Case ActiveInvestigation Open

AT&T, Inc. Data Security Incident

DE · AG Filing: Jul 29, 2026

Investigation Active — If you were affected, free legal review is available. No obligation.

Free Review →
Filing Window Open

Received a Notice Letter?

Cases are filed first-come, first-served. Submit now for a free attorney review — no cost, no obligation.

No attorney-client relationship is created by submitting this form. Attorney Advertising.

Join the Class Action Lawsuit

Learn how to participate in the class action and what compensation you may be entitled to.

Join the Class Action →

Received a notice letter?

Use our verification tool to confirm your letter matches this official AG filing.

Verify My Notice Letter

This case file references a public filing made with the state filing in DE. This website is not affiliated with, endorsed by, or operated by any state government agency.

Exposed Data — What's at Risk

Based on the data types reported in this filing, affected individuals face the following specific risks:

SIM Swap & Vishingmedium risk

Phone numbers exposed in breaches are used for SIM swapping attacks — hijacking your number to bypass two-factor authentication on financial accounts.

Quick Facts

State Filed
DE
Date Reported to AG
Jul 29, 2026
Date of Breach
Not
Records Affected
Not disclosed
Status
Investigation Open
Last Updated
Jul 29, 2026
Data Types Exposed
NameEmail AddressMailing AddressBilling AddressAccount NumberPasswordPayment Card InformationPurchase HistoryPhone Number

What Happened

AT&T, Inc. was responsible for safeguarding the personal data of its customers and employees. According to a DE state filing, AT&T, Inc. experienced a data security incident affecting an undisclosed number of individuals, exposing financial account information and payment data. This breach was recently disclosed and the window for legal action is open now.

AT&T, Inc. appears to be a major telecommunications and technology company that provides wireless, broadband, and digital services to millions of consumers. In the course of delivering these services, the company typically collects and stores sensitive customer information, including names, billing addresses, account credentials, and financial or payment card details. Official records show that a data security incident affecting this infrastructure was formally reported to the Delaware Attorney General in 2026. If you received a data breach notification letter in the mail, it means your personal information may have been involved in this security event. This page is designed to help you understand the nature of the incident and the specific types of data that may have been exposed.

Are You One of the Victims?

You may have been affected by the AT&T, Inc. data breach if:

  • You received a written data breach notification letter from AT&T, Inc.
  • You are or were a customer, patient, or employee of AT&T, Inc.
  • Your information was held by AT&T, Inc. in DE
  • Your bank or payment card data was potentially exposed

Applicable State Law

This breach was reported under the Delaware Online Privacy and Protection Act, which mandates notification to affected individuals and establishes your right to seek damages.

Received a notification letter from AT&T, Inc.?

Read our dedicated guide — what the letter means and exactly what to do.

Read Letter Guide →

Frequently Asked Questions

Do I need proof that my data was misused to file a claim against AT&T, Inc.?

No. Under Delaware Online Privacy and Protection Act and federal law, the unauthorized exposure of your personal data — regardless of whether it has been actively misused — can be sufficient grounds for a claim. The breach itself is the injury.

How much does filing a claim cost?

Nothing. The Law Office of David S. Harris handles data breach cases on contingency — you pay zero upfront and owe nothing unless compensation is recovered.

My financial account data was exposed. Can the bank recover my losses?

Banks may reverse fraudulent charges, but they are not obligated to compensate you for time lost, stress, or indirect damages. A class action claim against the breached company can recover those additional categories of harm.

Is there a deadline to file a claim?

State statutes of limitations for data breach claims typically run 2–4 years from the date of the breach or its discovery. Because this breach was recently disclosed, the window is open — but acting early preserves your options and strengthens the case.

What if AT&T, Inc. offered me free credit monitoring after the breach?

Accepting free credit monitoring from AT&T, Inc. does not waive your right to pursue legal action unless you signed a specific release waiving claims. In most cases, victims who accepted monitoring can still file.

"According to a state filing in DE on July 29, 2026, this breach affected not publicly disclosed individuals."

View official DE AG filing →

AT&T, Inc. breach?

Free case review · No fee unless you win

Call Now
Made with AI in Macaly