A data breach at Effortel, a mobile virtual network enabler (MVNE), has exposed the personal information of 70,000 customers across three Belgian mobile virtual network operators (MVNOs). The affected operators include Carrefour Mobile, Neibo, and Undo.
The breach occurred during testing for the implementation of a central database system designed to integrate customer data for emergency services. During this process, test files containing customer data were generated and subsequently accessed when a hacker penetrated the support portal between the MVNOs and Telfort. The incident reflects a growing pattern of cybersecurity challenges in the telecommunications sector, as shown by the recent surge in SIM-swap fraud attacks affecting mobile operators.
The compromised information includes customers’ names, dates of birth, email addresses, phone numbers, residential addresses, passport numbers, subscriber numbers, and technical identification data such as SIM card numbers. The exposure of such sensitive data raises particular concerns given the increasing regulatory focus on telecommunications security and customer data protection.
“We have to pass on certain customer data in the system, for example, for the emergency services. For this integration, we performed tests and generated files with customer data that unfortunately leaked,” said Laurent Bataille, General Manager at Effortel. “A hacker managed to penetrate the support portal between the MVNOs and Telfort and thus gain access to those files.”
MVNOs are telecommunications providers that operate on existing physical networks without maintaining their own infrastructure. Effortel serves as an enabler for these virtual operators, providing the technical capabilities needed to deliver mobile services to their customers. The industry has been adopting enhanced security measures, with some operators implementing FIDO2 and biometric authentication to better protect customer data.
Effortel has acknowledged the breach and is implementing response measures. The incident highlights the complexities involved in securing customer data during system testing and integration processes in the telecommunications sector, particularly as countries worldwide begin implementing stricter requirements for SIM card authentication and registration.
Sources: Cybernews, Cybernews News, KonBriefing