not a guarantee that no individual experienced harm.

Practical precautions

  • Be cautious with messages that use billing, plan or payment details to create urgency.
  • Do not reuse an AT&T password on another service.
  • Check account and payment requests through AT&T’s official website or app rather than an unsolicited link.
  • If you see suspicious account activity, contact AT&T through an official channel and report suspected identity theft or fraud to the appropriate authorities.

Do not confuse this case with AT&T’s separate 2024 cloud incident

AT&T disclosed a different incident in 2024 involving an AT&T workspace on a third-party cloud platform. Its SEC filing says that incident involved call and text interaction records from 2022 and January 2, 2023—not the vendor-retained customer information at issue in the FCC settlement. The filing said the records did not include call or text content, Social Security numbers, dates of birth or customer names. See the AT&T SEC filing for that separate disclosure.

The January 2023 vendor breach, the April 2024 cloud-workspace incident and the FCC’s September 17, 2024 announcement have different dates, data and regulatory contexts. The FCC—not the Federal Trade Commission—brought this $13 million action.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why the case matters

The enforcement action is about more than a single cloud intrusion. It addresses whether a carrier knows what customer data it has given to contractors, limits retention after the business purpose ends, verifies vendor security and can demonstrate ongoing oversight. Keeping obsolete information out of a third-party environment reduces the amount available to attackers if that environment is later compromised.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.