AT&T Inc.
The AT&T Inc. Customer Data Security Breach litigation was centralized before Judge Sidney A. Fitzwater in the Northern District of Texas in June 2024, consolidating claims arising from data security incidents affecting AT&T customers, including reports of unauthorized access to a large volume of customer call and text metadata and certain account information. With 140 pending actions, this is a substantial docket within the telecommunications-sector breach category, reflecting the scale of AT&T's customer base and the breadth of the reported incident.
Telecommunications-sector data-breach MDLs, including this one, tend to follow a fairly well-established procedural arc given the volume of prior carrier-breach litigation: early motion practice addressing standing and the sufficiency of alleged harm from metadata or account-data exposure (as opposed to more sensitive categories like financial or health information), followed by class-certification proceedings and, in many prior carrier dockets, a negotiated settlement framework. That established pattern provides useful comparative context for how this docket is likely to develop, even though its own factual record and any eventual settlement terms remain specific to this proceeding.
A notable open question in call/text metadata breach litigation generally — including in this docket — is how courts value harm from metadata exposure (which reveals who a customer communicated with and when, without necessarily exposing message content) relative to breaches involving more traditionally sensitive categories like financial account numbers or medical records. Criterica Intelligence's platform tracks this kind of harm-categorization question across the telecommunications-breach MDL landscape, since it materially affects how damages theories and settlement value are likely to develop in a docket like this one. A companion capital brief on this docket is available through Criterica Capital.
Reports indicate unauthorized access to a large volume of customer call and text metadata, along with certain account information, through AT&T's systems or a third-party vendor it used.
Telecommunications-sector breach MDLs tend to follow a well-established procedural arc — standing motions, class certification, and often a negotiated settlement — given the volume of prior carrier-breach dockets, which provides useful comparative context.
How courts value harm from call/text metadata exposure — which reveals communication patterns without necessarily exposing message content — relative to breaches involving more traditionally sensitive data like financial or medical records.
Yes — across the telecommunications-breach MDL landscape, since how courts categorize metadata harm materially affects damages theories and settlement value in dockets like this one.
Statistics shown reflect historical or illustrative model outputs derived from real case data. They are not predictions or guarantees of any individual outcome. Litigation results depend on facts, jurisdiction, judge, and counsel, and vary case by case. Model accuracy is subject to selection effects and changing legal dynamics.