Advertisement · 728 × 90
#
Hashtag
#OrangeBelgium
Advertisement · 728 × 90
Preview
Orange Belgium Data Breach Exposes 850K Users to SIM-Swapping Risks  Orange Belgium has suffered a major data breach in which an attacker accessed the personal information of approximately 850,000 customers, with SIM card numbers and Personal Unblocking Key (PUK) codes among the most sensitive details exposed. The breach, disclosed in a press release dated August 20, 2025, immediately raised concerns about the increased risk of SIM swapping—a fraud technique in which criminals gain control of a victim’s phone number by transferring it to a SIM card under their control. This enables them to intercept calls and messages, including those containing one-time passcodes for multi-factor authentication, potentially bypassing account security measures.  The compromised data included customer first and last names, phone numbers, SIM card numbers, PUK codes, and tariff plan details. The company stressed that no passwords, email addresses, or banking and financial information were accessed.  Upon detecting the intrusion in late July, Orange Belgium claims it promptly blocked access to the affected system, tightened security, and notified law enforcement. Affected customers are being contacted directly with advice to remain vigilant against suspicious communications.  Notably, the incident coincides with a separate cyberattack against Orange’s French operations, although the company has not confirmed any link between the two events. The French incident reportedly did not result in unauthorized access to customer or corporate data. In response to the breach, Orange Belgium introduced additional verification steps to prevent fraudulent SIM swaps, such as requiring customers to answer extra security questions when requesting SIM replacements. The answers to these questions were not compromised in the attack, according to the company.  However, white hat hacker Inti De Ceukelaire criticized this approach, arguing that these measures are unlikely to fully prevent SIM swapping, especially if attackers attempt to port numbers to other providers. He also noted that Orange Belgium has not provided guidance or support for changing PUK or SIM numbers—information that is typically considered highly sensitive by other telecom providers.  De Ceukelaire further criticized Orange’s initial communications for minimizing the seriousness of the breach, particularly in labeling the exposed PUK and SIM card numbers as “not critical.” He argued that this classification downplays the real-world risk to affected customers and accused Orange of misleading communications and shifting responsibility to users. The attack on Orange Belgium has been claimed by the Warlock ransomware group, which reportedly posted samples of the stolen data online and is offering the full dataset for sale. Warlock has been linked to a recent wave of attacks exploiting vulnerabilities in Microsoft SharePoint, specifically the ‘ToolShell’ exploit chain, which came to light in July 2025. The same group has previously targeted UK telecoms provider Colt Technology Services, leveraging one of the SharePoint-related vulnerabilities. By contrast, the French Orange incident was attributed to a different group, Babuk2, suggesting the attacks are not connected.  The breach highlights ongoing vulnerabilities in telecom security—particularly the potential for SIM swapping to undermine multi-factor authentication—and underscores the importance of robust data protection and transparent incident communication. While Orange Belgium has taken some steps to mitigate the immediate risks, critics argue that more comprehensive safeguards and clearer customer guidance are needed to adequately protect users from sophisticated attacks.

Orange Belgium Data Breach Exposes 850K Users to SIM-Swapping Risks #CyberFraud #DataLeak #OrangeBelgium

0 0 0 0
Post image

// Une attaque ciblée frappe #OrangeBelgium : 850 000 clients potentiellement exposés. Les pirates pourraient exploiter ces données pour des fraudes par #SIMSwapping.

Identité numérique en danger, vigilance maximale recommandée !

➡️ www.zataz.com/orange-belgi...

#cybersécurité #piratage #zataz

2 0 0 0
Preview
"Klanten blijven kwetsbaar achter, we moeten meer verwachten van dit bedrijf": ethisch hacker hard voor Orange na datalek | VRT NWS: nieuws Ethisch hacker Inti De Ceukelaire is teleurgesteld in Orange Belgium na de cyberaanval waarbij de gegevens van zo’n 850.000 klanten zijn buitgemaakt door hackers. Volgens hem doet het telecombedrijf n...

Our research expert Dave Singelée in VRTnws on the #OrangeBelgium #cyberattack: Beware of targeted phishing using personal data to trick victims into revealing more info. Remain vigilant. www.vrt.be/vrtnws/nl/20...
#orange #phishing

0 0 0 0
Preview
L’opérateur Orange ciblé par une cyberattaque : quels sont les risques pour les 850.000 clients concernés ? - RTBF Actus Aucune donnée critique n’a été compromise : aucun mot de passe, adresse e-mail, ni coordonnées bancaires ou...

#OrangeBelgium a été la cible fin juillet d’une #cyberattaque, quels sont les risques pour les 850.000 clients concernés ?
👉Aucune donnée critique compromise : aucun mot de passe, adresse mail, ni coordonnées bancaires ou financières ne sont concernés
www.rtbf.be/article/l-op...

1 0 0 0
Preview
Cyberaanval bij Orange Belgium: hackers kregen toegang tot 850.000 klantenaccounts | VRT NWS: nieuws Telecomoperator Orange Belgium is het slachtoffer geworden van een cyberaanval waardoor hackers toegang kregen tot 850.000 klantenaccounts. Dat meldt het bedrijf in een persbericht. Er werden volgens ...

Cyberaanval bij Orange Belgium: hackers kregen toegang tot 850.000 klantenaccounts
vrtnws.be/p.APbpM6jmX #OrangeBelgium #DataLeak #Datenleck

0 0 0 0