DALLAS — AT&T said Saturday that a large data set posted on the dark web contains information associated with about 73 million current and former customers, forcing the telecommunications company to reset account passcodes and investigate how the records were obtained. The company said approximately 7.6 million current account holders and 65.4 million former account holders are affected. AT&T's notice said the information appears to be from 2019 or earlier and that it is not yet clear whether the records originated from AT&T itself or from one of its vendors. The company said it has no evidence so far that the incident has materially affected its operations.

The disclosure follows renewed scrutiny of a data set that security researchers have connected to a trove first discussed publicly several years ago. AT&T is contacting affected customers, offering credit monitoring where appropriate and directing users to updated security guidance. Its customer support page explains the passcode-reset process and warns customers to remain alert for fraud. Reuters and the Associated Press reported Saturday that the exposed records include personal information and, in some cases, Social Security numbers.

Why the passcode reset matters

AT&T's most immediate action is resetting passcodes for current customers whose credentials may be represented in the data. Those numerical passcodes are used to authenticate customers in account-support interactions and can become especially sensitive when combined with names, phone numbers, addresses or other identifying information. A compromised passcode does not by itself provide access to every service, but it can add another useful credential for criminals attempting account takeover or social-engineering attacks.

The company is also advising customers to change passwords, review account activity and use multi-factor authentication where available. The broader risk extends beyond AT&T because leaked identity data can be combined with information from other breaches. A criminal who knows a customer's name, phone number, Social Security number and historical address may be able to construct convincing phishing messages, attempt credit fraud or impersonate the customer with another institution.

A data set with a disputed history

Questions about the origin of the records complicate the incident. A hacker claimed in 2021 to possess data connected to tens of millions of AT&T customers, while the company said at the time that the information did not appear to come from its systems. The newly circulated database has renewed that dispute. TechCrunch reported on March 22 that researchers had begun examining the re-released material and found records that appeared authentic for some AT&T customers.

AT&T's Saturday statement is therefore significant because the company is now acknowledging that the data set contains information associated with millions of its customers even while the precise source remains unresolved. That distinction matters for both cybersecurity analysis and legal responsibility. If the information came directly from an AT&T system, investigators would focus on the company's own controls and breach history. If it came from a vendor or another source, responsibility and remediation could be distributed across multiple entities.

Old data can still create current risk

The fact that the records appear to date from 2019 or earlier does not make them harmless. Phone numbers, names, birth dates and Social Security numbers can remain useful for years. Unlike passwords, many identity attributes cannot easily be changed. Former customers may face nearly the same fraud risk as current customers even though they no longer have an active AT&T account.

That is one reason the size of the affected population matters. Seventy-three million records represent a pool large enough to support automated fraud campaigns and targeted phishing alike. The risk is not that every affected customer will be victimized; it is that attackers can cheaply test stolen information across banks, retailers, wireless carriers and online services until some attempts succeed. NPR's contemporaneous coverage emphasized that the company is still working to determine the source while beginning direct customer notifications.

Telecom security carries unusual identity consequences

Wireless carriers hold a combination of billing data, phone numbers, device identifiers and authentication information that can make breaches particularly consequential. Control of a phone number can also intersect with account recovery for unrelated services. Criminals have exploited so-called SIM-swap attacks to take over numbers and intercept one-time authentication codes, making telecom account security an important layer in the broader digital identity system.

AT&T has not said that the newly disclosed data set resulted in SIM swaps or account takeovers. But the incident adds to pressure on large communications providers to minimize retained sensitive data, protect vendor connections and ensure that customer-service authentication is resilient even when pieces of personal information have leaked elsewhere.

The disclosure also comes only weeks after AT&T experienced a major nationwide wireless outage in February. The company attributed that service disruption to an incorrect network process rather than a cyberattack. The two events are technically separate, but together they reinforce the degree to which communications infrastructure depends on both operational resilience and information security.

Investigation now turns to provenance and harm

AT&T says internal and external cybersecurity experts are investigating. Key questions include when the data was originally collected, whether the exposed fields came from one system or several, whether a third party was involved, and how many records contain particularly sensitive identifiers. Regulators and state attorneys general may also examine whether notification and security obligations were met once the provenance is established.

For customers, the practical guidance is immediate even though the forensic picture is not. Current users whose passcodes were reset should create new credentials, monitor bills and account changes, and be skeptical of messages claiming to be from AT&T. Current and former customers should consider monitoring credit reports and financial accounts if they receive notice that Social Security numbers or other sensitive identifiers were exposed.

As of Saturday, the central fact is no longer in dispute: AT&T says records associated with roughly 73 million people are circulating on the dark web. What remains unresolved is how that data got there, exactly which systems were involved and how much harm the exposure will ultimately produce.