Publish date
September 1, 2026
{x} minute read
Written by
Reviewed by
Table of contents

Telecommunications providers sit at the center of modern life, carrying the calls, messages, locations, account credentials, and identity data that connect billions of people and businesses. Which makes them uniquely valuable targets: criminals want subscriber records they can monetize, while nation-state actors want access to the networks themselves. The biggest telecom data breaches show how quickly weak security measures can escalate from a customer privacy incident into a national security event. A single intrusion can either expose the data of tens of millions of subscribers or serve a much quieter, more dangerous purpose: foreign espionage services hiding within a carrier's routing and lawful-intercept systems to monitor high-value targets.

Salt Typhoon perfectly illustrates this second scenario, elevating telecom security from a standard compliance issue to a critical national security threat.

This list's ranking reflects that same gap between records exposed and damage done. It covers the 32 largest telecom breaches as of September 2026, mostly ordered by the number of records affected, though some smaller incidents rank higher due to their geopolitical impact.

Compliance landscape

An event like Salt Typhoon demands simultaneous responses regarding privacy, communications regulations, and national security. In the US, carriers are bound by Section 222 of the Communications Act and the Federal Communications Commission (FCC) Customer Proprietary Network Information (CPNI) rules, which govern call-record protection and breach notifications.

One correction worth noting upfront: the FCC's January 2025 ruling that treated the Communications Assistance for Law Enforcement Act (CALEA) as a mandatory cybersecurity duty was rolled back in November 2025. Instead, US carriers now operate under voluntary commitments rather than enforceable CALEA cybersecurity obligations.

Globally, regulations are becoming much stricter. For example, the European Union (EU)'s Network and Information Security 2 (NIS2) Directive mandates a phased reporting approach for essential telecoms: an initial early warning within 24 hours, followed by a comprehensive incident notification within 72 hours. Fines can reach up to €10 million or 2% of turnover. Similarly, the UK's Telecommunications (Security) Act empowers Ofcom to issue fines of up to 10% of a company's turnover. In Australia, the Australian Communications and Media Authority (ACMA) and the Office of the Australian Information Commissioner (OAIC) have actively pursued legal action against Optus over its 2022 data incident.

Before examining specific breaches, it is important to understand why carriers are targeted. Several structural vulnerabilities explain this trend:

  • Metadata is the primary target: Regulators require carriers to store call detail records for every subscriber.
  • Lawful intercept systems introduce built-in vulnerabilities: If compromised, these highly privileged systems grant attackers access to government-grade surveillance tools.
  • SIM swapping opens doors: Because SMS is still widely used for two-factor authentication, hijacking a phone number often grants access to a victim's personal and financial accounts.
  • Supply chain interconnectedness: Telecoms rely heavily on third-party vendors, creating multiple external points of failure.

Where continuous monitoring catches these gaps first

Most telecom intrusions stem from unpatched internet-facing devices, reused credentials, or third-party vendors with poor security postures. Continuous monitoring solutions, such as UpGuard's Breach Risk, help identify and close these vulnerabilities before attackers exploit them.

These platforms continuously map a carrier's internet-facing footprint, including routers, Virtual Private Network (VPN) concentrators, remote-access gateways, and Application Programming Interfaces (APIs). They rank findings by the probability of real-world exploitation rather than by raw severity. This ensures that an actively exploited flaw, like Citrix Bleed, which was behind the Comcast Xfinity breach, surfaces ahead of a theoretical vulnerability sitting in a patch queue.

On the credential front, these platforms monitor dark web marketplaces for leaked session tokens, providing security teams a window to force password resets.

32 biggest data breaches in telecommunications

The ranking follows record volume in descending order, though certain smaller incidents appear higher on the list due to their involvement in espionage operations, the severity of damage inflicted, or their role in driving regulatory reform. Disputed or attacker-claimed figures (like Jio's 120 million and TalkTalk 2025's 18.8 million) are ranked conservatively rather than at face value, since they aren't independently confirmed. For breaches in other industries, see the biggest data breaches worldwide.

1. Salt Typhoon campaign against global telecommunications carriers

Records affected: Not a bulk record theft in the conventional sense.

Reporting indicates that call records and metadata for tens of millions of subscribers are accessible, with the US government confirming targeted interception for a smaller set of individuals.

In December 2024, officials said fewer than 150 people had been directly notified that their communications were intercepted. The FBI stated in August 2025 that the wider campaign had hit at least 200 US companies. Treat any single "records affected" number for Salt Typhoon as unverified.

Date of breach: Intrusions dating to at least 2022, with confirmed persistence through 2024 and activity reported into 2025 and 2026.

Date disclosed: First reported by the press in late September and October 2024; Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI) statements followed in October and November 2024.

Country: Primarily the United States, with reported activity across Canada, the UK, and dozens of other countries.

Attack vector: Exploitation of unpatched internet-facing edge devices, above all Cisco routers, followed by credential theft, configuration changes, Generic Routing Encapsulation tunneling, and persistence techniques that reuse a network's own legitimate tools to stay hidden in core routing infrastructure.

Data types exposed: Call detail records and subscriber metadata; SMS content; voicemail; in some cases, captured call audio; router configurations; and access to CALEA lawful intercept systems that identify who is under US surveillance.

Salt Typhoon spent years inside the routing backbone of some of the largest US carriers. What separates it from every other entry is what the attackers reached: the lawful-intercept infrastructure itself, which meant a foreign service could see which people the US government was surveilling.

The campaign is best understood as an espionage-related access incident, as no one received a breach notification letter for Salt Typhoon the way AT&T's Snowflake customers did, but the strategic damage is far greater.

Aftermath: On January 17, 2025, the US Treasury sanctioned a China-based firm described as tied to the Ministry of State Security and to Salt Typhoon. The FCC's January 2025 CALEA declaratory ruling was later rescinded in November 2025 in favor of voluntary commitments. Congress held multiple hearings, and CISA, the National Security Agency (NSA), and international partners issued a joint advisory in August 2025.

