AT&T over the weekend admitted to having been hit by a cyberattack impacting account information for more than 70 million current and former customers, with that content having been dumped onto the dark web.

The telecommunications giant reported that “data-specific fields were contained in a data set released on the dark web approximately two weeks ago.” AT&T notes that the breach may have included access to full names, email addresses, mailing addresses, phone numbers, social security numbers, dates of birth, AT&T account numbers and passcodes.

AT&T’s initial assessment of data indicates its information from 2019 or earlier, and from approximately 7.6 million current AT&T accounts and approximately 65.4 million former accounts. However, the carrier stated that it’s not sure where the data was pilfered from and that it “does not have evidence of unauthorized access to its systems resulting in exfiltration of the data set.”

AT&T is reaching out to those impacted by the breach with recommendations to reset passwords. The carrier is also offering free identity theft and credit monitoring services.

The security breach comes just over a month after AT&T’s network suffered a nationwide outage blamed on “application and execution of an incorrect process used while working to expand our network.” The carrier did notably state that the outage “was not a cyberattack.”

AT&T's cyberattack has company

The AT&T cyberattack also comes less than a year after rival T-Mobile US was hit by one of numerous security breaches.

The T-Mobile US breach last May impacted just over 800 customers, exposing customer names, contact information, account numbers and associated phone numbers, T-Mobile account PINs, Social Security numbers, government IDs, dates of birth, balances due, internal codes used by T-Mobile US and the number of lines of service.

However, it followed a much larger attack that was reported in January 2023, which impacted 37 million postpaid and prepaid customers and customers from Google’s Fi mobile virtual network operator (mobile virtual network operator (MVNO)) service that runs through T-Mobile US.

T-Mobile US explained in a Securities and Exchange Commission (SEC) filing that the attackers were able to gain access to “basic customer information,” which it tried to downplay by stating “nearly all of which is the type widely available in marketing databases or directories.”

That accessed information included names, billing addresses, emails, phone numbers, dates of birth, account numbers, and information such as the number of lines on an account and service plan features. The carrier confidently stated, “no passwords, payment card information, social security numbers, government ID numbers, or other financial account information were compromised.”