Yamm Data Breach Exposes 29K Saudi Arabian Logistics Platform Phone Records
HEROIC's DarkHive system discovered the Yamm breach, exposing 28,914 records in July 2025. This Saudi Arabian platform suffered a database compromise that revealed user phone numbers, first and last names belonging to Saudi Arabian users of this service, without exposing any email addresses or password data.
Why This Is Dangerous
Phone number and identity breaches from Gulf region platforms are particularly dangerous because Saudi Arabian mobile numbers are the primary identifier for banking, government services, and WhatsApp communications in a region where phone-based identity verification is deeply embedded in financial and government authentication systems. Full names combined with Saudi phone numbers satisfy the identity requirements for social engineering attacks against Saudi Telecom Company and other Gulf region mobile carriers, enabling SIM swapping attacks that bypass SMS-based authentication. Saudi and Gulf region phone number databases are specifically sought for targeted fraud campaigns exploiting the region's mobile-first digital economy.
What Was Exposed
- Phone Number
- First Name
- Last Name
Why This Matters
Yamm users whose phone numbers and names were exposed face SIM swap fraud risk, as the combination of confirmed phone number and full name provides attackers with the information needed to impersonate victims to mobile carriers and execute unauthorized SIM transfers. Saudi Arabian SIM swapping attacks can compromise WhatsApp accounts used for business communication, banking OTP authentication, and government service verification that relies on mobile number identity. Anyone whose data was exposed in this breach should contact their mobile carrier to add a SIM lock or port protection and enable additional authentication on WhatsApp and banking platforms.
How Database Breach Works
Gulf region consumer platforms collect mobile phone registration data that is the primary digital identity mechanism in Saudi Arabia and neighboring countries, making these databases uniquely valuable for mobile-based fraud operations. Attackers exploit web application vulnerabilities to extract user contact databases from regional platform systems. The resulting Saudi Arabian phone number and identity data is incorporated into targeted SIM swap campaigns and WhatsApp social engineering operations that exploit the primacy of mobile identity in Gulf region digital services.
Check If You Are Affected
HEROIC offers a free identity scanner searching over 400 billion records including data from the Yamm breach. Visit heroic.com to check if your information was exposed.
Breach Breakdown
28,914 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds