LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › AT&T Listed by everest Ransomware Group

HIGH severityUnverified claimHow we verify

AT&T Listed by everest Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·October 28, 2022
AT&T Listed by everest Ransomware Group

Reported October 28, 2022.

HIGH
Severity
October 28, 2022
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The AT&T Listed by everest Ransomware Group (reported October 28, 2022) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On October 28, 2022, AT&T appeared on the leak site operated by the everest ransomware group. The group claims to have stolen internal data from the company through a ransomware attack that involved the exfiltration of internal files. The number of people affected remains unknown, and public detail on the incident is limited to this listing and the accompanying claim.

For a major telecommunications provider, any assertion of internal data theft raises immediate questions about the security of corporate systems and the potential downstream effects on customers and partners. What is confirmed so far is only the public claim itself; independent verification of the breach’s scope or success has not been detailed in the available record.

What happened

According to the reported information, AT&T was listed on the everest ransomware leak site on or around October 28, 2022. The group stated that it had conducted a ransomware attack and exfiltrated internal files. No further technical specifics—such as the initial access method, the duration of unauthorized access, the precise volume of data taken, or any ransom demand—have been disclosed in the public facts surrounding the listing. The number of individuals potentially affected is recorded as unknown. The incident is therefore known primarily through the threat actor’s own publication of the victim’s name and the assertion that internal data was stolen.

Inside everest

Everest is a ransomware operation that has been observed using double-extortion tactics: encrypting systems while also copying data and threatening to publish it if payment is not made. Like other groups in this category, it maintains a public leak site where it names victims and, in some cases, releases samples or larger sets of purportedly stolen files to increase pressure. The group’s listings function as claims of successful intrusion and data theft; they are not independent confirmations. Prior public reporting on everest has described it as one of several ransomware brands that emerged or rebranded in the early 2020s, typically targeting organizations across multiple sectors and leveraging common initial-access techniques such as compromised credentials or vulnerable remote services. No additional statements from everest specifically detailing the AT&T incident beyond the leak-site listing are included in the available facts.

About AT&T

AT&T is one of the largest telecommunications companies in the United States, providing mobile, broadband, and enterprise network services to millions of consumer and business customers. Organizations of this type routinely maintain extensive internal systems that hold employee records, network configuration data, customer account information, billing details, and operational documents. Because telecommunications providers sit at the center of everyday communications and critical infrastructure, any compromise of their internal environment can carry heightened consequences for service continuity, customer privacy, and trust. A claimed breach involving internal files is therefore consequential even when the exact contents remain unconfirmed, simply because of the volume and sensitivity of data such a company typically processes.

What was likely exposed

The facts state that internal files were exfiltrated in a ransomware attack. No more granular inventory—such as whether the files included customer databases, employee personal information, source code, network diagrams, or financial records—has been publicly detailed. In the absence of a confirmed data inventory, it is only possible to note what companies of AT&T’s scale and sector commonly store: customer names, contact details, account identifiers, call or usage metadata, payment-related information, employee records, and proprietary operational documents. Whether any of those categories were among the files the group claims to have taken is unconfirmed. Readers should treat the exposure as limited to the description given—internal files—until more precise disclosure occurs.

The real-world impact

For individuals, the primary risk depends on whether personal or account-related data was among the internal files. If customer or employee information was included, possible outcomes include targeted phishing, identity-driven fraud, or unauthorized account access attempts. Because the number of people affected is unknown and the exact data types beyond “internal files” are undisclosed, the concrete scale of individual harm cannot be stated. For the organization, a public ransomware listing can prompt regulatory scrutiny, customer notification obligations, forensic and remediation costs, and reputational damage. Even when a group’s claims are later shown to be incomplete or exaggerated, the mere appearance on a leak site often forces an internal investigation and external communications effort. Until fuller details emerge, both the personal and institutional impacts remain bounded by the limited public record.

If your data was in this claimed breach

If you are a current or former AT&T customer or employee, treat the incident as a prompt to review account security rather than as proof that your specific information was taken. Change passwords on related accounts, enable multi-factor authentication where available, and monitor financial and account statements for unfamiliar activity. Be alert to phishing messages that reference AT&T or this incident in an effort to obtain credentials or payment. Because the full contents of the claimed exfiltration are unconfirmed, checking whether your email address has appeared in other known breach datasets can provide an additional, practical signal. Free exposure-scan tools allow you to enter your email and see whether it surfaces in previously disclosed breach collections; that step does not confirm involvement in this specific event but helps you assess your broader exposure footprint and prioritize further protections.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyAT&T security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See AT&T’s full breach history →

More recent breaches

VTVCAB Listed by everest Ransomware GroupJune 6, 2022Ciena Listed by everest Ransomware GroupJanuary 20, 2026AT&T Careers - Database Leaked Listed by everest Ransomware GroupOctober 28, 2025AT&T Careers Listed by everest Ransomware GroupOctober 21, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the AT&T Listed by everest Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by everest — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram