Decoding the business of technology.
examnity.
Cybersecurity

Should You Join the AT&T Data Breach Settlement or Opt Out?

There's a very specific nausea that hits the moment you open your inbox and see those four words: Your data was compromised.

Should You Join the AT&T Data Breach Settlement or Opt Out?

Let's break down exactly what's on the table, what AT&T has actually offered, and whether you should take it or walk.

The Scale of Exposure: From 73 Million Records to Call Log Metadata

First, let's get the anatomy of this disaster straight—because AT&T didn't have just one breach. It had two, back-to-back, in the span of a single quarter, and conflating them is the single biggest mistake I see consumers making right now.

The March 2024 breach is the big one. On March 30, AT&T confirmed that a dataset containing records of approximately 7.6 million current account holders and 65.4 million former customers—73 million people total—had been leaked. The exposed data wasn't some low-risk breadcrumb trail of email addresses. We're talking full names, Social Security Numbers, email addresses, mailing addresses, phone numbers, and AT&T account passcodes. If you've ever held an AT&T account, the odds are uncomfortably high that your SSN is floating around in a dataset that's been passed through breach forums like a hot potato—some of this data reportedly dates back to 2021 or earlier.

Then, barely three months later, the July 2024 breach landed. This one involved the illegal download of call and text message metadata—not the content of your messages, not recordings of your calls, but the phone numbers you contacted, the timestamps, and the duration of every interaction between May 1 and October 31, 2022. Nearly every AT&T cellular customer was affected. This breach was tied to the Snowflake cloud storage incident, which also hit companies like Ticketmaster and Santander Bank. It's a different beast—less immediately dangerous than a stolen SSN, but a staggering privacy violation nonetheless.

The March and July 2024 breaches are separate incidents with separate legal tracks. Mixing them up will cost you real money in settlement decisions.

The critical distinction: the SSN leak exposes you to identity theft for years—potentially forever—while the call metadata breach reveals your communication patterns and social graph. Both are serious. Neither is acceptable from a carrier that charges premium rates and stores our most sensitive identifiers.

Analyzing the $60 Million Settlement for the 2023 Vendor Breach

Here's where things get genuinely confusing, and I need you to pay close attention—because a lot of the reporting out there is sloppy about which settlement applies to which breach.

The $60 million settlement that AT&T reached in June 2024 is for a completely different incident—a 2023 data breach involving a third-party marketing vendor that exposed records of 10.9 million customers. This one is finalized. The money is real. If you were among those 10.9 million people, you have a concrete decision to make.

Now, $60 million divided among 10.9 million affected users sounds substantial until you do the arithmetic. Before any per-person payout, legal fees and administrative costs eat a significant chunk—class-action settlements routinely see 25–33% of the total fund go to attorneys. What's left gets distributed among millions of claimants. In practice, individual payouts in cases like this often land somewhere between a few dollars and a couple hundred, depending on documented losses and the number of people who actually file claims versus those who sit on their hands.

Here's a quick comparison of what you're looking at depending on your situation:

ScenarioWhat You Get if You StayWhat You Risk if You Opt Out
2023 vendor breach (10.9M users, $60M settlement finalized)A modest payout—likely modest given the claimant pool—and one year of credit monitoringYou lose the guaranteed payout but retain the right to sue AT&T independently; legal costs are on you
March 2024 SSN breach (73M users, litigation still active)No settlement yet exists—staying in the class means you wait for whatever deal is eventually negotiatedOpting out now preserves your right to pursue individual claims later, potentially for significantly more
July 2024 call metadata breach (near-universal AT&T customer base)No settlement announced; litigation is in early stagesSame calculus as above—early opt-out keeps your options open

The math on the 2023 settlement isn't inspiring. If even half the 10.9 million affected users file claims, you're looking at individual payouts that might cover a month of your AT&T bill. The real value of the 2023 settlement—frankly—is the credit monitoring. One year of free identity theft protection is baseline, not generous, but it's something you don't have to shop for yourself.

The Trade-off: Free Credit Monitoring vs. Independent Litigation

AT&T's offer for the March 2024 breach follows the standard corporate playbook: one year of free credit monitoring and identity theft protection services. I've seen this script before—from Equifax, from T-Mobile, from every company that treats a catastrophic security failure as a PR problem to be managed rather than an engineering failure to be owned.

One year. For a breach involving Social Security Numbers.

Let me put this in perspective. Your SSN doesn't expire. It doesn't rotate like a password. A Social Security Number stolen in March 2024 is just as exploitable in March 2027, in 2030, in 2045. Offering one year of monitoring for a lifetime-identifier leak is like installing a smoke detector that automatically unplugs itself after 365 days. The gesture is real—I'm not saying credit monitoring is useless—but the coverage window is laughably mismatched to the actual threat horizon.

The alternative path—opting out and pursuing independent litigation—is expensive, slow, and uncertain. You'll need to hire your own attorney, front legal costs, and prove specific damages. That's a real barrier for most people. But here's the thing: the leverage of individual lawsuits is precisely what forces companies to negotiate meaningful settlements. If everyone takes the credit monitoring and shuffles along, AT&T absorbs this as a rounding error on its quarterly earnings call.

One year of credit monitoring for a stolen Social Security Number is a band-aid on a wound that never closes—the threat window is your entire lifetime.

I'm not going to sit here and tell you to hire a lawyer and go to war. That's a deeply personal calculation based on your financial situation, your risk tolerance, and whether you've already experienced concrete identity theft from this breach. But I am going to tell you that accepting AT&T's default offer without understanding what you're giving up is the one move I'd actively discourage.

