Orange Belgium has implemented new SMS-based security measures following a data breach in July 2025 that exposed sensitive customer information for approximately 850,000 customers, including SIM card numbers and Personal Unblocking Key (PUK) codes. The incident follows a concerning trend of telecom security breaches in Belgium, including a similar breach at Effortel that affected 70,000 customers across multiple mobile virtual networks.
The telecommunications provider has introduced an additional verification step for phone number transfers between networks. When a customer requests to transfer their number to a different carrier, Orange now sends a verification text message to the customer’s current number. Customers have an eight-hour window to reply with “STOP” if they did not initiate the transfer request, which immediately cancels the process. The approach matches successful implementations by other global carriers, such as AT&T’s Wireless Account Lock feature, which has shown effectiveness in preventing unauthorized number transfers.
The verification messages are sent from different numbers depending on the customer type: private customers receive SMS notifications from number 5000, while business clients receive them from 5995.
The Belgian Institute for Postal Services and Telecommunications (BIPT) has approved Orange’s new security protocol and will monitor its implementation. The regulatory body has also issued broader security recommendations for all Belgian telecom users, including enabling two-factor authentication, limiting personal information sharing on social media, and maintaining vigilance regarding suspicious communications.
The July breach exposed data that could potentially enable SIM swapping attacks, where malicious actors can hijack phone numbers to intercept calls and SMS messages, including one-time verification codes used for multi-factor authentication. Such attacks have become increasingly prevalent, with recent reports indicating losses of up to $68 million from SIM swap scams globally. In response, Orange Belgium has enhanced its cybersecurity infrastructure with additional measures including comprehensive forensic analysis, enhanced logging and monitoring, zero-trust network architecture implementation, and regular penetration testing.
The implementation of zero-trust architecture represents an industry-wide shift toward more robust security frameworks, similar to KT Corporation’s recent $724 million cybersecurity investment in South Korea. The measures are particularly crucial as telecommunications providers face increasing pressure to protect against sophisticated fraud schemes that specifically target number porting systems.
Sources: Mobile Europe, FireCompass, Telecompaper