AT&T is facing new challenges as hackers appear to be exploiting the massive 2021 data breach that affected an estimated 70 million customers . This time, the attackers didn’t just republish the data. Instead, they combined scattered records to directly link Social Security Numbers (SSNs) and dates of birth to individual users, significantly increasing the risk of identification and exploitation.

AT &T confirmed to BleepingComputer that it is investigating the case, noting that the data appears to come from the known 2021 breach, but has been repackaged to gain new utility for cybercriminals.
See also: Lee Enterprises says 40,000 people affected by breach
"It is not uncommon for cybercriminals to reuse old data for financial gain. We have just learned of allegations that AT&T data is being offered for sale on dark web forums and are conducting a full investigation," an AT&T spokesperson said.
According to HackRead, the data was recently posted on a Russian-language hacking forum. The attacker claimed that the data is related to the more recent “AT&T Snowflake” breach of 2024, which leaked call records from 109 million users.
In the post, the hacker claims to have "cleaned" the data of fake numbers and decrypted sensitive personal information, such as SSNs and dates of birth, adding that the data came from a "backup" he had kept.
However, according to an analysis by BleepingComputer, the exposed database does not come from the Snowflake, but from the initial 2021 breach attributed to the ShinyHunters (at that time the hackers had tried to sell the data for $200,000).
See also: Hacker arrested for breaching 5,000 hosting accounts
In 2024, a new threat actor leaked for free , claiming to come from the ShinyHunters breach, once again exposing the personal information of millions of Americans. The exposed files included names, addresses, mobile phone numbers, as well as encrypted dates of birth and Social Security Numbers (SSNs). However, this time, the hackers went one step further: they combined separate files to reveal the encrypted data, creating complete identification profiles.
AT &T, although it had initially denied that its data had been breached, eventually confirmed that the 2021 leak affected 73 million customers.

According to BleepingComputer, the new leak includes all of the above and contains 88,320,017 lines of data, a number that reduces to 86,017,088 unique records after removing duplicates. Of these, 48,896,044 unique mobile phone numbers along with associated customer information.
The difference in numbers is attributed to the fact that many users appear to have multiple profiles, likely due to using the same phone number at different addresses.
The resurgence of the leak, without AT&T's internal data but with the addition of critical personal information in unencrypted form, highlights the value of stolen data in the cybercrime market.
The “new” leak, which is essentially a repackaged version of the AT&T data breach from 2021, is extremely concerning — not because it reveals anything new, but because it shows how the same leak can remain active and dangerous years later.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Coinbase breach linked to TaskUs in India
Users who haven't changed their mobile numbers or other details since 2021 are at higher risk. Especially in environments where social security numbers or dates of birth are still used for identification, the damage could be severe.
The AT&T case confirms an uncomfortable truth: Effective data breach doesn’t end with disclosure. It requires long-term monitoring, customer support, and—most importantly—transparency.
Source: www.bleepingcomputer.com