No carrier has been fined over Salt Typhoon.

Source: Countering Chinese State-sponsored actors

2. AT&T (Snowflake call records)

Records affected: Approximately 110 million customers.

The stolen data comprised call and text metadata for nearly all AT&T wireless customers plus mobile virtual network operator customers on AT&T's network, covering May 1 to October 31, 2022, and a small number of records from January 2, 2023.

Date of breach: April 14 to April 25, 2024.

Date disclosed: July 12, 2024.

Country: United States.

Attack vector: Credential-based access to AT&T's workspace on the Snowflake cloud data platform, an account not protected by multi-factor authentication. Part of the wider ShinyHunters and UNC5537 campaign against Snowflake tenants that also hit Ticketmaster and Santander.

Data types exposed: Call and text records, including the numbers a customer interacted with, call and text counts, and aggregate durations. For a subset of records, cell site identifiers were included to approximate location. AT&T stated that call content, Social Security numbers, and dates of birth weren't in the stolen files.

No other entry here involves more stolen records, and the cause wasn't some exotic exploit: an unprotected cloud data warehouse tenant, accessed with credentials harvested by infostealer malware, with no multi-factor authentication in the way. Reporting indicated AT&T paid a ransom of roughly $370,000 in bitcoin for a video purporting to show deletion of the data.

Aftermath: Consolidated class-action litigation resulted in a $177 million settlement covering this incident and the separate March 2024 dataset, preliminarily approved in 2025, with a claims deadline of November 18, 2025. The settlement allocates roughly $28 million to the Snowflake class and $149 million to the March 2024 class.

Sources: The Record on the AT&T ransom payment, AT&T Data Incident Settlement notice

3. T-Mobile US breach (2021)

Records affected: 76.6 million US consumers, the figure cited by the FCC in its 2024 settlement. T-Mobile's own disclosures in August and September 2021 described roughly 7.8 million postpaid customers and more than 40 million former or prospective customers who had applied for credit.

Date of breach: Discovered and disclosed in August 2021.

Date disclosed: August 16 to 17, 2021, with expanding disclosures through September 2021.

Country: United States.

Attack vector: Exploitation of an exposed and misconfigured gateway discovered through internet scanning, followed by lateral movement and brute-forcing into production servers. The attacker publicly claimed responsibility and described T-Mobile's security as "awful."

Data types exposed: Names, dates of birth, Social Security numbers, driver's license and government ID numbers, phone numbers, International Mobile Equipment Identity and International Mobile Subscriber Identity (IMSI) numbers, and account PINs for a subset.

The 2021 breach stands as the largest US telecom identity-data theft on record and the benchmark case for repeat-offender risk, recurring across the biggest US data breaches. T-Mobile had already disclosed breaches in 2018, 2019, and 2020 and would disclose more in 2023, so the FCC's eventual settlement covered a cluster of incidents rather than a single event. Because the stolen data included Social Security and driver's license numbers, it carries a far higher identity-theft risk than a metadata breach.

Aftermath: T-Mobile agreed to a $350 million class-action settlement in 2022 plus $150 million in security spending. In late 2024, it reached a $31.5 million settlement with the FCC covering the 2021, 2022, and 2023 incidents, split evenly between a civil penalty and mandated cybersecurity investment. A separate multistate attorneys general settlement of $31.5 million was also announced.

Sources: FCC settlement announcement, T-Mobile 2021 incident update

4. AT&T (March 2024 leaked dataset)

Records affected: Approximately 73 million records (7.6 million current account holders and 65.4 million former account holders) appeared in the leaked file. AT&T's notification filings cited a materially lower number of individuals notified, reported at around 51 million.

Date of breach: Disputed. The data is dated to 2019 or earlier, and a version was offered for sale in 2021.

Date disclosed: March 30, 2024.

Country: United States.

Attack vector: Unconfirmed. AT&T stated it had no evidence of unauthorized access to its systems and couldn't rule out a vendor as the source.

Data types exposed: Names, addresses, phone numbers, email addresses, dates of birth, Social Security numbers, and AT&T account passcodes. The passcodes were reportedly stored in a weak, reversible encoding, which made the leak dangerous for account takeover and SIM swap.

This entry matters less for its size and more for how it was handled. AT&T denied the authenticity of the data in 2021 and only conceded the link in 2024 when the full file was dumped publicly, three years after affected customers could have been warned. Weak, unprotected passcodes made the dataset a ready-made SIM-swap toolkit.

Aftermath: Included in the consolidated $177 million AT&T settlement, with roughly $149 million allocated to this class. AT&T force-reset passcodes for affected active accounts, and the FCC opened an inquiry.

Sources: AT&T statement on the leaked dataset, BleepingComputer on the 73 million and 51 million figures

5. SK Telecom 2025 USIM breach

Records affected: 23.2 million people, according to the Personal Information Protection Commission's findings. Some reporting cites close to 27 million subscriber records or SIM identifiers.

Date of breach: Malware in the Home Subscriber Server environment, with intrusion activity going back to 2022 and mass exfiltration detected in April 2025.

Date disclosed: April 22, 2025.

Country: South Korea.

Attack vector: Compromise of internet-facing systems and lateral movement into the core network with little segmentation; deployment of BPFDoor and related Linux backdoors; and unencrypted storage of Universal Subscriber Identity Module (USIM) breach authentication keys.

Data types exposed: IMSI, phone numbers, USIM authentication keys, and 23 other categories of USIM identifiers. Exposure of authentication keys is qualitatively worse than a normal data leak because it enables SIM cloning and interception of calls, SMS, and two-factor codes.

No non-US telecom breach in the current cycle carries more consequences. SK Telecom offered free USIM replacements to its entire subscriber base, suspended new sign-ups for a period, and saw a mass exodus of customers. The chief executive later resigned.

