READ. SCROLL. LISTEN.

Unbiased headlines. Facts, not spin.

Every story is an unbiased news briefing written from 113+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

FCC Tells Appeals Court It Won't Refund AT&T's $57 Million Location Data Fine

FCC Tells Appeals Court It Won't Refund AT&T's $57 Million Location Data Fine
The FCC filed a brief on September 23, 2026 telling the Fifth Circuit that AT&T isn't getting its $57 million fine back, arguing the carrier waived its refund claim and kept selling customer location data to unvetted third parties for months after the practice was publicly exposed. T-Mobile has a similar $92 million refund bid pending at the Supreme Court, and Verizon already lost the same fight in August.

The Federal Communications Commission told a federal appeals court this week that AT&T isn't getting back the $57 million it paid in 2024 for selling customers' real-time location data. The agency's brief, filed September 23 at the U.S. Court of Appeals for the Fifth Circuit and reported by Tech Times, argues AT&T waived its refund claim and that the original forfeiture order already spelled out the carrier had no right to repayment.

The FCC also laid out a substantive case that AT&T committed 84 separate violations of federal privacy law, continuing to share customer location data with 84 different entities for nearly a year after public reporting exposed that the company's consent-verification system couldn't actually stop abuse.

How a Missouri Sheriff Blew the Whistle

This all traces back to May 2018, when the New York Times published an investigation by reporter Jennifer Valentino-DeVries revealing that a Missouri sheriff named Cory Hutcheson had used a location-finding service from a company called Securus Technologies to track hundreds of people without warrants or consent. His targets included a local judge, several highway patrol officers, and his own predecessor as sheriff.

Securus got that data by tapping into carrier location-data pipelines. AT&T sold real-time position data, pulled from the constant cell-tower pings every phone generates just by being powered on, to commercial middlemen called location aggregators. Those aggregators resold access to downstream services like Securus. AT&T required the downstream providers to certify they had customer consent, but by the company's own admission it had no way to verify those certifications or catch fraudulent ones.

84 Violations, One Year, No Fix

According to the FCC's brief, AT&T kept the pipeline running for close to a year after the Times story broke, continuing to share location data with dozens of entities even after the structural flaw in its consent system was public knowledge. That's the basis for the 84-count violation tally the agency is defending in court.

The fine is part of a broader $196 million enforcement action the FCC imposed across the major wireless carriers two years ago for the same underlying conduct. AT&T's $57 million is the biggest single piece still in active litigation.

Where the Other Carriers Stand

T-Mobile has a parallel $92 million refund petition sitting at the Supreme Court, with the Justice Department's response due on September 25, 2026. Verizon already tried this route and lost. The Supreme Court denied its rehearing request in August without offering any explanation, closing off Verizon's path to a refund.

That leaves AT&T as the only one of the three carriers still fighting an active case with a real chance of getting money back, though the FCC's new filing makes clear the agency intends to fight it on both procedural and substantive grounds.

AT&T's Legal Position

AT&T's own legal argument for why it deserves a refund isn't detailed in the FCC's brief as reported, and the carrier hasn't issued a public statement laying out its position in this specific filing. But the carrier's likely defense, based on the underlying facts, is that AT&T wasn't the party directly misusing the data. The downstream providers and aggregators were the ones who allegedly abused certified consent records, and AT&T's certification-based system was reportedly similar to what other carriers used across the industry at the time. Whether an inadequate verification system amounts to the same thing as knowing misconduct is a real legal question, and it's the crux of what the Fifth Circuit will have to decide.

The FCC's core allegation, however, isn't about the initial design flaw. It's about AT&T allegedly continuing the exact same practice for nearly a year after the flaw became public. That's a harder fact pattern to explain away.

A Broader Pattern Still Unfolding

The underlying data category here, location and call information tied to individual customers, is what the industry calls Customer Proprietary Network Information, or CPNI. James Okafor, a field CISO writing for Accuro AI, has separately flagged that carriers are now wiring AI systems, including Verizon's Gemini-based care assistant and T-Mobile's roughly $100 million OpenAI partnership, directly into systems that hold this same class of data. Okafor's point isn't about the AT&T case specifically, but it underscores that the oversight question the FCC is litigating over 2018-era data sharing hasn't disappeared. It has just moved into new infrastructure.

The Fifth Circuit hasn't set a date for oral argument or a ruling on AT&T's case. The Supreme Court's next move on T-Mobile's petition depends on how the Justice Department responded by the September 25 deadline, which has now passed. Whether AT&T ever sees a dollar of its $57 million again now rests entirely on how the Fifth Circuit reads the forfeiture order the FCC says already closed the door.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

unknown
Tech TimesAT&T Paid $57M for Selling Location Data, Now Wants It Back; FCC Says No - techtimes.com
unknown
accuroai.coTelecom AI Security: CPNI, Care & Network Agents