Data breach
Mobilink Pakistan
- Records
- 44,002,025
- Breach date
- 1 January 2013Estimated
- Added
- 13 January 2025
What was exposed
3 types of data · 2 more reported · 1 puts you at serious risk
- Names44,002,006
- Social security numbers43,997,814
- Phone numbers14,664,890
- Home addressesReported, not counted
- CitiesReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
Pakistan's largest mobile operator at the time, Mobilink, now known as Jazz, is at the center of one of the country's biggest data exposures. Our investigation team estimates that roughly 44 million records, indexed as 44,002,025 rows, are tied to this listing, with an estimated breach date of January 1, 2013. The data surfaced publicly years later: ZDNet reported in May 2020 that details of 44 million Pakistani mobile subscribers had leaked online, forming part of a larger cache of 115 million records that a hacker had tried to sell the month before for $2.1 million in bitcoin.
The origin of the data was never firmly established. ZDNet found that most of the leaked phone numbers belonged to Jazz (formerly Mobilink) customers, but the files also contained numbers from other Pakistani operators. The outlet concluded it could not confirm the data was taken from Jazz's own servers, and it noted the source could have been a government organization, a Jazz partner, or a telemarketing firm. ZDNet also verified the data's accuracy with multiple Pakistani users.
April 2020: A hacker attempted to sell a package of 115 million Pakistani mobile user records for $2.1 million in bitcoin on a hacker forum, an ad spotted by threat intelligence firm Rewterz, prompting investigations by the Pakistan Telecommunication Authority (PTA) and the Federal Investigation Agency (FIA), according to ZDNet.
May 5, 2020: ZDNet reported that 44 million Pakistani mobile subscriber records had been released online for free, and confirmed they matched samples from the larger 115 million record cache.
What Information Was Compromised?
Our analysis found the following data types in this breach: approximately 44 million names, roughly 44 million national identification numbers, and about 14.7 million phone numbers.
The national identification figures correspond to Pakistani CNIC numbers, the country's national identity card numbers, a category confirmed by ZDNet's analysis of the leaked files. That reporting also documented additional fields in the leaked records, including home addresses (city, region, and street name), landline numbers, and dates of subscription.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
CNIC numbers are a cornerstone of identity in Pakistan, used for banking, SIM card registration, and government services. Combined with full names, addresses, and phone numbers, this data can enable identity fraud, SIM swap attempts, and targeted scams. Coverage of telecom-related fraud in Pakistan has repeatedly described scammers using leaked personal details to impersonate operators and trick customers. Because the records also include data belonging to local companies, business contacts could face phishing and social engineering attempts as well.
What Is Mobilink Pakistan Doing in Response?
Jazz has disputed that the data came from its servers. ZDNet reported that the company previously rejected claims the leak originated from its systems, and that a Jazz spokesperson did not respond to a request for comment on the May 2020 disclosure. The Pakistan Telecommunication Authority and the Federal Investigation Agency were investigating the matter as of ZDNet's May 2020 reporting. We found no confirmed details of a formal customer notification program tied to this listing as of September 25, 2026.
What Should You Do If You Were Affected?
Watch for phishing calls, texts, and emails that reference your name, address, or mobile number. Scammers often use leaked data to sound convincing.
Never share your CNIC number, bank details, or one-time passwords over the phone or by message, even if the caller claims to be from your operator or bank.
Consider enabling a SIM PIN with your mobile operator and ask your carrier about extra protections against unauthorized SIM swaps.
Monitor your bank and mobile money accounts for unusual activity, and report anything suspicious to your provider right away.
If you believe your identity has been misused, you can report the incident to Pakistan's Federal Investigation Agency cybercrime wing.
