AT&T Enters into Largest Data Breach Settlement with FCC to Date
Time 2 Minute Read

On April 8, 2015, the Federal Communications Commission announced a $25 million settlement with AT&T Services, Inc. (“AT&T”) stemming from allegations that AT&T failed to protect the confidentiality of consumers’ personal information, resulting in data breaches at AT&T call centers in Mexico, Colombia and the Philippines. The breaches, which took place over 168 days from November 2013 to April 2014, involved unauthorized access to customers’ names, full or partial Social Security numbers and certain protected account-related data, affecting almost 280,000 U.S. customers.

In addition to the $25 million civil penalty, the Consent Decree requires AT&T to:

  • notify all affected customers;
  • pay for credit monitoring services for customers who were affected by the breaches in Colombia and the Philippines;
  • bolster its privacy and data security practices, including by appointing a senior compliance manager, conducting a privacy risk assessment, implementing an information security program, and training employees on its privacy policies; and
  • file regular compliance reports with the FCC.

This settlement is the FCC’s largest privacy and data security enforcement action to date and according to FCC Chairman Tom Wheeler, demonstrates that “the Commission will exercise its full authority against companies that fail to safeguard the personal information of their customers.”

You May Also Be Interested In

Time 3 Minute Read

The Connecticut Attorney General recently issued a legal memorandum regarding the application of existing Connecticut laws, such as the Connecticut Data Privacy Act, to the use of artificial intelligence.

Time 3 Minute Read

On March 20, 2026, Oklahoma Governor Kevin Stitt signed SB 546 into law, enacting the Oklahoma Consumer Data Privacy Act, which will take effect on January 1, 2027.

Time 2 Minute Read

On February 5, 2026, Alabama Governor Kay Ivey signed Alabama House Bill 161, the App Store Accountability Act, establishing age categorization, age verification and parental consent requirements for mobile application marketplace providers operating in Alabama, effective January 2027.

Time 2 Minute Read

On March 5, 2026, the California Privacy Protection Agency announced that the agency had reached a settlement with Ford Motor Company resolving an enforcement action against the company that alleged noncompliance with the California Consumer Privacy Act’s opt-out of sale/sharing rights.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page