Aftermath: In late August 2025, the Personal Information Protection Commission imposed a fine of 134.8 billion KRW (about $91 million at the time), its largest ever against a single company, citing failures in access control, USIM key encryption, and the timeliness of notifications. SK Telecom filed suit in January 2026 to overturn the fine, so it's under legal challenge and shouldn't be described as final.

Sources: The Register on the SKT fine, Light Reading on the SKT court challenge

6. Kyivstar

Records affected: Not primarily a data-theft event. Roughly 24 million subscribers lost mobile and internet service. Kyivstar stated that subscriber personal data wasn't leaked, though Ukrainian officials acknowledged the attackers had deep access and the Solntsepek persona claimed to have taken data.

Date of breach: Initial access was assessed to date back to May 2023, with the destructive payload executed on December 12, 2023.

Date disclosed: December 12, 2023.

Country: Ukraine.

Attack vector: Attackers compromised employee credentials and maintained undetected privileged access for months before wiping core IT infrastructure.

Data types exposed: Not the point of the operation. The operational impact was the destructive payload.

Kyivstar defines the far end of the telecom threat model as an adversary who doesn't want your data but wants your network gone. The attackers destroyed a reported 10,000 computers and more than 4,000 servers, taking mobile service offline for around 24 million subscribers for days in the middle of a war, turning off air-raid alert systems in some regions.

Aftermath: No regulatory fine; this was a targeted state attack, not a compliance failure. Kyivstar waived December charges and offered compensation, and the SBU said it was gathering evidence for potential International Criminal Court proceedings. The incident is cited across NATO and EU guidance as a reference case for telecom resilience.

Sources: Reuters exclusive on the Kyivstar intrusion, CFR cyber operations tracker entry

7. Free / Free Mobile (Iliad Group)

Records affected: Reported at approximately 19.2 million subscribers, including around 5.11 million International Bank Account Number (IBAN) bank account numbers. The sanction decision by France's data protection authority, the Commission Nationale de l'Informatique et des Libertés (CNIL), concerns personal data related to about 24 million subscriber contracts.

Date of breach: October 2024.

Date disclosed: October 25 to 26, 2024.

Country: France.

Attack vector: Compromise of an internal management tool, reported to involve a stolen or misused administrator credential.

Data types exposed: Names, email addresses, postal addresses, phone numbers, contract details, and IBAN bank account numbers for a large subset. Passwords and card details were not included.

The Free breach ranks as the largest French telecom data leak on record, and the IBAN exposure is unusual because bank account numbers enable direct-debit fraud and convincing targeted phishing; unlike passwords, they can't be reset. It sits within a striking cluster of French carrier breaches that also hit SFR, Bouygues Telecom, and Orange, a pattern explored further in the biggest data breaches in France.

Aftermath: On January 13, 2026, the CNIL imposed fines totaling €42 million, comprising €27 million against Free Mobile and €15 million against Free SAS, one of the largest CNIL penalties ever issued, citing failures in security of processing under Article 32 of the General Data Protection Regulation (GDPR).

Sources: CNIL sanction decision, BleepingComputer report on the fine

8. Optus

Records affected: Approximately 9.8 million customer records were exposed. Optus stated that 2.1 million records had valid or expired identity document numbers exposed; about 1.2 million had at least one current, valid government ID number, and about 900,000 had numbers from expired documents.

Date of breach: September 17-20, 2022.

Date disclosed: September 22, 2022.

Country: Australia.

Attack vector: Optus left an internet-facing customer-identity API exposed without authentication, reachable from the public internet, with enumerable customer identifiers. Effectively, no credentials were required.

Data types exposed: Names, dates of birth, phone numbers, email addresses, and, for a subset, home addresses, passport numbers, driver's license numbers, and Medicare numbers.

Optus is the case that changed Australian privacy law. The trivial access route, an unauthenticated public API, combined with the exposure of identity documents, triggered a national reissuance exercise for passports and licenses. It directly produced the December 2022 amendments that raised Australian privacy penalties to the greater of AU$50 million, three times the benefit obtained, or 30% of adjusted turnover.

Aftermath: The ACMA commenced Federal Court proceedings in May 2024, and the OAIC separately commenced civil penalty proceedings. Optus lost its bid to claim privilege over the Deloitte forensic report.

Sources: ACMA Federal Court proceedings, Optus incident page

9. Reliance Jio (disputed)

Records affected: Claimed at more than 120 million subscribers. This figure is unverified, and Jio disputed it at the time. Independent researchers who sampled the exposed site found real records. Still, no one has independently established the total, and Jio said the data appeared "unauthentic" while filing a police complaint about unlawful access.

Date of breach: Unknown; data surfaced in July 2017 (frequently misdated to 2020).

Date disclosed: July 9 to 10, 2017.

Country: India.

Attack vector: A third-party website served a searchable interface that appeared to show Jio subscriber records. The underlying source was never publicly established.

Data types exposed: First and last name, mobile number, email address, telecom circle, SIM activation date, and, in some records, Aadhaar number.

The Jio incident remains the largest claimed telecom leak in India and the clearest case study of an unresolved breach. Treat it as an allegation with partial corroboration, not an established 120-million-record breach. The presence of Aadhaar numbers in some records drew the most scrutiny.

Aftermath: The searchable site was taken offline, police filed complaints, and at least one arrest was reported. India had no dedicated data-protection law at the time.

Sources: Deccan Herald report, contemporaneous coverage of Jio's police complaint

10. T-Mobile US API breach (January 2023)

Records affected: Approximately 37 million current postpaid and prepaid customer accounts.

Date of breach: From on or around November 25, 2022; detected January 5, 2023.

Date disclosed: January 19, 2023.

Country: United States.

