Data breach
AT&T Careers
- Records
- 563,482
- Breach date
- 21 October 2025Estimated
- Added
- 29 October 2025
What was exposed
3 types of data
- Email addresses1
- Names1
- Phone numbers1
About this breach
The Everest ransomware group claims to have stolen hundreds of thousands of records tied to AT&T's job application system, and a copy of the data has since appeared online. According to reporting by Hackread, the group first posted a listing for "AT&T Careers" on its leak site on October 21, 2025, claiming roughly 576,000 records from att.jobs, the telecom company's recruitment portal. AT&T has not publicly confirmed any compromise. The investigation team reviewed a copy of the data circulating in criminal forums and indexed 563,482 rows, which appear to represent job applicants or HR contacts rather than wireless customers. Because the only original source is a criminal actor's posting, the full scope and origin of the data remain unverified.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
Breach Timeline
October 21, 2025: The Everest ransomware group added a password-protected "AT&T Careers" entry to its dark-web leak site, claiming about 576,686 records and giving the company a deadline to make contact.
October 24, 2025: Hackread.com contacted AT&T for comment; the company did not respond.
October 28, 2025: The group released the data publicly, and threat-intelligence trackers marked the listing as leaked.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses, phone numbers, and names.
Hackread's analysis of the released files described two CSV files: one labeled "user_list" containing email addresses, full names, and phone numbers of about 429,103 individuals, and another labeled "customer_list" containing email addresses, phone numbers, and last names of about 147,621 individuals. Our investigation team's review of a sample found no Social Security numbers, payroll data, or customer account credentials.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Names, email addresses, and phone numbers are the core ingredients for targeted scams. People who applied for jobs at AT&T could receive convincing phishing emails or text messages that impersonate recruiters, hiring managers, or onboarding systems. A common pattern after breaches like this is a fake "job offer" or "assessment" link that harvests passwords or payment details.
Because the exposed data lacks passwords or financial details in the reviewed sample, the direct financial risk appears limited. The bigger danger is social engineering: an attacker who knows your name, phone number, and that you applied to AT&T can craft messages that feel personal and legitimate. Contact details can also feed credential-stuffing attempts against other accounts if reused passwords come into play elsewhere.
What Is AT&T Careers Doing in Response?
AT&T has issued no public confirmation or denial of the Everest claim. As of the reporting on October 28, 2025, no regulator filings, company notices, or technical advisories had corroborated the posting. The att.jobs recruitment site runs on Workday, a third-party HR platform, and the actor's claim appears to concern that careers system, not AT&T's wireless customer accounts. Without an official statement, the incident should be treated as an unconfirmed threat-actor claim.
What Should You Do If You Were Affected?
If you applied for a job with AT&T around this period, take a few practical steps:
Change the password on your AT&T Careers or Workday account, and make sure it is not reused on other sites.
Turn on multi-factor authentication where the service offers it.
Be skeptical of unexpected emails or texts about job applications, assessments, or offers. Do not click links in these messages; go to the official careers site directly instead.
Watch for follow-up scams by phone. Legitimate recruiters will not ask for passwords, Social Security numbers, or bank details over text or email.
Consider a password manager so each account gets a unique password.
