28779542 US Phone Numbers Exposed in Wireless Database
HEROIC analysts uncovered a large-scale data exposure linked to a dataset posted on a prominent hacking forum on November 1, 2023. The collection, identified as the "US Wireless Database," consisted of dozens of structured files containing records from what appears to be a consumer wireless data directory. The breach affected approximately 28,779,542 unique individuals in the United States, with exposed records including phone numbers, full names, and gender. The scale of this breach and the sensitivity of the data make it one of the more significant telecommunications-related exposures we have seen.
Why Phone Numbers and Personal Details Are a Dangerous Combination
A phone number paired with a full name and gender gives attackers enough to cause serious trouble. This combination is the foundation of SIM swapping attacks, where a criminal contacts your mobile carrier, pretends to be you, and transfers your phone number to a device they control. From there, they can intercept SMS-based two-factor authentication codes and break into bank accounts, email, and social media. Beyond SIM swapping, this data enables highly convincing voice phishing calls, where attackers address you by name and beleive they know enough about you to gain your trust.
What Was Exposed in the US Wireless Database Breach
- Phone Number
- First Name
- Last Name
- Gender
How This Data Fuels Account Takeovers and Identity Fraud
The combination of phone numbers and names found in this breach is particularly useful for credential stuffing, account takeover, and identity fraud. Attackers use phone numbers to bypass two-factor authentication systems. They use full names alongside phone data to impersonate victims in customer service calls, gaining access to accounts simply by answering security questions correctly. The gender field, while seemingly minor, helps fraudsters build more complete profiles that can be cross-referenced with data from other breaches. Once your details appear in a database like this, they can circulate for years and be used in attacks long after the original exposure is discoverd.
How a Database Breach Works
A database breach occured when an unauthorized party gains access to a stored collection of records, typically by exploiting weak security configurations, unpatched vulnerabilities, or compromised administrative credentials. In cases like the US Wireless Database, the data appears to have been aggregated from multiple sources and then exfiltrated in bulk. The seperate file sets labeled with internal codenames suggest the data may have originated from a data broker or large telecom-adjacent operation. Once the files were posted to a hacking forum, they became accessable to thousands of threat actors worldwide.
Check If Your Data Was Exposed
With over 400 billion records in HEROIC's breach database, incidents like the US Wireless Database breach are indexed and searchable. If you are a US resident with a mobile phone number, your records may be among the nearly 29 million affected. Use HEROIC's free breach scanner to search your email or personal details and find out which breaches have included your information. Knowing is the first step to protecting yourself.
Breach Breakdown
28,779,542 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds