AT&T, the telecommunications giant, has disavowed any connection to a vast dataset impacting 71 million individuals, which surfaced on a cybercrime forum, allegedly stemming from a 2021 breach of the company’s systems, as claimed by a hacker.
While the legitimacy of all data entries remains unverified, BleepingComputer confirmed the accuracy of certain entries, including those not publicly accessible for scraping, casting a shadow of doubt over the origin and integrity of the leaked information.
Initially attributed to a threat actor named ShinyHunters, who sought to sell the dataset on the RaidForums for a hefty sum, AT&T vehemently denied the breach’s association with their systems in 2021, a stance reiterated in light of recent developments.
Despite AT&T’s repeated assertions of no evidence of a breach within its infrastructure, a new threat actor, identified as MajorNelson, has now leaked purported data from the same alleged 2021 breach, including sensitive details such as names, addresses, mobile phone numbers, encrypted birth dates, and social security numbers.
Disturbingly, the threat actors have decrypted encrypted data, elevating concerns over the accessibility and potential misuse of highly sensitive personal information. Independent verification by the media, alongside corroborating assessments from cybersecurity researchers, underscores the gravity of the situation.
While some discrepancies in the leaked data have been noted, attributable to AT&T’s extensive customer base, caution is advised for individuals who were customers before and during 2021. They are urged to remain vigilant against targeted attacks, including SMS and email phishing and SIM swapping schemes.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543