AT&T Services Inc. agreed to a $13 million civil penalty announced by the Federal Communications Commission (FCC) on September 17, 2024. The settlement resolved an FCC Enforcement Bureau investigation into a January 2023 breach of an unidentified vendor’s cloud environment. The vendor had retained AT&T customer information for years after it was supposed to be returned or destroyed. The penalty goes to the United States Treasury; the FCC proceeding did not create a customer compensation fund or claims deadline.
The key facts
| Question | Answer |
|---|---|
| Regulator | Federal Communications Commission Enforcement Bureau |
| Company | AT&T Services Inc. |
| Breach | January 2023 compromise of a vendor’s cloud environment |
| Customers involved | 8,931,656 AT&T Mobility customers |
| Penalty | $13,000,000 civil penalty |
| Recipient | United States Treasury |
| Consumer payment | None identified in this FCC proceeding |
The FCC described the action as a settlement. “Fine” is understandable shorthand, but this was a negotiated civil penalty resolving an investigation, not a court judgment after trial. The FCC announcement and consent decree are the controlling public documents.
What happened in the vendor’s cloud environment
AT&T used an unidentified vendor to create and host personalized billing and marketing videos. To provide that service, AT&T shared customer information, including some Customer Proprietary Network Information (CPNI), reportedly during 2015–2017.
The vendor’s contract required it to return or destroy the information when it was no longer needed. According to the FCC, information remained in the vendor’s cloud environment for years beyond that point. Threat actors accessed the environment and exfiltrated AT&T customer information in January 2023. The vendor is not named in the public FCC materials.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
The vulnerability was fixed on January 6, 2023, and the FCC order says no additional unauthorized activity was identified after January 8. AT&T reported the incident to the FCC on February 7, 2023, and filed a supplemental report on May 15, 2023.
How many customers and what data were involved?
The order identifies 8,931,656 AT&T Mobility customers as involved. That does not mean every person had the same information exposed.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
- Line-count information was involved for all affected customers.
- For approximately 1% of affected customers, the identified data also included bill-balance and payment information.
- For approximately 1%, it included rate-plan names and features.
- The public order refers to other customer information but does not provide a complete itemized list.
The cited FCC documents do not establish that Social Security numbers, passwords, call contents or text contents were exposed in this January 2023 vendor incident.
Why the FCC investigated AT&T
Section 222 of the Communications Act limits how telecommunications carriers handle customer information, including CPNI. The related rule, 47 C.F.R. § 64.2010(a), requires carriers to take reasonable measures to discover and protect against unauthorized access to CPNI.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitchesRank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
The FCC investigated whether AT&T failed to protect customer information, improperly used or disclosed CPNI, failed to take reasonable safeguards against unauthorized access, or maintained unreasonable privacy, cybersecurity and vendor-management practices. The case illustrates that outsourcing data processing does not outsource the carrier’s responsibility for controlling that data.
What AT&T admitted—and what it did not
AT&T resolved the investigation without a trial. Under the consent decree, it accepted the factual paragraphs describing the investigation as a true and accurate description for purposes of the agreement and FCC civil enforcement. The decree expressly says that no other admissions were made. That is narrower than a general admission of liability or wrongdoing.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
What the settlement required beyond the payment
The FCC agreement required a company-wide compliance program addressing both retained data and third-party access.
Data inventory and retention controls
- Maintain an inventory of customer information and where it is stored.
- Set retention limits and require secure return or destruction when a business need ends.
- Limit unnecessary storage, sharing and access.
Vendor oversight
- Use written vendor requirements covering security, retention and disposal.
- Obtain vendor certifications and conduct continuing assessments.
- Apply sanctions when vendors fail to meet the requirements.
Security governance and response
- Operate a comprehensive information-security program that considers relevant standards, including the NIST Cybersecurity Framework.
- Appoint a compliance officer and maintain a compliance plan and manual.
- Train employees and relevant vendors.
- Maintain access controls and breach-response procedures.
- Conduct annual compliance audits.
AT&T had to submit reports six months and 12 months after the decree’s effective date, followed by annual reports. Most requirements expire three years after that effective date unless the decree specifies otherwise. Payment of the $13 million civil penalty was due within 30 calendar days of the effective date.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Did customers receive money?
No customer payment program is identified in this FCC proceeding. The $13 million went to the Treasury, not directly to affected account holders, and the public materials do not establish a claims process or deadline for this settlement. Other AT&T litigation or incidents must be evaluated separately rather than treated as part of this FCC penalty.
What AT&T reported about fraud
According to the FCC order’s account of AT&T’s findings, the company monitored impacted accounts and found no evidence of AT&T account-related fraud or other unlawful or unauthorized activity tied to the breach. The order also says porting, SIM-swap and equipment-fraud rates for impacted customers were consistently lower than rates for AT&T Mobility customers generally. Those are AT&T’s reported monitoring results, not a guarantee that no individual experienced harm.
Practical precautions
- Be cautious with messages that use billing, plan or payment details to create urgency.
- Do not reuse an AT&T password on another service.
- Check account and payment requests through AT&T’s official website or app rather than an unsolicited link.
- If you see suspicious account activity, contact AT&T through an official channel and report suspected identity theft or fraud to the appropriate authorities.
Do not confuse this case with AT&T’s separate 2024 cloud incident
AT&T disclosed a different incident in 2024 involving an AT&T workspace on a third-party cloud platform. Its SEC filing says that incident involved call and text interaction records from 2022 and January 2, 2023—not the vendor-retained customer information at issue in the FCC settlement. The filing said the records did not include call or text content, Social Security numbers, dates of birth or customer names. See the AT&T SEC filing for that separate disclosure.
The January 2023 vendor breach, the April 2024 cloud-workspace incident and the FCC’s September 17, 2024 announcement have different dates, data and regulatory contexts. The FCC—not the Federal Trade Commission—brought this $13 million action.
Why the case matters
The enforcement action is about more than a single cloud intrusion. It addresses whether a carrier knows what customer data it has given to contractors, limits retention after the business purpose ends, verifies vendor security and can demonstrate ongoing oversight. Keeping obsolete information out of a third-party environment reduces the amount available to attackers if that environment is later compromised.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




