The Vianet Breach Contains Exactly 93,345 Customer Email and Phone Records
HEROIC analysts identified a database breach at Vianet, a Nepali internet service provider, that occured in April 2020 and exposed 93,345 customer records. The compromised data included email addresses, phone numbers, first names, and last names, a dataset that provides attackers with a complete personal contact profile for nearly every affected individual and enables highly targeted social engineering attacks against Vianet's customer base in Nepal.
Names and Phone Numbers Together Enable SIM Swap and Vishing Attacks
When attackers hold both a customer's full name and phone number, they can call mobile carriers posing as the account holder and request a SIM swap to redirect calls and texts, including two-factor authentication codes. The Vianet dataset is partcularly dangerous because it originates from an ISP, meaning recipients of phishing calls or texts may beleive they are hearing from their own internet service provider. This trust makes vishing and social engineering attacks far more likely to succeed against the 93,345 individuals whose records were exposed.
What Was Exposed in the Vianet Breach
- Email Address
- Phone Number
- First Name
- Last Name
Why ISP Customer Data Carries Elevated Risk
Internet service provider records are accessable to a wide range of threat actors because they provide a direct link between a person's real-world identity and their online presence. Attackers who hold a victim's ISP account details can impersonate technical support, report fake outages to gather additional personal information, or cross-reference the data with other breached datasets to build more complete profiles. For Nepali users whose personal data may not be indexed in major international breach databases, this incident represents a seperate and significant exposure that has likely gone undetected.
How Database Breaches Work
A database breach occurs when an unauthorized party gains access to a production database, often through SQL injection, insecure API endpoints, or misconfigured access controls. The extracted records are compiled into a file and distributed through dark web marketplaces or Telegram channels. ISP databases are particularly valuable because the records tend to be accurate and current, tied to billing relationships where customers have strong incentive to keep their information up to date.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches across more than 400 billion leaked records to check whether your email address or personal information appeared in the Vianet breach or any other known incident. Run a free scan at HEROIC and take control of your digital exposure today.
Breach Breakdown
93,345 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds