Main Content Main Menu

Legal Updates

Print PDF
FCC Fines AT&T $25m for Data Privacy Lapse

The Federal Communications Commission (FCC) reached a $25 million settlement with AT&T for failing to protect the privacy, personal information and social security numbers of its customers.  According to the FCC’s complaint, AT&T employees actively stole this information from an estimated 300,000 people at call centers working in Mexico, Colombia and the Philippines.

The Federal Communications Commission (FCC) reached a $25 million settlement with AT&T for failing to protect the privacy, personal information and social security numbers of its customers.  According to the FCC’s complaint, AT&T employees actively stole this information from an estimated 300,000 people at call centers working in Mexico, Colombia and the Philippines.

In Mexico, the information was gathered between November 2013 and April 2014.  Unlike most large-scale breaches, this was not an aggregate data dump.  Rather, according to the FCC complaint, the information in question was harvested and sold to an individual known only as “El Pelón.”  El Pelón would contact the call center with specific requests and information pulls, and the employee or employees would then provide the information.  It is believed that this data was used to reprogram phones for resale on the global market, as the stolen information was used to submit 290,803 handset unlock requests through AT&T’s website.

According to a statement released by AT&T:  "We are terminating vendor sites as appropriate. We’ve changed our policies and strengthened our operations."  The company further reported that they have been taking steps to inform affected customers. 

The $25 million civil penalty levied on the No. 2 wireless carrier is the largest data security enforcement action to date.  In October, the FCC imposed a $10 million fine on telecom companies TerraCom and YourTel for consumer privacy breaches.  The recent settlement with AT&T is another example of a regulatory body cracking down on companies who fail to properly protect their customer’s personal identifiable information.

Archives

Back to Page

Connell Foley LLP Cookie Preference Center

Your Privacy

When you visit our website, we use cookies on your browser to collect information. The information collected might relate to you, your preferences, or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience.

Strictly Necessary Cookies

Always Active

Necessary cookies enable core functionality such as security, network management, and accessibility. These cookies may only be disabled by changing your browser settings, but this may affect how the website functions.

Functional Cookies

Always Active

Some functions of the site require remembering user choices, for example your cookie preference, or keyword search highlighting. These do not store any personal information.

Form Submissions

Always Active

When submitting your data, for example on a contact form or event registration, a cookie might be used to monitor the state of your submission across pages.

Performance Cookies

Performance cookies help us improve our website by collecting and reporting information on its usage. We access and process information from these cookies at an aggregate level.

Powered by Firmseek