Tuttur
We noticed a concerning data leak originating from Tuttur, a Turkey-based mobile gambling application, surfacing on July 10, 2025. The sheer volume of compromised personal information, particularly the inclusion of phone numbers alongside full names, immediately raised a red flag regarding potential downstream impacts like targeted phishing or SIM-swapping attacks. What struck us as particularly noteworthy was the relatively straightforward nature of the exposed data, suggesting a potential vulnerability in data handling or storage rather than a sophisticated exfiltration technique. The fact that this data subsequently appeared on a well-known hacking forum amplifies the urgency of understanding the root cause and mitigating further exploitation.
The Tuttur breach, discovered on July 10, 2025, involved a database compromise that exposed approximately 330,239 unique phone numbers, along with corresponding first and last names. While the total number of affected records is reported to be closer to 500,000, the precise count of uniquely identifiable individuals whose full names and phone numbers were exfiltrated is significant. This type of data is highly valuable for threat actors seeking to conduct social engineering campaigns, account takeovers, or to build detailed profiles for more advanced attacks. The data's subsequent appearance on a prominent hacking forum indicates that it has entered the illicit marketplace, increasing the likelihood of its acquisition and misuse by various malicious actors. The source structure of the leak, while not detailed in the initial report, is presumed to be a direct dump of user account information, highlighting a critical failure in data segregation or access control within Tuttur's infrastructure.
While specific news coverage on the Tuttur breach itself is limited at this early stage, the leak of personal contact information is a recurring theme in cybersecurity incidents. OSINT searches reveal Tuttur's positioning as a popular mobile gambling platform in Turkey, suggesting a user base susceptible to targeted SMS-based scams or fraudulent communications. Research into similar breaches involving mobile applications often points to vulnerabilities in API security, insecure direct object references (IDOR), or misconfigured cloud storage. The presence of phone numbers in such leaks frequently correlates with an increased risk of SIM-swapping attacks, where attackers port a victim's phone number to a SIM card they control, thereby intercepting multi-factor authentication codes and gaining access to sensitive accounts.
Breach Breakdown
330,239 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds