AT&T, T-Mobile, New York Times, Google data breach: what happened and what to do
Last reviewed June 22, 2025 · 1 record on file · sources listed below
A researcher discovered a massive data breach that exposed millions of files containing sensitive business and personal information. The breach affected major companies such as AT&T, T-Mobile, the New York Times, and Google, with the exposed data potentially dating back several years.
If you have an account with AT&T, T-Mobile, New York Times, Google, assume the exposed details are circulating. The practical risk today is rarely the leak itself — it is the calls and messages that use those details to sound legitimate.
What we have on file
Every entry below is a catalogued record with its original source. We do not paraphrase beyond what the source reports.
What to do
- Change the password anywhere you reused itThe exposure matters most when the same password protects your email, because email is how everything else gets reset.
- Treat every call and text about this breach as a scam until proven otherwiseNo company will ask you for a one-time code, a PIN or a password. Hang up and call the number printed on your card.
- Read your statements for the next three monthsCard fraud usually starts with a small test charge. Catching that one is what stops the large one.
- Give your email account a password nothing else usesIt is the account that can reset all the others, so it is the one worth protecting first.
Questions people ask
Was my data in the AT&T, T-Mobile, New York Times, Google breach?
Having an account alone does not confirm exposure. The reliable check is whether your email address appears in the leaked datasets in circulation — that takes seconds and does not require your password.
Is it too late to do anything?
No. Leaked personal details do not expire, and neither does the defence: a unique password on your email, and a fraud alert on your credit file, still work years later.
Will AT&T, T-Mobile, New York Times, Google contact me?
They may. But scammers contact people too, using exactly these breach details to sound convincing. Never act on an inbound call or text — call back on a number you already had.