Effortel breach exposes data of 70,000 Belgian mobile customers
- Organization
- Effortel
- Exploit
- Hacking
- Industry
- Telecommunications
Effortel, a Belgium-based mobile virtual network enabler that supplies back-end infrastructure to more than 30 mobile virtual network operators worldwide, confirmed in May 2025 that a data breach had exposed personal information belonging to about 70,000 customers of three Belgian operators: Carrefour Mobile, Neibo and Undo.
The company said the exposure originated in testing work for a central database intended to pass subscriber details to emergency services. Real customer data was used to generate test files, and an attacker who exploited a support portal linking the operators to Effortel was able to reach them.
Reported data categories included names, dates of birth, email addresses, phone numbers, postal addresses, passport numbers, subscriber numbers and technical SIM card identifiers. Effortel said a majority of the customers involved, between 60% and 65%, had no direct identity data held in the affected systems, only payment identifiers linked through payment providers.
Laurent Bataille, Effortel's general manager, acknowledged that files generated for the integration tests had leaked and urged customers to stay alert to phishing attempts built on the stolen details. Carrefour Mobile notified its own customers by text message and published a dedicated help page. It had earlier reported some 64,000 stolen customer records, and Undo had warned its customers of a cyberattack roughly three weeks before Effortel's disclosure.