Key Takeaways

  • A U.S. federal district court judge has preliminarily approved a $177 million settlement between AT&T and plaintiffs who filed lawsuits last year over two massive data security incidents affecting millions of customers.
  • The multiple lawsuits were consolidated into a single class action, presided over by Judge Ada Brown of the U.S. District Court for the Northern District of Texas. According to a Friday (Nov. 15) order, the judge has scheduled a hearing for Dec. 3 to consider whether to grant final approval to the settlement.
  • An AT&T spokesperson said in an email: "While we deny the allegations in these lawsuits that we are responsible for these criminal acts, we have agreed to settle to avoid the costs and uncertainties of prolonged litigation."

Deep Dive

This consolidated class action highlights an issue of growing concern to corporate leaders: the rising costs of cybersecurity threats and data breaches.

Data from the FBI's Internet Crime Complaint Center shows that in 2024, the center received 859,532 complaints of suspected internet crimes,reporting losses exceeding $16 billion, a 33% increase from the previous year. That data comes from a report released in April.

"Cybersecurity is not just an IT issue or a crisis scenario in an emergency plan, but a continuously growing business concern with real financial impacts, including potential costs such as incident response, legal liability, reputational damage, and revenue loss due to loss of consumer trust," wrote EY cybersecurity consultants Tunde Lawson and Jaime Kipnes in a related article in April.(Article link)

The two authors said that mitigating cyber risks and incorporating them into an organization's long-term financial strategy is a shared mission among multiple C-suite executives, including the CFO. The CFO "is uniquely positioned to quantify these risks and estimate the costs of incidents."

They wrote that CFOs, working in tandem with chief information security officers, can "better understand the probability and exposure of risks, set metrics for spending and return on investment, and make recommendations on prioritizing cybersecurity spending."

According to UK-based consultancy Cyber Management Alliance, AT&T was one of the companies that reportedthe largest cyberattackslast year.

AT&T's proposed settlement includes: $149 million to resolve class action claims related to a breachdisclosed in March 2024; the remaining $28 million is to compensate class members affected by anotherAT&T data breach disclosed in July 2024.

"Plaintiffs and class members are foreseeable victims of AT&T's inadequate data security practices, and it is equally foreseeable that AT&T's failure to provide timely and adequate notice of the data breaches will cause plaintiffs and class members to suffer the harms described in this complaint," the consolidated class action complaint filed last month said.

In thepublic noticeregarding the first breach, the telecom giant said it determined that "specific fields" of company data were included in a dataset posted on the "dark web." The notice said up to 73 million current and former customers were affected by the incident.

According to a set offrequently asked questionsreleased by the company at the time, the leaked data varied by customer and account, but could include full names, email addresses, mailing addresses, phone numbers, Social Security numbers, dates of birth, and AT&T account numbers and passwords.

The incident triggered a wave of class action lawsuits. In June 2024, the U.S. Judicial Panel issued an orderconsolidatingthe cases in the U.S. District Court for the Northern District of Texas.

After disclosing the second data breach, the company faced another wave of lawsuits. According to asecurities filing, the incident exposed six months of phone and text records of "nearly all" AT&T cellular customers in 2022.