SIM-Swap Risk Surges After FacilityBills Breach: 27,677 Records
HEROIC analysts identified a data breach tied to FacilityBills, a Nigerian bill management application, on August 1, 2024. The exposure affected 27,677 records and included phone numbers, first names, and last names. No passwords were included in this breach. The compromised data was discovered through monitoring of underground forums and data marketplaces where the dataset was made available.
Why This Is Dangerous
With access to full names and direct phone numbers, attackers can launch highly personalized social engineering campaigns, impersonate account holders to customer support teams, and execute SIM-swap fraud. Nigeria's mobile-payment ecosystem means phone numbers are often tied directly to financial accounts, amplifying the downstream risk of this specific data combination. Attackers who already hold other breach data can use this to enrich profiles and move toward account takeover with greater precision.
What Was Exposed
- Phone Number
- First Name
- Last Name
Why This Matters
Even without passwords, exposed personal identifiers create lasting risk. Threat actors combine name and phone data with other breached datasets to build complete identity profiles. These profiles feed credential stuffing attacks on accounts where the victim reused usernames, enable targeted phishing and vishing calls addressed by the victim's real name, and support identity theft and fraudulent account creation. The fact that FacilityBills users trusted the platform with their contact details makes the breach a direct vector against their financial and personal lives.
How Database Breaches Work
A database breach occurs when an attacker gains unauthorized access to a backend data store, typically by exploiting misconfigured access controls, unpatched software vulnerabilities, or weak authentication on database management interfaces. Once inside, the attacker can export user tables directly. Because bill-management apps must store contact information to function, the records are dense with usable PII. Organizations that fail to encrypt fields at rest, segment database access by role, or monitor for unusual query volumes are especially vulnerable to this type of exfiltration.
Check If You Are Affected
If you used FacilityBills, your phone number and name may be in circulation on dark web forums. HEROIC's free scanner checks your personal information against more than 400 billion exposed records. Run a free scan now to find out whether your data was part of this or any other known breach.
Breach Breakdown
27,677 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds