Breach Intelligence Report 24 Sep 2024

The Bell Canada Breach Happened in 2017. The Data Resurfaced in 2024.

HEROIC
HEROIC Threat Intelligence Team
Email Address Phone Number Plaintext Password First Name Last Ip
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 2,231,118
Source Type Database
Origin Darkweb
Password Type Plaintext

The Bell Canada breach happened in May 2017. The stolen data sat in criminal hands for years. Then, in September 2024, it resurfaced on a dark web forum -- still live, still usable, and now available to anyone willing to look. For over 2.2 million Bell Canada customers, the clock on their exposure did not start in 2017. It started the day that database reappeared. This is the Bell 2017 incident: a breach that refused to stay buried.

This is one of two known Bell Canada data breaches. See also: Bell 2014, which exposed approximately 40,000 records in a prior incident.


Why This Is Dangerous

Bell Canada is one of Canada's largest telecommunications companies, operating bell.ca. In May 2017, an attacker exfiltrated a large customer database and made demands. When Bell did not comply, the data was released publicly online. The breach exposed 2,231,118 unique records containing some of the most dangerous field combinations a criminal can obtain: email addresses, phone numbers, plaintext passwords, full names, and IP addresses.

The 2024 resurfacing is particularly alarming because it signals the data has been re-indexed and is now circulating in new criminal networks. Even if a victim changed their Bell password years ago, their email address and phone number are almost certainly the same -- making them active targets for credential stuffing and phishing across hundreds of other platforms.


What Was Exposed

  • Email addresses -- 2 million+ unique addresses, testable against other platforms instantly
  • Plaintext passwords -- directly usable without cracking; the most dangerous credential type
  • Phone numbers -- enables SMS phishing and account recovery hijacking
  • First names and last names -- makes targeted attacks highly personalized
  • IP addresses -- reveals approximate home locations and internet service providers
  • 153,000 survey responses from 2011-2012 with additional personal context
  • 162 Bell employee records including names, phone numbers, and plaintext passcodes

Why This Matters

Plaintext passwords change the severity calculation entirely. Most breach data requires attackers to crack hashed passwords before use. Plaintext passwords are instant. Here is what attackers do with this dataset:

  • Credential stuffing: Email and password combinations are tested against banks, email providers, social media, and retail accounts using automated tools capable of millions of attempts per hour.
  • Account takeover: Even where passwords have since been changed, email addresses trigger account recovery flows and phone numbers allow interception of SMS verification codes.
  • Identity theft: Full names, emails, and phone numbers in combination are sufficient to impersonate individuals in financial and government systems.
  • Targeted fraud: IP addresses paired with names and contact details enable geographically targeted scams and convincing impersonation.

How a Database Breach Works

The Bell 2017 breach is a textbook extortion-driven database compromise. An attacker gained unauthorized access to Bell Canada's systems, extracted millions of records, and leveraged the data as a bargaining chip. When no deal was reached, the data went public. The inclusion of employee credentials alongside customer records indicates a significant internal access failure, likely through compromised admin accounts or insufficient network segmentation. The 2024 resurfacing suggests the data was picked up and redistributed by a second actor -- a common pattern with high-value telecom breach archives that remain in circulation for years.


Check If You Are Affected

HEROIC's database contains over 400 billion compromised records, including data from the Bell 2017 breach and thousands of other incidents. If you were a Bell Canada customer in 2017 or earlier, your information may be in circulation right now.

Search your email in HEROIC's 400B+ record database now.


Related Parts

  • Bell 2014 -- A prior Bell Canada breach exposing approximately 40,000 records

Breach Breakdown

Domain N/A
Leaked Data Email Address, Phone Number, Plaintext Password, First Name, Last Name, IP Address
Password Types Plaintext
Date Leaked 24 Sep 2024
Check in 5 seconds

2,231,118 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,532 scanned today
Breach Rank #1,208 by affected users
Impact Score
40
sensitivity + scale + recency
Est. Financial Impact $16.1M fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance