Data breach
Lyca Mobile
- Records
- 1,213,786
- Breach date
- 27 January 2025Estimated
- Added
- 27 January 2025
What was exposed
5 types of data
- Phone numbers1,213,786
- Phone carriers1,213,786
- Names865,553
- Email addresses635,210
- Account balances146,456
About this breach
A hacker forum post has surfaced advertising a database of more than 1.2 million Lyca Mobile customer records, most of them tied to the company's French operation. According to our investigation team, the listing contains 1,213,786 rows, including phone numbers, 635,210 email addresses, 865,553 names, and 146,456 account balances. Our team estimates the breach date as January 27, 2025, the same day the leak appeared. No ransomware group has claimed responsibility. The database was reportedly obtained through scraping or an exploitation of Lyca Mobile's systems rather than a direct hack, though the exact method remains unconfirmed. The company has not publicly commented on this specific leak, and details beyond the indexed data types remain limited.
Independent threat intelligence firm SOCRadar flagged the leak on January 27, 2025, noting that the threat actor claimed the data was obtained in January 2025 and covered 1.2 million users with roughly 375,000 unique email addresses. French security outlet Zataz separately reported that a hacker using the alias "Magouilleur" was behind the January leak. A second, larger leak affecting more than 1.5 million Lyca Mobile users surfaced in February 2025, suggesting the operator's systems were probed repeatedly over a short period. Zataz reported that attackers exploited weak protections on Lyca Mobile's reseller management panel, generating phone number ranges and pulling account data from them for days before the extraction was cut short.
Breach Timeline
January 27, 2025: SOCRadar's Dark Web Team detected a hacker forum post advertising an alleged Lyca Mobile France database of more than 1.2 million records, with the actor claiming the data was obtained in January 2025.
February 2025: Zataz reported a second Lyca Mobile data leak affecting more than 1.5 million users, detailing how attackers scraped records from a reseller panel over nine days.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses (635,210), phone numbers (1,213,786), account balances (146,456), names (865,553), and phone carrier information (1,213,786).
Independent reporting on the leaked forum listing by Brinztech suggests the dataset also contained telecom-specific network identifiers, including SIM card serial numbers (ICCID), international mobile subscriber identities (IMSI), and mobile numbers (MSISDN), alongside account numbers.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The combination of full phone numbers, names, and email addresses gives criminals the raw material for targeted phishing by text message and email. Because the messages can reference real account details, they are harder to spot than generic scams. SIM swap fraud is a particular concern for mobile customers: if an attacker convinces a carrier to port a victim's number, they can intercept one-time passcodes used for banking and email. Account balances in the leak could also help criminals identify which customers are worth pursuing.
What Is Lyca Mobile Doing in Response?
Lyca Mobile published a statement on its website acknowledging a cyber attack that disrupted top-up services and some national and international calling across its markets. In that statement, the company said it was urgently investigating whether personal information was compromised, that it believed its records were fully encrypted, and that it had engaged third-party technical experts. It also said it was in contact with regulators and law enforcement and that affected mobile services had been restored. The statement does not confirm the specific January 2025 leak examined here, and we have not seen a company notice that directly addresses the leaked database.
What Should You Do If You Were Affected?
Change your Lyca Mobile account password and any security questions, especially if you reused that password elsewhere.
Watch out for unexpected texts or emails claiming to be from Lyca Mobile. Do not click links or share one-time codes.
Contact your carrier to ask about extra protections against SIM swaps, such as a port-out PIN.
Monitor statements linked to your mobile account and report anything unusual to Lyca Mobile directly.
Be cautious with calls or messages that reference your phone number or account balance, as these details are now circulating.
In the news
- SOCRadar, "Lyca Mobile Breach, U.S. Government VPN Access, TalkTalk Data Leak Among Latest Cyber Threats"socradar.io (opens in a new tab)
- Brinztech Alert: The Alleged Database of Lyca Mobile is Leakedbrinztech.com (opens in a new tab)
- Zataz, "Lycamobile se fait syphoner, encore et encore !"zataz.com (opens in a new tab)
- Statement from Lyca Mobilelycamobile.fr (opens in a new tab)
