AT&T Data Breach Exposes Phone Numbers and Financial Account Access

Published: 13 September 2026
Other Commercial data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: 30th March 2024

A former AT&T retail employee in Portland, Oregon used his system access to perform unauthorized SIM swaps, letting outside criminals intercept authentication codes and access customer bank accounts. He was sentenced to 16 months in federal prison. Affected individuals should freeze their credit, monitor bank accounts closely, and watch for phishing attempts referencing AT&T.

CompanyAT&T
IndustryOther Commercial
Data Types ExposedPhone Numbers, Authentication Codes, Bank Account Access, Financial Account Information
People AffectedNot Publicly Disclosed
Attack MethodInsider Access
Regulators NotifiedDelaware Attorney General, Wisconsin Department of Agriculture, Trade and Consumer Protection

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the AT&T Data Breach?

A former AT&T retail store worker used his internal system access to carry out unauthorized SIM swaps on customer accounts. As a result, cybercriminals were able to hijack victims’ phone numbers and intercept the one-time codes used for account verification. This access ultimately let outside criminals drain money from customer bank accounts.

The worker, identified as Kenneth Carter, 44, carried out these SIM swaps from a store location in Portland, Oregon. Because he had legitimate employee access to AT&T’s customer systems, Carter could reassign a victim’s phone number to a device controlled by criminals without the customer’s knowledge. This type of insider abuse is especially dangerous because it bypasses normal external security defenses entirely.

Once a criminal controls a victim’s phone number, they can intercept text messages and calls used for two-factor authentication. This means they can reset passwords and approve fraudulent transactions at banks and other financial platforms. Investigators determined that Carter carried out these swaps as a paid side arrangement with outside cybercriminals, essentially selling his access for profit.

The scheme came to light through a federal investigation into SIM-swap fraud affecting numerous victims nationwide. Following the investigation, Carter was prosecuted and sentenced to 16 months in federal prison for his role. Although the breach discovery date has not been publicly disclosed, the case demonstrates how insider threats can pose serious risk to any large telecommunications provider.

Who was affected?

This breach affected AT&T customers whose phone numbers were targeted for SIM-swap fraud at or through the Portland store where Carter worked. Because SIM swaps require the perpetrator to specifically select and target a phone number, victims were likely not random. Instead, many appear to have been chosen because they were believed to hold valuable financial accounts.

The exact number of affected individuals has not been publicly disclosed. In addition, the geographic scope beyond the Portland, Oregon store location remains unclear from available records. However, because SIM-swap fraud is often used against people with substantial banking or cryptocurrency holdings, victims may span a range of ages and financial backgrounds.

It is not known whether any affected customers were minors. Nevertheless, anyone who was an AT&T wireless customer with service tied to that Portland store during the relevant period should consider themselves potentially at risk. AT&T account holders nationwide should also stay alert, since SIM-swap techniques can be used against any wireless carrier’s customers.

What Information Was Potentially Exposed?

The core harm in this incident came from unauthorized control over customers’ phone numbers. However, this type of access can cascade into exposure of far more sensitive personal and financial information once criminals gain control of the accounts tied to that phone number.

  • Phone numbers and associated account access
  • Authentication codes sent via text message or call
  • Bank account access and financial account information
  • Potentially linked personal account credentials

Because authentication codes are the gateway to nearly every online financial account, this type of breach can be more damaging than a typical data leak. Once criminals control a victim’s number, they can request password resets on banking apps, investment platforms, and cryptocurrency exchanges. As a result, many SIM-swap victims discover unauthorized withdrawals only after the money is already gone.

In addition to direct financial theft, victims often face secondary risks. For example, criminals may use the hijacked number to access email accounts, social media, or other personal accounts linked to that phone. This can lead to further identity theft, unauthorized account creation, or long-term monitoring of a victim’s digital identity well after the initial fraud occurs.

What is the company doing?

Following the discovery of Carter’s scheme, law enforcement pursued a federal investigation that led to his prosecution and sentencing. AT&T cooperated with authorities in identifying the fraudulent activity tied to the Portland store. The company also took internal action against the employee responsible once his unauthorized access was uncovered.

AT&T has also filed formal notifications with state regulators regarding this incident. The company notified the Delaware Attorney General as part of its regulatory disclosure obligations. AT&T additionally filed with the Wisconsin Department of Agriculture, Trade and Consumer Protection on March 30, 2024.

Going forward, AT&T likely faces pressure to strengthen internal controls that limit employee access to sensitive account functions like SIM transfers. This may include stricter monitoring of employee activity and additional verification steps before a SIM swap can be processed. Customers affected by this specific scheme should watch for direct notification from AT&T regarding steps taken on their individual accounts.

What Should Affected Individuals Do?

Monitor Your Credit Reports

Affected individuals should pull their credit reports from all three major bureaus and review them closely. Because SIM-swap fraud often leads to unauthorized financial activity, new accounts or inquiries you don’t recognize could be a red flag. You can request free credit reports through AnnualCreditReport.com.

Checking your credit report regularly helps you catch fraud early, before it spirals into a larger problem. In addition, reviewing your report every few months for the next year is a smart habit after any incident involving financial account exposure. This gives you a clearer picture of any unauthorized activity tied to your identity.

Consider a Fraud Alert or Credit Freeze

Because this breach involved potential access to bank accounts, affected individuals should strongly consider placing a fraud alert or credit freeze on their credit files. A fraud alert requires lenders to verify your identity before extending new credit. A credit freeze goes further by blocking new account openings entirely until you lift it.

To set up either protection, contact Equifax, Experian, and TransUnion directly. This process is free and can be done online or by phone. As a result, even if a criminal has your phone number and personal details, they will have a much harder time opening new accounts in your name.

Watch for Phishing and Social Engineering Attempts

Criminals involved in SIM-swap schemes often follow up with phishing messages designed to extract more personal information. Therefore, be cautious of unexpected texts, calls, or emails asking you to verify account details or click a link. Legitimate companies rarely ask for sensitive information this way.

If you receive a suspicious message referencing your AT&T account or banking activity, do not respond directly. Instead, contact the company through its official customer service number listed on your bill or its verified website. This simple step can prevent a second wave of fraud following the initial breach.

Secure Your Financial Accounts Directly

Anyone who suspects their phone number was involved in a SIM swap should contact their bank and other financial institutions immediately. Ask about enabling additional authentication methods that do not rely solely on text messages, such as authenticator apps. This reduces the risk of a repeat attack using the same technique.

Additionally, review recent account statements for unauthorized transactions and report anything suspicious right away. Many banks offer fraud protection guarantees, but timely reporting is often required to qualify. Taking these steps quickly can limit your financial losses and help investigators track related fraudulent activity.

Consult a Data Breach Attorney

If you experienced financial losses or identity theft tied to this incident, it may be worth speaking with a data breach attorney. Many offer free case evaluations to determine whether you have grounds for compensation. This is especially relevant if your losses were substantial or if unauthorized access has caused ongoing problems.

An attorney can also help you understand your rights under state and federal consumer protection laws. Because insider-caused breaches can carry unique legal implications, professional guidance may help clarify your options moving forward. This step costs nothing to explore and could help you recover losses tied to the fraud.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



More Information

Official data breach notification report (PDF) from Delaware Attorney General

View the public data breach notification listing from Wisconsin Department of Agriculture, Trade and Consumer Protection

Related Data Breaches

Check other recent data breach notifications →