More Than a Million Salt Mobile Records Offered for Sale
A forum actor posting as SaltMobile1 is selling what they describe as a database of Salt, a Swiss mobile operator, containing more than 1,090,000 records. The stated fields are record identifier, name, date of birth, street and house number, postal code, city, country, a complete address string, email address, up to three telephone numbers, a count of numbers held and a timestamp. The actor's own word for how it was obtained is scraped rather than breached, and no mechanism is described. The post also carries a warning that another party is reselling the same samples. Price is by negotiation. The claim is unverified.
▣Post details
!What the post claims
- More than 1,090,000 records
- Described as scraped
- Record identifiers
- Full names
- Dates of birth
- Street and house number
- Postal code and city
- Country field
- Complete address string
- Email addresses
- Up to three phone numbers
- Count of numbers per record
- Extraction timestamps
- Sample published inline
- Price by negotiation
- Warning about a rival seller
- Offer of further samples
- No mechanism described
◱Screenshot
☷Mapped techniques
Mapped from the actor's own account. Claimed, not confirmed.
- Initial access T1190 Exploit public facing application Inferred Collection at this volume through scraping implies an interface returning full customer records to an unauthenticated or weakly limited caller. No endpoint is named.
- Collection T1213 Data from information repositories Inferred Every sample row carries a timestamp within the same second, differing only in fractions, which indicates one automated run rather than records created over time.
- Exfiltration T1567 Exfiltration over web service Inferred Samples are posted inline and the sale is handled through messaging services.
⚠Potential impact
For a mobile operator's customers the sharp risk is account recovery and SIM swap, because name, date of birth and address are the details support desks still use to confirm identity, and here they arrive already attached to the subscriber's own numbers. Records holding two or three numbers also expose household or family groupings, which makes a call claiming to be about a relative's line considerably more convincing. Dates of birth are the element that lifts this above an ordinary marketing list, since they are reused as a verification factor well beyond telecoms.
iStatus Unverified
The timestamps are the most informative detail in the post: across the sample they fall within a single second in January 2026, differing only in fractions, which is the signature of one scripted collection run rather than data accumulated by a business over years. The actor also says scraped rather than breached, which points at an interface returning more than it should rather than an intrusion, and the field mixture sits oddly, since address and multiple phone numbers resemble directory data while dates of birth and email addresses do not. Provenance is contested, with the post itself alleging another seller is circulating the same samples. Dark Web Informer has not retrieved the data and is not linking the contact addresses, and Salt has not publicly addressed the claim.
Dark Web Informer // Threat Intelligence