Moody's Warns: AT&T's Latest Data Breach May Trigger Customer Churn
Moody's Ratings noted on Monday that AT&T's recently disclosed massive data breach constitutes a 'credit negative' factor, raising serious questions about its network risk management practices. The breach involved call and text records from nearly six months in 2022, affecting 'almost all' AT&T cellular network customers. Moody's warned that customers may switch to competitors due to privacy concerns. AT&T already faces a proposed class-action lawsuit, and a separate data breach disclosed in March has already triggered multiple lawsuits.

Briefing at a Glance
- Credit rating agency Moody's said Monday that the massive cybersecurity breach disclosed by AT&T last week is a "credit negative" factor for the company.
- The breach exposed call and text records for "nearly all" AT&T cellular customers over a six-month period in 2022, the telecom giant said in a securities filing on July 12.
- "This latest disclosed AT&T breach is a credit negative event that raises serious questions about the company's cyber risk governance and management practices," Neil Mack, vice president and senior analyst at Moody's Ratings, said in an emailed statement. "The key risk is customer churn, as customers may view their private data as more vulnerable at AT&T than at wireless competitors."
Deeper Insight
Cyberattacks can weaken the creditworthiness of companies, organizations, and governments, hitting revenue and raising costs, according to a June report from Moody's. The report was shared with CFO Dive.
"Business disruption, customer attrition, or theft of intellectual property can disrupt revenue streams," the report said. "At the same time, financial expenses may increase due to attack mitigation costs, regulatory fines, and legal settlements."
AT&T's disclosure last week has already triggered a proposed class action lawsuit. Plaintiff Dina Winger, an AT&T cellular customer, filed suit on July 12 in the U.S. District Court for the Northern District of Texas on behalf of "all others similarly situated," alleging that the personal identifying information of breach victims "would not have been compromised but for the errors and omissions of AT&T's obligations to Plaintiff and the Class."
"AT&T's failure to exercise reasonable care in protecting the personal identifying information it holds or controls foreseeably will result in Plaintiff and the Class suffering one or more forms of injury. This data breach was also foreseeable given the known high frequency of cyberattacks and data breaches in the telecommunications industry," the complaint said.
Winger is represented by the law firms Mathias Raphael PLLC and Foster Yarborough PLLC.
The cybersecurity incident comes as AT&T already faces multiple class action lawsuits over another massive consumer data breach disclosed in March.
"There will be more court cases," David Vladeck, a Georgetown University law professor and former director of the Federal Trade Commission's Bureau of Consumer Protection during the Obama administration, said in an email. "They will allege that AT&T should have had stronger defenses, and in any event, why did the company retain information of little use? Ultimately, it is hard to see what viable defense the company has."
AT&T did not immediately respond to a request for comment.
No 'Material Impact' from Latest Breach
In last week's securities filing, AT&T said it learned on April 19 that a threat actor claimed to have illegally accessed and copied AT&T call logs. The company said an internal investigation determined that the hacker illegally accessed an AT&T workspace on a third-party cloud platform and, between April 14 and April 25, obtained files containing records of customer call and text interactions from May 1 to October 31, 2022, and January 2, 2023.
"As of the date of this filing, this incident has not had a material impact on AT&T's operations, and AT&T does not believe this incident is reasonably likely to materially impact the company's financial condition or results of operations," the company said.
According to the filing, the compromised records include telephone numbers and cumulative call duration data, but do not include the content of calls or texts, social security numbers, dates of birth, or other personal information or personal identifying information. "While the data does not include customer names, there are often ways to use publicly available online tools to find the name associated with a specific telephone number," the filing said.
AT&T's previous breach led to data from 7.6 million current account holders and about 65.4 million former customers being posted on the "dark web," the company said in a March notice. The compromised data varied by customer and account, but may have included full names, email addresses, mailing addresses, phone numbers, social security numbers, dates of birth, and AT&T account numbers and passcodes, according to a series of FAQs the company published at the time.
That incident sparked a series of proposed class action lawsuits. In June, the Judicial Panel on Multidistrict Litigation issued an order consolidating the cases in the U.S. District Court for the Northern District of Texas.
It is too early to tell what legal impact AT&T's latest announcement will have on the litigation stemming from the March disclosure, according to Larry Golston, an attorney at Beasley Allen Law Firm, one of the firms representing plaintiffs.
"It is clear this is yet another significant cybersecurity failure involving AT&T, raising questions about the adequacy and effectiveness of AT&T's cybersecurity protocols, policies, and the company's oversight of its personnel and contractors," Golston said in an email.