Threat Actors Eye SIM-Swap Targets After the Mobile Communications of Iran Leak of 275,465 Subscribers
On illicit forums where telecom data trades for a premium, the Mobile Communications of Iran dump is already being sliced and cross-referenced against phone-number databases. The 275,465 subscriber records, stripped down to names and emails, are exactly the raw material a SIM-swap operator needs to stitch together a full victim profile before placing a call to a carrier support agent.
Why This Telecommunications Breach Is Dangerous
Hamrah-e Aval, the brand name under which Mobile Communications of Iran operates, is the largest mobile carrier in the country, and a breach of its subscriber data is not merely a privacy event. Threat actors with access to verified first name, last name, and email for a confirmed subscriber have cleared the hardest step of any social-engineering telecom attack: proving they are the account holder. Combined with information from other breaches or public records, this dataset becomes a foundation for SIM-swaps, account recovery fraud, and targeted surveillance of dissidents, journalists, and expats.
What Was Exposed in Mobile Communications of Iran
- Email addresses registered to active Hamrah-e Aval subscriber accounts
- First names and last names tied directly to those email accounts
- Subscriber confirmation, implicitly proving the target uses the specific carrier
- 275,465 total records large enough for automated enrichment pipelines
Why This Matters
Telecom breaches have a longer half-life than most. Email addresses change slowly, legal names almost never, and the link between a person and their mobile carrier is durable. Threat actors who obtain this data can hold it for years, waiting for the target's phone number to appear in a separate leak before launching a fully enriched attack. For users inside Iran, the exposure also raises the specter of state-adjacent surveillance, since detailed carrier subscriber lists are exactly what intelligence services and aligned groups seek out.
How Database Breaches Work
Large telecom subscriber databases are rarely stolen by casual attackers. The exfiltration typically involves either a compromised internal employee, a vendor with legitimate database access, or a prolonged network intrusion that goes undetected for months. Once the data is pulled, it commonly surfaces first on closed forums to a small circle of buyers, then leaks wider as those buyers resell or trade it. The Mobile Communications of Iran data appearing on April 8, 2025, is likely already deep into that second distribution phase.
Check If You Are Affected
If you are a current or former Hamrah-e Aval customer, treat your account as compromised and enable every available account-recovery safeguard with your carrier. Search the HEROIC DarkHive database of 400 billion-plus records to confirm whether your email appears in the Mobile Communications of Iran breach and identify any other dumps tied to your identity.
Breach Breakdown
275,465 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds