# AT&T Data Breach- SSN found on "Dark Web" (Spring 2024)

**URL:** <https://boards.straightdope.com/t/at-t-data-breach-ssn-found-on-dark-web-spring-2024/1000439>\
**Category:** In My Humble Opinion\
**Created:** [April 18, 2024, 12:50am UTC](https://boards.straightdope.com/t/at-t-data-breach-ssn-found-on-dark-web-spring-2024/1000439 "2024-04-18T00:50:06Z")\
**Posts on this page:** 11\
**Page:** 2

<div class="post-metadata">

**Author:** ![wguy123](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/wguy123/32/3161_2.png) [@wguy123](https://boards.straightdope.com/u/wguy123)\
**Post date:** [April 18, 2024, 4:54pm UTC](https://boards.straightdope.com/t/at-t-data-breach-ssn-found-on-dark-web-spring-2024/1000439/21 "2024-04-18T16:54:03Z")

</div>

Ha, close! Multi-factor authentication. Very related to 2FA - Two-factor auth.

Most common type is requiring an SMS message to send you a code you enter. There are better ways to do this such as the many types of MFA code apps (MS Authenticator, Google Authenticator, etc). But, any MFA is better than no MFA.

---

<div class="post-metadata">

**Author:** ![wolfpup](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/wolfpup/32/10618_2.png) [@wolfpup](https://boards.straightdope.com/u/wolfpup)\
**Post date:** [April 18, 2024, 5:02pm UTC](https://boards.straightdope.com/t/at-t-data-breach-ssn-found-on-dark-web-spring-2024/1000439/22 "2024-04-18T17:02:37Z")

</div>

> [@LSLGuy](#):
>
> I really can’t imagine caring about stuff like this.
> 
> About half of the USA uses (or used) AT&T for something and had their info compromised.

I concur with this.

I mentioned elsewhere that I lost my wallet – or more likely had it lifted by a pickpocket – back in December. It would have been awful if I’d had my credit and debit cards in there but I keep all plastic in a separate wallet, and there was actually nothing there except a small amount of cash and, unfortunately, my social insurance card (similar to the SSN in the US). So someone has my social insurance number but I very much doubt anyone is doing anything with it, even though potentially it **can** be used as the starting point for identity theft. I’m not worried about it and apparently neither is the federal government – they will not issue a new SIN unless you provide proof that the old one has been used for fraud. Presumably this is very rare.

---

<div class="post-metadata">

**Author:** ![ThelmaLou](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/thelmalou/32/390_2.png) [@ThelmaLou](https://boards.straightdope.com/u/ThelmaLou)\
**Post date:** [April 18, 2024, 6:39pm UTC](https://boards.straightdope.com/t/at-t-data-breach-ssn-found-on-dark-web-spring-2024/1000439/23 "2024-04-18T18:39:01Z")

</div>

> [@LSLGuy](#):
>
> I really can’t imagine caring about stuff like this.

> [@wolfpup](#):
>
> I concur with this.

I get this, and both of you are people whose opinions I respect.

One could look at this as a kind of insurance. Yeah, nothing may ever happen, but if you can expend minimal effort (at no cost) to diminish those chances even more, then why not? Belt _and_ braces, as it were.

---

<div class="post-metadata">

**Author:** ![wolfpup](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/wolfpup/32/10618_2.png) [@wolfpup](https://boards.straightdope.com/u/wolfpup)\
**Post date:** [April 18, 2024, 6:43pm UTC](https://boards.straightdope.com/t/at-t-data-breach-ssn-found-on-dark-web-spring-2024/1000439/24 "2024-04-18T18:43:39Z")

</div>

By amazing coincidence … a phishing scam just this afternoon!

> [@Damn Dirty April! (Monthly Mini-Rants)](https://boards.straightdope.com/t/damn-dirty-april-monthly-mini-rants/999679/175):
>
> So I’m sitting here minding my own business when the phone rings. The caller ID comes up as “likely spam” so I press the button to put it on speakerphone just for amusement. Lo and behold it’s my bank, telling me that they had blocked a fraudulent transaction with my debit card at some carpet place and cancelled my debit card, and would I please call them at the provided 877 number. Instead, I called the bank’s telephone banking line and asked for the fraud department. The fraud department f…

---

<div class="post-metadata">

**Author:** ![LSLGuy](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lslguy/32/5813_2.png) [@LSLGuy](https://boards.straightdope.com/u/LSLGuy)\
**Post date:** [April 18, 2024, 7:54pm UTC](https://boards.straightdope.com/t/at-t-data-breach-ssn-found-on-dark-web-spring-2024/1000439/25 "2024-04-18T19:54:51Z")

</div>

> [@ThelmaLou](#):
>
> One could look at this as a kind of insurance. Yeah, nothing may ever happen, but if you can expend minimal effort (at no cost) to diminish those chances even more, then why not? Belt _and_ braces, as it were

Certainly true in general.

I need to access the SSA website every month. Phoning them, a 90-minute project, to turn on electronic access then call them again to turn it back off would be a total PITA for me.

I open a credit account someplace every couple of months, and sometimes more often. Having to visit 6 websites to unlock everything then relock them all afterwards would likewise be a major PITA.

I never use a debit card except at an in-bank ATM precisely because of the much weaker consumer fraud protections.

My banks watch my credit cards for fraud and have never failed to spot a fraud before even daily checks by me would have.

One can make a fetish of defensive maneuvers. IMO “Can’t hurt; might help” ignores a vast psychic cost of worrying about shadows.

It’s the same mindset that gets gun nuts shooting people in their driveways. It’s letting ill-founded fear live in your mind rent-free.

YMMV of course and I wish you only peace of mind however you find that.

---

<div class="post-metadata">

**Author:** ![ThelmaLou](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/thelmalou/32/390_2.png) [@ThelmaLou](https://boards.straightdope.com/u/ThelmaLou)\
**Post date:** [April 18, 2024, 8:53pm UTC](https://boards.straightdope.com/t/at-t-data-breach-ssn-found-on-dark-web-spring-2024/1000439/26 "2024-04-18T20:53:55Z")

</div>

> [@LSLGuy](#):
>
> I need to access the SSA website every month. Phoning them, a 90-minute project, to turn on electronic access then call them again to turn it back off would be a total PITA for me.

No kidding!

> [@LSLGuy](#):
>
> I open a credit account someplace every couple of months, and sometimes more often.

I have one credit card and have had it for years. No other credit accounts.

> [@LSLGuy](#):
>
> I never use a debit card except at an in-bank ATM…

Ditto that.

> [@LSLGuy](#):
>
> My banks watch my credit cards for fraud

As I mentioned, I have multiple alerts. I set these up after my credit card number used to be stolen every couple of years. Talk about a nuisance! I’ve only had one serious event since then-- a charge made for $400+ at a TJMaxx here in town _with no card present!_ I get no surprises re my credit card.

> [@LSLGuy](#):
>
> One can make a fetish of defensive maneuvers…

Hey! Let’s not talk about fetishes in such a public space. 😊

> [@LSLGuy](#):
>
> It’s the same mindset that gets gun nuts shooting people in their driveways.

See my post somewhere else about bra holsters. Just make sure you shoot **that** boob out there instead of your own boob.

> [@LSLGuy](#):
>
> …I wish you only peace of mind…

I know. 😘

---

<div class="post-metadata">

**Author:** ![Chronos](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/chronos/32/134_2.png) [@Chronos](https://boards.straightdope.com/u/Chronos)\
**Post date:** [April 19, 2024, 12:05am UTC](https://boards.straightdope.com/t/at-t-data-breach-ssn-found-on-dark-web-spring-2024/1000439/27 "2024-04-19T00:05:24Z")

</div>

My mom got this email too, and asked me to look at it, but it didn’t give any further information without a login that she doesn’t have. And what information is there in the email is consistent with a big nothingburger: A “social security number showing up on the Dark Web” could just mean that someone posted a big list of random nine-digit numbers. Was her number actually connected to her name, or anything else? The big scary alert email didn’t actually say.

