Sept. 23, 2024
On Sept. 17, the Federal Communications Commission (FCC) announced that it has reached a Consent Decree with AT&T Services Inc. to resolve an investigation into a data breach that occurred in January 2023. AT&T's vendor experienced a data breach that exposed the personally identifiable information (PII) of 8,931,656 AT&T Mobility customers, including customer proprietary network information (CPNI) elements like line counts, billing information, and rate plan details. As part of the Consent Decree, AT&T will pay a $13 million civil penalty and take various measures to strengthen its data governance practices.
The Consent Decree reminds telecommunications carriers of their obligations to protect customer data and to make sure their third-party vendors also protect customer data in their possession or control.
Consent Decree Terms
The Consent Decree requires AT&T to make significant changes to its data governance and security practices including:
Key takeaways for telecommunications carriers
We will continue to monitor the FCC for similar enforcement actions. Please contact us if you would like more information or have questions regarding the impact of this order.
These materials have been prepared for informational purposes only and are not legal advice. This information is not intended to create, and receipt of it does not constitute, an attorney-client relationship. Internet subscribers and online readers should not act upon this information without seeking professional counsel.