Let's talk mechanics—because opting out isn't some vague act of protest. It's a specific legal procedure with real consequences, and getting it wrong means you're locked in whether you like it or not.

Opting out of a class-action settlement means you formally notify the court that you do not wish to be bound by the terms of the settlement agreement. In return, you retain your right to sue the defendant independently. You are no longer part of the class, which means you don't receive whatever payout the settlement provides—but you also aren't capped by it.

This matters enormously in the AT&T context because there is no finalized settlement for the March 2024 breach yet. The litigation is active. That means right now, affected users aren't choosing between a known payout and an unknown lawsuit—they're choosing between participating in whatever deal gets negotiated down the road and preserving the option to pursue their own claim.

Key considerations before opting out:

1. You need your own legal representation. Class-action attorneys work on contingency for the whole class; if you opt out, you're hiring and paying a lawyer yourself. Hourly rates for data breach litigation range from $300 to $700+, though many attorneys work on contingency for individual cases if the damages are substantial enough.

2. Document everything now. If you've experienced identity theft, fraudulent accounts opened in your name, or out-of-pocket costs for credit freezes, fraud alerts, or identity restoration services—start building that paper trail immediately. Individual claims succeed or fail on documented, provable damages.

3. Deadlines matter. Once a settlement for the 73-million-user breach is reached and preliminary court approval is granted, a deadline will be set for opting out. Miss that window, and you're in the class whether you wanted to be or not. Since no settlement has been announced yet, there's no opt-out deadline—but when one arrives, it'll likely give you 30 to 90 days to act.

4. There's no guarantee of a better outcome. Opting out doesn't mean you'll win more. It means you might win more—or you might spend thousands on legal fees and recover nothing. That's the gamble.

The March 2024 breach—73 million records, Social Security Numbers included—is the main event, and it's still playing out in the courts. No settlement. No payout numbers. No opt-out deadlines. What exists right now is a tangle of class-action lawsuits that will eventually either consolidate or be tried individually, with AT&T's legal team doing what every corporate defense team does: delay, narrow the class definition, and argue that actual damages are minimal.

Here's what I expect to happen, based on the pattern of every major data breach litigation I've tracked over the past decade: AT&T will eventually settle. The question is how much, and who gets what. The precedent from Equifax's 2017 breach—which affected 147 million people—resulted in a $425 million settlement that, after legal fees and administrative costs, offered affected consumers either free credit monitoring or a cash payout initially capped at $125 (which was later reduced to roughly $5–$6 per person due to the volume of claims). That's the playbook. That's the realistic floor.

The ceiling, if you opt out and litigate successfully, depends entirely on whether you can demonstrate concrete harm. Courts have historically been skeptical of "my data was stolen" as a standalone claim—they want to see fraudulent charges, denied loans, time and money spent on credit freezes and identity restoration. If you have that documentation, individual litigation becomes a real option. If you don't, the class-action settlement—whatever it turns out to be—might be your most practical path.

I've been testing and reviewing consumer technology long enough to recognize a pattern: companies that invest aggressively in security infrastructure—end-to-end encryption, zero-trust network architecture, aggressive patching schedules—rarely end up in these situations. AT&T's recurring breaches suggest something deeper than an isolated failure. They suggest a culture where security is a cost center to be minimized, not a core engineering mandate.

The smart home ecosystem—where devices from security cameras to smart thermostats increasingly route through major carrier networks—makes these breaches even more consequential. When your network provider leaks your SSN, the blast radius extends to every connected device and platform in your life.

The Verdict: What I'd Actually Do

I don't do fence-sitting, so here's my position:

If you were affected by the 2023 vendor breach (10.9 million users): Take the settlement. The payout will be modest, but the credit monitoring is free, and the cost-benefit of opting out for a potentially $15 check doesn't pencil out.

If you were affected by the March 2024 SSN breach (73 million users): Enroll in the free credit monitoring immediately—there's no reason not to, it costs you nothing. But don't sign anything that waives your future claims. Stay informed on the litigation. When a settlement is proposed, evaluate the terms carefully before accepting. If you have documented damages from identity theft, consult with an attorney who specializes in data breach litigation before any opt-out deadline arrives.

If you were affected by the July 2024 call metadata breach: The practical risk is lower than the SSN breach—metadata exposure is a privacy violation, not an identity theft catalyst. Watch the litigation, but don't lose sleep over this one the way you should over the SSN leak.

AT&T had every resource to prevent this. They chose not to. The least you can do is make an informed decision about what that choice is worth to you.

FAQ

Should I join the settlement for the 2023 vendor breach?
Yes, it is generally recommended to take the settlement. The individual payout is likely to be small, and the free credit monitoring provides a baseline of protection without the high costs of independent litigation.
Can I opt out of the March 2024 SSN breach settlement right now?
No, there is no settlement or opt-out deadline for the March 2024 breach yet. The litigation is still in the active stages.
What is the difference between the March 2024 and July 2024 breaches?
The March breach involved sensitive personal identifiers like Social Security Numbers, while the July breach involved call and text metadata, such as the numbers you contacted and the duration of those interactions.
What happens if I opt out of a class-action settlement?
By opting out, you are no longer bound by the settlement terms and lose the right to any payout from it, but you retain the right to pursue an independent lawsuit against the company at your own expense.
What should I do if I have experienced identity theft from the AT&T breaches?
You should document everything, including fraudulent accounts, denied loans, and any out-of-pocket costs for credit freezes or identity restoration. This evidence is essential if you decide to pursue an individual claim.