
A recent data breach at Effortel, a mobile virtual network enabler (MVNE), has resulted in the unauthorized exfiltration of personal data belonging to approximately 70,000 customers of three Belgian mobile virtual network operators (MVNOs). The affected MVNOs include Carrefour Mobile, Neibo, and Undo.
Effortel, which provides technical infrastructure and services such as SIM card activation and billing to more than 30 MVNOs worldwide, experienced the breach during a testing phase involving the implementation of a central database. The company functions as an intermediary between physical telecom network operators like Proximus and virtual operators that do not maintain their own network infrastructure.
According to Laurent Bataille, General Manager at Effortel, the breach occurred while testing a system integration that required the use of real customer data. The objective was to facilitate the transmission of essential information to emergency services. During this process, test files containing sensitive customer information were created. A hacker exploited a vulnerability in the support portal connecting MVNOs and Effortel, gaining unauthorized access to these files.
The compromised data includes names, birth dates, email addresses, telephone numbers, physical addresses, passport numbers, subscriber identifiers, and technical details such as SIM card numbers. Bataille noted that for approximately 60 to 65 percent of customers, identity confirmation occurs via online payments, and no direct identity data is stored. Instead, payment IDs are kept, which can only be linked to personal information through the payment provider.
Effortel has advised customers to remain vigilant against potential phishing attacks, warning that malicious actors may use the stolen data to craft convincing fraudulent communications. Prior to this announcement, Carrefour Mobile reported last month that data from 64,000 of its customers had been stolen. Undo, another MVNO operating through Effortel, also notified its customers three weeks ago of a cyberattack that led to the theft of personal information by an unauthorized party.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543