The Federal Communications Commission (FCC) has reached a $13 million settlement with AT&T to resolve an investigation into whether the telecommunications giant failed to protect customer data after was breached three years ago.
See also: AT&T denies data leak allegations

The FCC investigation also examined the integrity of AT&T's supply chain and whether the telecommunications giant engaged in poor privacy and cybersecurity practices.
The massive data breach investigated by the FCC occurred in January 2023, when threat actors accessed customer data approximately 9 million AT&T wireless accounts stored by a vendor contracted to create personalized video content, including billing and marketing videos.
The CPNI data exposed in the January 2023 breach included customer names, wireless account numbers, phone numbers, and email addresses.
Although the vendor was supposed to destroy or return the data after the contract expired—years before the breach—it failed to do so. It was found that AT&T had inadequately monitored the vendor’s compliance with their contractual obligations.
See also: AT&T: Massive service outages in many areas
In addition to the settlement, AT&T also agreed to strengthen its data governance practices to protect its consumers' sensitive data from similar vendor data breaches in the future.

The consent decree requires AT&T to implement a comprehensive Information Security Program that includes broad customer data protections, improve data inventory processes to track data shared with vendors, ensure vendors follow retention and disposition rules for customer information, and conduct annual compliance audits to assess AT&T's compliance with these requirements.
The Chief of the Enforcement Bureau, Loyaan A. Egal, also underscored the importance of the case, noting that “communications service providers have an obligation to reduce the attack surface and entry points that threat actors seek to exploit in order to gain access to sensitive customer data.”
“Protecting our customers’ data remains one of our top priorities. A vendor we used in the past experienced a security incident last year that exposed data about some of our wireless customers,” an AT&T spokesperson said.
See also: Access Sports breach affects data of 88,000 users
In today’s digital age, data breaches, such as the one AT&T settled through the settlement, have become a significant and concerning issue for both consumers and organizations. A data breach occurs when unauthorized individuals gain access to sensitive, protected, or confidential data. This can include personal information such as names, social security numbers, and credit card information, or corporate data such as trade secrets and information. The consequences of a data breach can be severe, leading to financial losses, reputational damage, and legal ramifications. It underscores the critical need for strong cybersecurity measures and the importance of educating individuals and employees about secure data practices.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