Attack vector: Abuse of a single application programming interface, queried at scale without triggering rate limiting or anomaly detection for roughly six weeks.

Data types exposed: Name, billing address, email address, phone number, date of birth, account number, and service-plan details. T-Mobile stated that payment card data, Social Security numbers, and passwords weren't exposed via this API.

Coming 18 months after the 76.6-million-record 2021 breach, the 2023 API incident pushed regulators to stop treating T-Mobile's breaches as separate events. The exposed fields are lower risk than in 2021. Still, the volume and the six-week undetected duration made it a governance story, since an authenticated but under-monitored API is a common cause of large modern telecom leaks.

Aftermath: Folded into the FCC's consolidated investigation, resolved by the $31.5 million settlement and consent decree in 2024 that also covered the 2021 and 2022 incidents.

Sources: BleepingComputer report on the T-Mobile API breach, FCC consent decree

11. Bouygues Telecom

Records affected: 6.4 million customer accounts.

Date of breach: Detected August 4, 2025.

Date disclosed: August 6 to 7, 2025.

Country: France.

Attack vector: Unauthorized access to customer account systems.

Data types exposed: Contact details, contractual data, civil-status information, and IBAN bank account numbers for a subset. Bouygues stated that passwords and payment card details weren't affected.

Bouygues was the third of the four major French operators to disclose a large breach within twelve months, following Free and SFR, and the second to expose IBANs. Taken with Free, the two incidents put the bank account numbers of well over 10 million French subscribers into criminal hands, prompting the operators to adopt a joint anti-fraud posture.

Aftermath: Bouygues notified the CNIL and affected customers and filed a criminal complaint.

Sources: TechCrunch report, The Record report

12. Three UK

Records affected: Reported up to 6 million of Three's roughly 9 million customers as potentially at risk; Three stated that 133,827 customer accounts were accessed and that 400 to 500 handsets were fraudulently ordered.

Date of breach: November 2016

Date disclosed: November 17 to 18, 2016.

Country: United Kingdom.

Attack vector: Use of a legitimate employee login to access Three's customer upgrade database to identify customers eligible for handset upgrades and intercept the devices.

Data types exposed: Names, phone numbers, addresses, and dates of birth. Three stated that the upgrade system did not store any payment card or bank account data.

Three is the archetypal insider-credential fraud case in telecom where the objective wasn't the data itself but the handsets, with the customer database used purely as a targeting list. It's a useful counterpoint to the espionage and mass-exfiltration entries because it shows how carrier customer systems get abused for ordinary criminal profit.

Aftermath: The National Crime Agency made three arrests, and the UK's Information Commissioner's Office (ICO) launched an investigation.

Sources: Dark Reading report

13. NTT Communications

Records affected: 17,891 corporate customer organizations (business customers, not individual consumers).

Date of breach: Unauthorized access was detected on February 5, 2025, and lateral movement to a second device was detected on February 15, 2025.

Date disclosed: March 2025.

Country: Japan.

Attack vector: Compromise of NTT Communications' Order Information Distribution System, detected through anomalous log activity, followed by pivoting to another internal device.

Data types exposed: Customer contract number, contract name, contact name, telephone number, email address, postal address, and service-usage information.

NTT Communications' breach is a business-to-business exposure rather than a consumer one; the records identify which Japanese enterprises buy which network services, a high-quality targeting list for supply-chain and social-engineering attacks against Japan's corporate sector.

Aftermath: NTT Com blocked the compromised devices and notified Japan's Personal Information Protection Commission.

Sources: BleepingComputer report, SecurityWeek report

14. BSNL (Bharat Sanchar Nigam Limited)

Records affected: Not stated in record counts. Two exposures were reported: approximately 191 GB of data in December 2023 and approximately 278 GB in May-June 2024. No verified subscriber count is available for either.

Breach dates: December 2023 and May 2024.

Date disclosed: December 2023 and June 24 to 26, 2024.

Country: India.

Attack vector: Not publicly established. Data was offered for sale by a threat actor using the handle kiberphant0m.

Data types exposed: Reported to include IMSI numbers, SIM card details, home location register data, and authentication keys, alongside server snapshots. If accurate, the presence of SIM and authentication material makes this closer to the SK Telecom breach than to a customer data leak.

The BSNL case matters because it's a state-owned operator providing government and rural connectivity, and because it was breached twice within roughly six months. The Indian government acknowledged the incident in Parliament, though the dataset's completeness and authenticity were never independently verified.

Aftermath: The Indian Computer Emergency Response Team investigated, and the Department of Telecommunications acknowledged the incident.

Sources: MediaNama report, Business Standard report

15. Telefonica

Records affected: The January 2025 incident involved roughly 20,000 employee names and email addresses, about 236,493 lines of customer data and 469,724 lines of internal ticket data, totaling around 2.3 GB. A second claimed incident later in 2025 involved an actor asserting that 106 GB was exfiltrated from another Jira instance; Telefonica disputes that second figure.

Date of breach: January 2025 (first), mid-2025 (second, claimed).

Date disclosed: January 2025 and subsequently.

Country: Spain.

Attack vector: Infostealer malware harvested credentials from about 15 Telefonica employees, which were used to authenticate to an internal Jira development ticketing server without additional multi-factor authentication.

Data types exposed: Employee names and corporate email addresses, internal Jira tickets containing customer data and operational details, and internal documentation.

Telefonica clearly illustrates the infostealer-to-internal Software-as-a-Service (SaaS) path that now drives a large share of enterprise breaches. No vulnerability was exploited; attackers harvested credentials from infected machines and reused them against an internal tool. Jira and similar systems routinely contain customer data pasted into support tickets, which can turn a developer tool into a customer data breach. The attackers were linked to the Hellcat extortion group.

Aftermath: Telefonica confirmed the January incident, blocked the affected accounts, and notified authorities.

