Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
AT&T’s 2024 data breach is confirmed; the reported $370,000 payment to delete stolen records is not. WIRED reported that AT&T paid a threat actor in Bitcoin for deletion of the data and a video purporting to show it. AT&T has not publicly confirmed the payment, and no video can establish that every copy was destroyed. The records were about calls and texts—not their contents—but still carried privacy and social-engineering risks.
The distinction matters: AT&T’s filing with the U.S. Securities and Exchange Commission confirms that customer call and text records were accessed and copied. The ransom payment is a media report, not an admission by AT&T. A later guilty plea in a broader hacking case adds context about the alleged criminal operation, but does not independently verify AT&T’s specific payment or prove that its data was erased everywhere.
At a glance: AT&T disclosed the breach on July 12, 2024. WIRED reported a $370,000 Bitcoin payment in May 2024. The exposed records concerned calls and texts during specified periods in 2022 and 2023; AT&T said they did not include the contents of calls or messages. Complete deletion cannot be independently established. In a later development, Canadian defendant Connor Moucka pleaded guilty on August 5, 2026, in the wider hacking-and-extortion case.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
What AT&T confirmed about the breach
In its SEC filing, AT&T said the stolen records involved calls and texts made between May 1 and October 31, 2022, and on January 2, 2023. AT&T learned on April 19, 2024, that a threat actor claimed to have accessed and copied call logs. The company’s investigation concluded that unauthorized access and copying had occurred between approximately April 14 and April 25, 2024.
#1 Best Overall
AT&T described the records as covering nearly all its wireless customers and customers of mobile virtual network operators using its wireless network. The disclosed fields included phone numbers involved in interactions, counts of calls or texts, and aggregate call duration for a day or month. Some records also included cell-site identification numbers.
AT&T said the records did not contain call or text content, Social Security numbers, dates of birth, customer names as fields, or other direct personally identifying information. But a phone number may be linked to a person using publicly available information. And cell-site identifiers are not GPS coordinates: they can provide some location-related context, but should not be described as precise live tracking.
Contemporary coverage often put the exposure at more than 100 million people. AT&T’s own wording was “nearly all” wireless customers; the number of records is not necessarily the number of unique people, since records can include repeated interactions and numbers belonging to people who are not AT&T customers. The Justice Department’s later estimate of at least 100 million individuals relates to the wider campaign across its victims, not an AT&T-only count.
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #2
- Ideal for Gifting
- Ideal for a bookworm
- Compact for travelling
What is known about the $370,000 payment
On July 14, 2024, WIRED reported that AT&T paid a member of the ShinyHunters hacking group about $370,000 in Bitcoin in May 2024. The report cited statements from the alleged recipient and a security researcher who helped facilitate the transaction, along with cryptocurrency-wallet evidence. It said a video purporting to show deletion was supplied. Other reporting said the initial demand was $1 million, but that figure, too, is not an AT&T-confirmed statement.
AT&T’s SEC disclosure confirms the breach, not the ransom deal. The careful description is therefore that AT&T reportedly paid for deletion—not that the company admitted paying or that it proved the data was destroyed. The available reporting supports a credible account of a transaction, but the public record does not independently establish whether the recipient controlled every copy, whether collaborators kept duplicates, or whether every system and backup was cleared.
Why call and text records can still be sensitive
Metadata is not message content, but it can reveal patterns. A network of numbers and interaction frequency can help someone infer relationships with family, doctors, lawyers, banks, journalists, employers, or public agencies. Timing, call duration, and—in some records—cell-site identifiers can add context. Combined with phone directories, social media, or other leaked data, these details may make targeted impersonation and phishing more convincing.
Rank #3
That does not mean every affected customer faces imminent identity theft. Because AT&T said Social Security numbers and dates of birth were not in these records, the most direct concern is privacy, profiling, and social engineering—not a straightforward identity-theft scheme based solely on the disclosed fields. Be alert to messages that invoke a real contact, appointment, financial issue, or family emergency, but do not assume that every unusual call is connected to this breach.
The Snowflake connection—and what it does not establish
AT&T described the source as an AT&T workspace on a third-party cloud platform. Media coverage and congressional correspondence identified the platform as Snowflake and placed the incident within a wider campaign involving customer environments. That context should not be simplified to “Snowflake’s core service was hacked”: public discussion of the campaign included compromised credentials and account protections, while responsibility and the precise initial access path for AT&T were not fully established in the cited public disclosure.
In its filing, AT&T said it activated incident response, brought in outside cybersecurity experts, and did not believe the data was publicly available at that time. The Justice Department granted delays to public disclosure on May 9 and June 5, 2024, citing potential national-security or public-safety concerns. AT&T said it would notify current and former impacted customers.
Rank #4
What the later guilty plea adds
On August 5, 2026, the Justice Department announced that Connor Riley Moucka, a Canadian national, pleaded guilty to a broad hacking and extortion conspiracy. Prosecutors described a campaign involving more than 165 organizations, billions of records, and more than $2.5 million in ransom payments overall; the stolen data included non-content call and text history records. The alleged co-conspirator John Erin Binns remains outside U.S. custody, according to the DOJ case page.
The guilty-plea announcement supports the existence of a wider criminal campaign. It does not publicly identify the AT&T payment as part of the campaign-wide total, nor does it resolve every detail of the reported $370,000 transaction or deletion arrangement.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Why a deletion video cannot settle the question
A screen recording can show someone deleting files from one visible location. It cannot prove that no offline copy, export, backup, screenshot, temporary file, or collaborator-held duplicate exists. Nor can it establish that the visible environment contained the whole dataset or that the person on screen controlled every copy. A cryptographic hash check or controlled escrow process might provide stronger evidence about a defined dataset, but neither can guarantee that no separate copy exists somewhere else.
Best Value
- It can be a gift option
- Comes with secure packaging
- Helpful in various ways
For that reason, a video “purporting to show deletion” is not proof that the data vanished everywhere. Even if the reported payment and deletion video are accurately described, payment cannot reverse the original access or remove copies already made.
What AT&T customers can do
- Be skeptical of targeted contact. Verify unexpected requests for money, passwords, codes, or urgent action through a known, independently sourced phone number—not a number or link in the message.
- Secure important accounts. Use unique passwords and multifactor authentication, especially for email, financial, and mobile-carrier accounts. Never share one-time login codes with someone who contacts you unexpectedly.
- Watch for impersonation. A convincing message may refer to a real person or relationship. Confirm sensitive claims directly with the person or organization through an established channel.
- Ignore unsolicited “breach compensation” links. Contact AT&T through its official website or app if you need to check a notice or account issue.
- Monitor for suspicious account activity. If you receive an unexpected password reset, account-change alert, or request to transfer your number, contact the provider using its official contact information.
The disclosed data does not, by itself, make paid credit monitoring an automatic necessity for every customer. Follow any direct notice from AT&T and take action based on the information it says applies to you.
What security teams should take from the incident
For organizations holding sensitive customer or communications data, the broader lesson is to treat identity and data access as part of breach prevention—not just perimeter security. Use phishing-resistant multifactor authentication where available, rotate credentials exposed by infostealer malware, limit service-account privileges, and monitor for unusual bulk queries and exports. Keep audit logs and immutable backups, and segment especially sensitive datasets so a compromised account cannot reach everything.
Organizations should also decide in advance how they will handle extortion: preserve evidence, involve incident response, legal counsel, executive leadership, insurers, and law enforcement as appropriate, and review applicable sanctions and legal obligations before any payment decision. A deletion promise may be one factor in a risk decision; it is not a substitute for containment, notification, or remediation.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