---

<div class="post-metadata">

**Author:** ![BigT](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bigt/32/12044_2.png) [@BigT](https://boards.straightdope.com/u/BigT)\
**Post date:** [April 19, 2024, 1:30am UTC](https://boards.straightdope.com/t/at-t-data-breach-ssn-found-on-dark-web-spring-2024/1000439/28 "2024-04-19T01:30:02Z")

</div>

> [@Chronos](#):
>
> My mom got this email too, and asked me to look at it, but it didn’t give any further information without a login that she doesn’t have. And what information is there in the email is consistent with a big nothingburger: A “social security number showing up on the Dark Web” could just mean that someone posted a big list of random nine-digit numbers. Was her number actually connected to her name, or anything else? The big scary alert email didn’t actually say. ⁢

My only caveat is wondering how they got her email address. If she doesn’t have an account with them, then how would they match the SSN to her email? That would make me suspect there is more info linking the SSN.

That is, unless this is AT&T themselves sending the message to an email address they have on file. Or even sending a mass email to all customers involved in the breach.

---

<div class="post-metadata">

**Author:** ![LurkMeister](https://avatars.discourse-cdn.com/v4/letter/l/3da27b/32.png) [@LurkMeister](https://boards.straightdope.com/u/LurkMeister)\
**Post date:** [April 19, 2024, 2:35am UTC](https://boards.straightdope.com/t/at-t-data-breach-ssn-found-on-dark-web-spring-2024/1000439/29 "2024-04-19T02:35:18Z")

</div>

Years ago when there was a data breach of federal employee records I was given a free account with MyID, and I get occasional notices from them (including notices of people on the sex offender registry moving within a certain distance of my home). When I recently signed up for a new credit card I got multiple alerts concerning it. I also had to temporarily unfreeze my credit record so the application could get processed.

---

<div class="post-metadata">

**Author:** ![LSLGuy](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lslguy/32/5813_2.png) [@LSLGuy](https://boards.straightdope.com/u/LSLGuy)\
**Post date:** [April 19, 2024, 11:30am UTC](https://boards.straightdope.com/t/at-t-data-breach-ssn-found-on-dark-web-spring-2024/1000439/30 "2024-04-19T11:30:58Z")

</div>

> [@BigT](#):
>
> My only caveat is wondering how they got her email address. If she doesn’t have an account with them, then how would they match the SSN to her email? That would make me suspect there is more info linking the SSN.

Since this is @Chronos’ Mom, she’s probably sorta elderly.

An easier explanation is she has a business relationship, an account, with AT&T. But has never used their “convenient” online access and therefore has no login. Which is the word @Chronos used.

---

<div class="post-metadata">

**Author:** ![Chronos](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/chronos/32/134_2.png) [@Chronos](https://boards.straightdope.com/u/Chronos)\
**Post date:** [April 19, 2024, 12:15pm UTC](https://boards.straightdope.com/t/at-t-data-breach-ssn-found-on-dark-web-spring-2024/1000439/31 "2024-04-19T12:15:48Z")

</div>

The email my mom got was (purportedly) from AT&T (I didn’t get as far as verifying, before I got to the point of “there’s no actual information here”). But now that I think of it, she doesn’t have a business relationship with them. She did, years ago, but not any more.

They could, of course, be maintaining a database of their former customers, years after the business relationship ended, which includes their email addresses and SSNs. In which case, the proper security measure would be a class-action lawsuit against AT&T. Or of course, it’s possible that it’s a pure scammer who has nothing but email addresses, and is just scaring people by saying that they found SSNs (maybe in the hopes that they’ll accidentally use their real username/password for some important account, on the login screen). I’ll have to take another look at that email she got.

[Previous page](https://boards.straightdope.com/t/at-t-data-breach-ssn-found-on-dark-web-spring-2024/1000439.md?page=1)