Sources: Infosecurity Magazine report, BleepingComputer on the later claimed leak

16. Comcast Xfinity

Records affected: Approximately 35.8-35.9 million customers.

Date of breach: October 16 to 19, 2023.

Date disclosed: December 18 to 19, 2023.

Country: United States.

Attack vector: Exploitation of CVE-2023-4966, known as Citrix Bleed, a session-token disclosure flaw in Citrix NetScaler that has been exploited since late August 2023. Xfinity patched per the initial guidance but was compromised before Citrix issued additional mitigation advice, because patching alone didn't invalidate already-stolen session tokens.

Data types exposed: Usernames and hashed passwords; for some customers, names, contact details, the last four digits of Social Security numbers, dates of birth, and security questions and answers.

Citrix Bleed explains why edge devices dominate the modern breach picture; it lets attackers steal authenticated session tokens directly from device memory, so patching without terminating existing sessions left the door open. Exposing security-question answers alongside partial Social Security numbers is a bad combination for account-recovery abuse.

Aftermath: Comcast reset customer passwords and offered credit monitoring. Reporting indicates a class-action settlement of roughly $117.5 million.

Sources: SecurityWeek report, CISA advisory on CVE-2023-4966

17. Syniverse

Records affected: Login credentials for the Electronic Data Transfer environment were compromised for approximately 235 of Syniverse's carrier customers. No subscriber record count was ever published. Syniverse handled hundreds of billions of text messages per year, so the incident was often described in terms of potential exposure of billions of messages. Still, that framing is an inference about what could have been reached, not a confirmed exfiltration count.

Date of breach: Access began in May 2016 and was discovered in May 2021.

Date disclosed: September 2021.

Country: United States.

Attack vector: Not publicly detailed. An unknown actor maintained access to operational and IT systems for approximately five years.

Data types exposed: Carrier credentials for the Electronic Data Transfer environment, which carries SMS traffic, roaming records, and signaling data between operators.

Syniverse is the most important supply-chain entry here. It's the plumbing between carriers, and a five-year undetected presence there is the theoretical worst case for SMS-based two-factor authentication and for location tracking via roaming signaling. Nothing was ever publicly confirmed as stolen at scale. Still, the dwell time and position in the ecosystem make it a key point for third-party breach prevention across intermediary providers.

Aftermath: US senators raised national-security concerns about the adequacy of disclosure. No public fine. The incident is routinely cited in arguments for retiring SMS as an authentication factor.

Sources: SecurityWeek report

18. Charter Communications / Spectrum (2026)

Records affected: Disputed. Attackers operating under the ShinyHunters banner claimed to have obtained roughly 4.9 million Spectrum customer records; a separate analysis of the leaked dataset put the number of distinct individuals at 13 million or more, largely Spectrum Enterprise business contacts.

Date of breach: Claimed by the attackers to have occurred around April 1, 2026.

Date disclosed: Became public in May 2026.

Country: United States.

Attack vector: Reported as part of the broader ShinyHunters campaign against SaaS and Customer Relationship Management (CRM) tenants. Confirm the specific vector against a primary source, as early reporting on ShinyHunters campaigns has frequently been revised.

Data types exposed: full names, work email addresses, company and home addresses, and phone numbers, weighted toward Spectrum Enterprise business customers.

Of the 2026 entries, this is the most significant telecom incident, and it targets a company already named as a Salt Typhoon victim. The same carrier can be simultaneously a nation-state espionage target and a commodity extortion target, and the two require different controls. Because the dataset is heavily business-contact-oriented, its primary downstream risk is credible business email compromise rather than consumer identity theft.

Aftermath: Unresolved at the time of writing.

Sources: BleepingComputer on the Charter breach

19. Russell Cellular (Verizon authorized retailer, 2026)

Records affected: Claimed to be more than 6.3 million records in a 61 GB database offered for sale.

Date of breach: Unknown; database advertised March 17, 2026.

Date disclosed: March 2026, via a criminal forum listing.

Country: United States.

Attack vector: Not established.

Data types exposed: Not fully established from the listing; dealer systems of this type typically store customer identity data, credit application information, and account details.

Authorized dealers and retail franchisees are the least-defended part of the carrier ecosystem and hold much of the same customer data as the carrier itself, including the identity documents used for credit checks. This entry is included because the dealer channel is where SIM-swap fraud is most often enabled, and because it shows the pattern continuing into 2026.

Sources: Security Magazine on the Russell Cellular listing

20. Korea Telecom (KT) Corporation (femtocell breach)

Records affected: 16,647 subscribers confirmed by the regulator. The true figure is unknown because malware-infected server logs were missing.

Date of breach: October 8, 2024 to September 5, 2025 (approximately 11 months undetected).

Date disclosed: September 2025, after a customer complaint about unauthorized charges.

Country: South Korea.

Attack vector: Attackers duplicated authentication certificates recovered from lost or discarded KT femtocells (small, low-power cellular base stations designed for home or small business use) and used the cloned devices to attach to and traverse KT's internal network. KT set the femtocell certificate validity to 10 years and didn't restrict source IP addresses.

Data types exposed: Resident registration numbers, subscriber and device identifiers, and interception of SMS and voice-call authentication codes used for mobile payments.

KT stands out as the most technically instructive telecom breach of the current period. The entry point wasn't a server but a piece of radio-access hardware: a lost femtocell whose long-lived certificate the attacker cloned to gain a trusted position inside the network. The same BPFDoor implant family appeared here as in the SK Telecom breach, pointing to a common set of actors targeting Korean carriers.

Aftermath: In July 2026, the Personal Information Protection Commission fined KT 53.97 billion KRW (about $37.5 million to $39 million depending on the exchange rate) and issued corrective orders. The Commission referred KT to prosecutors over deleted server logs.

Sources: BleepingComputer report on the KT fine, Seoul Economic Daily report

21. LG Uplus

Records affected: Approximately 300,000 customer records were reported in the January 2023 incident.

Date of breach: Data surfaced in January 2023; the underlying compromise reportedly predated that.

Date disclosed: January 2023, with a series of denial-of-service outages the following month.

Country: South Korea.

Attack vector: Not fully established publicly. The Korean government's investigation found significant deficiencies in LG Uplus's security posture.

Data types exposed: Names, dates of birth, phone numbers, addresses, and other subscriber details.

LG Uplus completes the picture of systemic weakness across all three Korean mobile network operators, which is why South Korea now has one of the world's most aggressive telecom-privacy enforcement regimes. The company was ordered to increase security spending following the government investigation.

Aftermath: The Commission imposed a fine reported to be around 6.8 billion KRW. In July 2026, it referred LG Uplus to prosecutors over the alleged destruction of evidence servers.

Sources: Tech Times on the 2026 referrals

22. TalkTalk (2015)

Records affected: 156,959 customers, including bank account details and sort codes for 15,656.

Date of breach: October 21, 2015.

Date disclosed: October 22, 2015.

Country: United Kingdom.

Attack vector: SQL injection against three vulnerable web pages inherited from TalkTalk's 2009 acquisition of Tiscali's UK operations. The pages ran outdated software with a known vulnerability, and TalkTalk didn't know the pages existed.

Data types exposed: Names, addresses, dates of birth, phone numbers, email addresses, and, for a subset, bank account numbers and sort codes.

TalkTalk 2015 is the case that made UK boards take breach liability seriously. The vulnerability was a textbook SQL injection in inherited infrastructure, and the ICO's report was clear about the failure to implement basic security measures. It remains the standing example of acquisition-inherited technical debt as a cause of breaches.

Aftermath: The ICO imposed a £400,000 penalty in October 2016, then its largest ever, under the Data Protection Act 1998. TalkTalk reported costs of around £42 million and the loss of over 100,000 customers. A separate £100,000 ICO fine followed in 2017.

Sources: ICO monetary penalty coverage, TechCrunch report

23. TalkTalk (2025, disputed)

Records affected: Claimed at more than 18.8 million current and former subscribers by a threat actor using the alias b0nd. TalkTalk called the figure "wholly inaccurate and significantly overstated" and noted its subscriber base is around 2.4 million.

Date of breach: Claimed January 2025.

Date disclosed: January 27, 2025.

Country: United Kingdom.

Attack vector: TalkTalk attributed the incident to a third-party supplier, CSG's Ascendon subscription-management platform, rather than its own systems.

Data types exposed: Claimed to include names, email addresses, IP addresses, phone numbers, and subscriber PINs. TalkTalk stated that no financial information or passwords were involved.

The 2025 TalkTalk claim is included because it demonstrates the verification problem that dominates this category. It's also a third-party incident, continuing the pattern of carrier breaches originating in billing and subscription platforms.

Aftermath: TalkTalk notified the ICO and affected customers.

Sources: IT Pro report with TalkTalk's response, TechCrunch report

24. Vodafone Germany (2013)

Records affected: Approximately 2 million customers, confirmed by Vodafone.

Date of breach: Detected September 5, 2013.

Date disclosed: September 12, 2013.

Country: Germany.

Attack vector: Vodafone described a highly sophisticated intrusion into a server in Germany that it believed required insider knowledge. Vodafone identified a contractor with internal access and handed them over to the police.

Data types exposed: Names, addresses, dates of birth, bank sort codes, and bank account numbers. Vodafone stated that credit card details, mobile phone numbers, passwords, and PINs weren't accessed.

Vodafone Germany remains the largest confirmed breach at a European mobile operator before the 2024 to 2025 French cluster, and it's the earliest large-scale example of a recurring pattern - bank account identifiers, not card numbers, are the payload carriers hold in volume. The insider dimension is another reason it remains relevant, since privileged internal or contractor access remains a leading cause of carrier data loss.

Aftermath: Vodafone wrote to all affected customers and worked with German prosecutors, who arrested a suspect. This predates GDPR, so the penalty exposure under the then-applicable German law was small by modern standards.

Sources: SecurityWeek report, BBC News report

25. SFR (2024 and 2025 incidents)

Records affected: No single company-confirmed figure exists across the incidents. Reported figures include roughly 1.4 million records in a mid-2024 exposure, an SFR statement that bank details of around 50,000 customers were involved in the September 2024 RED by SFR incident, and "several million" names, addresses, and phone numbers after the December 2025 incident, alongside a criminal-forum listing claiming more than 3.6 million records. All of these are media-reported, aggregator-derived, or attacker-claimed. SFR hasn't published a consolidated count of affected customers.

Date of breach: A mid-2024 exposure; a September 3, 2024 incident in the order-management tool of RED by SFR; and a further intrusion reported in December 2025.

Date disclosed: September 19, 2024, for the RED by SFR incident; December 17 to 18, 2025, for the later incident.

Country: France.

Attack vector: For September 2024, unauthorized access to a customer order-management tool. For December 2025, reporting indicates the attackers compromised an internal tool used by fixed-network technicians and pivoted from there into SFR systems.

Data types exposed: Names, postal addresses, phone numbers, and email addresses across the incidents; for the September 2024 RED by SFR incident, also order details, IBANs, handset identifiers, and SIM card numbers.

SFR rounds out the four major French operators on this list, and together with Free, Bouygues Telecom, and Orange, it helps explain why France, rather than the United States, has been the telecom market most affected by breaches over the past two years. The recurrence itself is notable, and the December 2025 entry point was an operational field-engineering tool rather than a customer-facing system, exactly the class of internal application that rarely gets the same access-control scrutiny as billing or CRM.

Aftermath: SFR notified the CNIL and filed criminal complaints.

