AT&T Settlement (Kroll): Claims, Payment Delays, and Covered Breaches

The AT&T Kroll settlement is a $177 million class action deal resolving claims from two 2024 AT&T data breaches, with Kroll Settlement Administration LLC handling notices, claims, and eventual payments. As of mid-2026, the court has not granted final approval, the claim window has already closed, and no money has been distributed.

The case, In re AT&T Inc. Customer Data Security Breach Litigation (MDL No. 3:24-md-03114-E), is before Judge Ada Brown in the U.S. District Court for the Northern District of Texas. A final approval hearing was held on January 15, 2026, and ran six hours. Five months later, Judge Brown still had not ruled.

What You Could Have Claimed

The $177 million fund is divided into two pools, one for each breach. The first pool holds $149 million for people whose personal information appeared on the dark web in the March 2024 incident. The second pool holds $28 million for account holders and users whose call and text metadata was taken in the July 2024 Snowflake breach.

Class members could file for one of two payment types from the relevant pool:

  • Documented losses. Claimants who could show specific financial harm tied to the breach could seek up to $5,000 from the first pool or up to $2,500 from the second. Anyone affected by both breaches could claim up to a combined $7,500.
  • Tiered cash payments. Claimants without documented losses receive a pro rata share of whatever remains in the relevant pool after fees, costs, and service awards. In the first pool, people whose Social Security numbers were exposed are paid at five times the rate of those whose Social Security numbers were not involved.

The claim deadline was December 18, 2025. More than two million class members filed claims before it closed. Only 1,556 people opted out, and 15 formal objections were submitted. If you did not file by December 18, 2025, you are not in line for a payment.

Why No Payments Have Been Made

Two things have to happen before Kroll can send money. First, Judge Brown must grant final approval to the settlement. As of June 2026, she has not ruled, despite the January hearing. Second, any appeals from that ruling have to run their course. The settlement website notes that appeals “can take time,” and no projected payment date has been announced.

Individual payment amounts are also unknown. Final per-person figures depend on how many valid claims Kroll accepts and how much the court awards in attorney fees, costs, and service awards. Plaintiffs’ lawyers have asked for a combined $59 million in fees, roughly one-third of the fund. The Lanier team requested $49.67 million in fees plus about $565,000 in costs; the Ostrow team requested $9.33 million in fees plus about $231,000 in costs. Those requests were argued at the January hearing and remain pending along with final approval.

Checking on a Claim You Already Filed

Kroll is processing submitted claims while the court decides. If you filed before the deadline, you can check status through the settlement website at telecomdatasettlement.com or by calling Kroll at (833) 890-4930. Written correspondence goes to:

AT&T Data Incident Settlement
c/o Kroll Settlement Administration LLC
P.O. Box 5324
New York, NY 10150-5324

Legitimate email notices come from attsettlement@e.emailksa.com. Messages from any other address purporting to be from the settlement should be treated with caution.

Which Breaches This Covers

The settlement covers two separate incidents AT&T disclosed in 2024. The March 30, 2024 disclosure involved a data set posted to the dark web with information dating to 2019 or earlier, affecting about 7.6 million current and 65.4 million former AT&T account holders. Exposed fields included names, addresses, phone numbers, email addresses, dates of birth, Social Security numbers, account passcodes, and billing account numbers. AT&T said it had not determined whether the data originated from its own systems or a vendor.

The July 12, 2024 disclosure involved AT&T’s workspace on the Snowflake cloud platform, accessed between April 14 and April 25, 2024. Hackers took call and text metadata for nearly 110 million customers covering May 1 through October 31, 2022, and January 2, 2023. That data included the phone numbers customers interacted with, the number of calls and texts, and aggregate call durations. It did not include the content of communications, Social Security numbers, or names, though phone numbers can often be tied to identities through public tools.

If your exposure came from a different AT&T incident or a different company’s breach, this settlement does not cover it.