Sources: L'Usine Digitale on the 2025 incident, Le Monde Informatique on the claimed listing

26. Orange Belgium

Records affected: Approximately 850,000 customer accounts, confirmed by Orange Belgium.

Date of breach: Late July 2025.

Date disclosed: August 20, 2025.

Country: Belgium.

Attack vector: Unauthorized access to one of Orange Belgium's IT systems, detected by internal security teams. The Warlock ransomware group subsequently claimed responsibility for the attack.

Data types exposed: Names, phone numbers, SIM card numbers, PUK unlock codes, and tariff-plan details. Orange Belgium stated that passwords, email addresses, and banking information weren't compromised.

The Orange Belgium breach earns its place here because of what was taken, not how much. PUK unlock codes are the unblocking keys for a SIM, and their exposure, alongside SIM card numbers and phone numbers, materially lowers the barrier to SIM-related fraud and social engineering targeting retail staff. It sits in the same conceptual family as the SK Telecom USIM key breach, at a much smaller scale.

Aftermath: Orange Belgium notified customers, reported the incident to the Belgian Data Protection Authority, and implemented additional controls.

Sources: Orange Belgium corporate statement, BleepingComputer report

27. Orange Group / Orange Romania

Records affected: No company-confirmed count. The attacker claimed to have exfiltrated over 600,000 records and approximately 380,000 unique email addresses, totaling roughly 6.5 GB of data.

Date of breach: Access reportedly persisted for about a month, with the bulk of the exfiltration on February 25, 2025.

Date disclosed: Late February 2025.

Country: Romania (Orange Group is headquartered in France).

Attack vector: Reported use of compromised credentials against internal systems, including a Jira instance and internal portals. The actor was associated with the HellCat extortion group.

Data types exposed: Reported to include employee records, customer email addresses, source code, invoices, contracts, and partial payment card data. Orange stated the affected system was a non-critical back-office application and that customer operations weren't disrupted.

Orange Romania is the second entry here, after Telefonica, in which an internal Jira instance was the breach surface. Engineering ticketing systems accumulate customer data, credentials, and contract documents pasted in by staff, are usually authenticated via corporate single sign-on but lack two-factor authentication, and are rarely classified as systems that hold personal data.

Aftermath: Orange confirmed a breach of a non-critical back-office application at its Romanian branch and said it was investigating with the authorities.

Sources: BleepingComputer report, Tech Monitor report

28. TPG Telecom / iiNet

Records affected: Approximately 280,000 active iiNet email addresses and around 20,000 active iiNet landline numbers, plus around 10,000 customer names, street addresses, and phone numbers, and around 1,700 modem setup passwords.

Date of breach: Unauthorized access confirmed on August 16, 2025.

Date disclosed: August 19 to 20, 2025.

Country: Australia.

Attack vector: Unauthorized third-party access to an iiNet order-management system using stolen account credentials belonging to a single employee.

Data types exposed: Email addresses, landline phone numbers, customer names, street addresses, and a small number of modem setup passwords. TPG stated the system held no copies of identity documents and no credit card or banking data.

The iiNet incident is a useful counterweight to Optus in the Australian market: same country, same regulatory regime, three years later, and a materially better outcome because the compromised system didn't hold identity documents. That's a data-minimization result rather than a detection one, since the initial access still relied on a single set of stolen employee credentials, with no phishing-resistant second factor in place.

Aftermath: TPG removed the access, engaged external responders, and notified authorities.

Sources: iTnews report, The Register report

29. Singtel (Accellion FTA)

Records affected: Approximately 129,000 individual customers, plus a small number of enterprise customers and current and former staff, per Singtel's own disclosure.

Date of breach: Exploitation on or around January 20, 2021.

Date disclosed: February 2021.

Country: Singapore.

Attack vector: Exploitation of zero-day vulnerabilities in Accellion's legacy File Transfer Appliance, a third-party managed file-transfer product, using the DEWMODE web shell. Part of the global Accellion campaign attributed to FIN11 and the Clop extortion group.

Data types exposed: Names, dates of birth, mobile numbers, addresses, and national identity card numbers for individual customers; bank account details for a group of former employees. Clop claimed it took 73 GB of Singtel data.

Singtel is the textbook case for managed file transfer as a telecom breach vector, and it's the direct ancestor of the MOVEit and Cleo campaigns that followed. A managed file-transfer appliance is exactly the kind of system carriers use to move bulk subscriber and billing files to partners, so a single zero-day in a shared product can trigger simultaneous breaches across continents. Singtel is also the parent of Optus, which shows that group-level security programs don't automatically transfer to subsidiaries.

Aftermath: Singtel took the appliance offline, offered affected customers free identity monitoring, and notified Singapore's Personal Data Protection Commission. Accellion retired the product.

Sources: Infosecurity Magazine report, BleepingComputer on the Accellion campaign

30. KDDI (2026 email platform breach)

Records affected: KDDI initially reported that up to 14.22 million sets of email addresses and passwords may have been affected. In a later update, it confirmed unauthorized access to the email addresses of approximately 12.23 million users and the passwords of approximately 7.61 million users.

Date of breach: Initial compromise dated to May 16, 2026; unauthorized access detected on June 17, 2026.

Date disclosed: June 23, 2026, with a revised scope update in early July 2026.

Country: Japan.

Attack vector: Exploitation of a zero-day vulnerability in third-party software integrated into a shared email platform.

Data types exposed: Email addresses and, for a subset, mail-service account passwords. KDDI reported no confirmed secondary damage at the time of its filing.

KDDI is the largest confirmed telecom credential exposure of 2026 and makes the strongest case here for treating shared infrastructure as a concentration risk. One email platform, operated by one carrier, sat behind six separate consumer Internet Service Provider (ISP) brands, so a single zero-day exposed most of the Japanese consumer ISP market at once. ISP mailbox passwords are dangerous because that mailbox is often the account-recovery address for everything else the customer owns.

Aftermath: KDDI reported the incident to Japan's communications ministry and the Personal Information Protection Commission, forced password resets, and advised customers to change reused credentials.

Sources: BleepingComputer report, The Japan Times report

31. Odido (2026)

Records affected: Approximately 6.2 million customers.

Date of breach: February 7-8, 2026.

Date disclosed: February 2026, with the scale becoming clear through late February and early March 2026.

Country: Netherlands.

Attack vector: Social engineering attributed to ShinyHunters, where phishing emails and voice impersonation of internal IT staff were used to defeat multi-factor authentication and obtain access to a Salesforce customer-contact environment, from which data was exported. This follows the same campaign pattern as the wider 2025 to 2026 ShinyHunters Salesforce and CRM extortion wave.

Data types exposed: Names, addresses, phone numbers, email addresses, dates of birth, bank account details, and passport or national ID numbers. Odido stated that passwords, call records, and billing data weren't affected.

Odido ranks as the most damaging European telecom breach of 2026, and arguably the most damaging in Dutch history, because the exposed set combines the two things that can't be reset - bank account identifiers and government identity-document numbers. Dutch reporting established that the leaked data included records for government ministers and individuals under state protection, turning a consumer privacy incident into a national-security and personal-safety matter. Odido publicly refused to pay a ransom, after which the attackers released the data in stages, which demonstrates that non-payment doesn't undo exfiltration.

Aftermath: Odido notified the Dutch Data Protection Authority and customers, and Dutch law enforcement pursued suspects, with Dutch nationals reported as arrested or under suspicion.

Sources: BleepingComputer report, NL Times on ministers and protected individuals in the dataset

32. MTN Group

Records affected: Not disclosed. MTN confirmed that personal information of some customers in certain markets was exposed, but has never published a number.

Date of breach: Disclosed as a recent incident in April 2025; MTN didn't publish a precise intrusion date.

Date disclosed: April 24 to 25, 2025.

Country: South Africa (group headquarters), with the exposure described as affecting customers in specific markets.

Attack vector: Not publicly established. MTN referred to an unknown third party claiming to have accessed data associated with parts of its systems.

Data types exposed: Personal information of some customers in certain markets. MTN stated that its core network, billing systems, and mobile-money infrastructure weren't compromised.

MTN is the only sub-Saharan African carrier here, included because the region is systematically under-represented in breach reporting rather than because the incident is large in confirmed terms. It also illustrates a disclosure style common outside the US, EU, and Australia, where a listed-company announcement that confirms an incident, reassures about core systems, and never produces an affected-individual count.

Aftermath: MTN activated its cyber-response plan and notified regulators in South Africa and other affected markets.

Sources: The Record report, SecurityWeek report

How UpGuard helps monitor telecom breach risk

The incidents above cluster around a few repeatable failures: unpatched internet-facing edge devices and third-party and cloud tenants without multi-factor authentication. Continuous external visibility across those three surfaces is what shortens the time between compromise and detection. The UpGuard platform addresses them through three products:

  • Breach Risk provides external attack surface management and threat intelligence, including exposure and edge-device visibility, as well as dark-web exposure monitoring, prioritized by exploitation probability rather than raw severity scores. 
    • Edge-device and exposed-service discovery continuously maps a carrier's internet-facing footprint, including routers, VPN concentrators, remote-access gateways, and APIs, to identify exposure and missing patches. This asset class underpins Salt Typhoon's router persistence, the unauthenticated APIs behind the Optus and T-Mobile breaches, and the unpatched Citrix NetScaler flaw behind Comcast Xfinity.
    • Dark-web and criminal-forum monitoring watches marketplaces and forums for leaked credentials, session tokens, and stolen datasets, the access vector behind the AT&T Snowflake theft, the Telefonica and Orange Romania Jira breaches, and the KDDI credential exposure, so a security team can force resets and revoke sessions before stolen access is used against them.
    • Typosquat and lookalike-domain detection flags phishing infrastructure built to impersonate a carrier's brand, the kind of setup behind the social-engineering access used against Odido and the retail-channel fraud that fuels SIM-swap schemes.
  • Vendor Risk assesses and monitors third-party and supply-chain exposure, relevant to the Snowflake, Accellion, CSG/Ascendon, and Salesforce-tenant breaches that now dominate the sector.
  • User Risk surfaces workforce risks such as compromised credentials and infostealer exposure, the initial access behind the AT&T, Telefonica, Orange Romania, and Odido incidents.

To see how continuous monitoring applies to your own attack surface and vendor ecosystem, don't wait to be added to this growing list of the biggest data breaches in telecommunications - start a free trial.

Frequently asked questions

What is the biggest telecom data breach?

According to confirmed records, AT&T's 2024 Snowflake theft of call and text metadata for about 110 million customers is the largest single telecom record event. Salt Typhoon is the most consequential telecom compromise in terms of impact, but it has no defensible record count because it was an espionage access rather than a bulk theft.

What was the Salt Typhoon telecom hack?

Salt Typhoon was a Chinese state-linked espionage campaign that gained persistent access to the routing and lawful-intercept systems of US and global carriers. Its goal was to surveil high-value targets.

How many people did the AT&T data breach affect?

AT&T disclosed two separate 2024 incidents: a leaked dataset of about 73 million records and a Snowflake theft of call and text metadata affecting about 110 million wireless customers.

What are telecom carriers required to do after a data breach?

Obligations vary by jurisdiction, from US CPNI and FCC notification rules to the EU's NIS2 24-hour and 72-hour timelines, the UK Telecommunications (Security) Act enforced by Ofcom, and Australian oversight by the OAIC and ACMA.

Why are telecom companies targeted so often?

Carriers hold subscriber metadata, lawful-intercept systems, and SIM authentication secrets, and they expose large third-party and retail attack surfaces, which makes them valuable to both criminal and nation-state actors.