Carrefour Mobile 2025 Data Breach

Carrefour Mobile French MVNO Breach (2025): 63K Customer Records Exposed

Company · Grocery and retail services · Supermarket and hypermarket chain · Global

Carrefour Mobile French MVNO Breach (2025): 63K Customer Records Exposed

Global retailer operating supermarkets, hypermarkets, and related digital services.

Confirmed · ObscureIQ Intelligence
Breach Risk Index i
65/100
Lower riskHigher risk
High and current: recent, valuable data circulating on the dark web now.
Data Sensitivity i
Elevated
Exposed data raises the risk of fraud, targeting, and impersonation. Proactive steps are warranted.
63KRecords
2025Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Crucial data exposed
Gov IDPassport Number
Classification Tags
Cloud MisconfigurationFood & DiningFoodDirect Customers2025

Breach Summary

Carrefour Mobile, the Belgian mobile virtual network operator brand owned by French retailer Carrefour, disclosed a customer data breach in April 2025. The incident was traced to Effortel, the mobile virtual network enabler that operates back-end systems on behalf of Carrefour Mobile and several other Belgian MVNOs.\n\nEffortel attributed the root cause to a hacker accessing test files that had been generated during work on a central emergency-services database. The exfiltrated information for Carrefour Mobile customers included names, dates of birth, email addresses, phone numbers, residential addresses, passport or national identity card numbers, subscriber numbers, and technical mobile-network identifiers including IMSI numbers and security question answers. Roughly 63,000 Carrefour Mobile customers were affected, alongside customers of two other Effortel-served MVNOs, Neibo and Undo, for a combined total of about 70,000 records.\n\nThe exposure carries higher risk than a typical contact-data breach because of the combination of identity documents and SIM-level identifiers. Passport or ID numbers paired with name, address, and date of birth support identity-verification bypass at financial and government services. IMSI and subscriber numbers make SIM-swap attacks more credible, which directly threatens accounts that use SMS-based authentication. Affected Carrefour Mobile customers should treat their phone number as a higher-risk authentication channel, change passwords used on the platform, and remain alert to fraud calls or messages referencing their Carrefour Mobile account.

Full threat analysis, exploitation vectors, and principal guidance below.

10 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

63K records analyzed

About Carrefour Mobile

Carrefour Mobile is a mobile virtual network operator (MVNO) brand operated by the Belgian arm of French global retailer Carrefour. The service offers mobile-phone subscriptions, prepaid plans, and SIM-card products to retail customers, with infrastructure provided by external mobile network operators rather than by Carrefour itself. The brand is one of several supermarket-linked MVNOs in Belgium and operates as a value-positioned telecom offering tied to the broader Carrefour retail ecosystem. The Belgian Carrefour Mobile operation is distinct from Carrefour's much larger French and global retail and digital businesses.

Why They Hold Your Data

Retail-linked mobile services collect subscriber identity, phone numbers, billing data, service addresses, payment records, and account-management information across telecom operations.

Recent Developments

Carrefour Mobile took its website offline as a containment measure following the April 2025 incident and required customers to reset passwords once service was restored. The breach was attributed to its mobile virtual network enabler, Effortel, which separately disclosed that the same incident affected three Belgian MVNOs it serves: Carrefour Mobile, Neibo, and Undo. Effortel attributed the root cause to a hacker accessing test files generated during work on a central database for emergency services. As of early 2026, no public regulatory action under GDPR has been announced against Carrefour Mobile or Effortel.

Data Points Exposed

3 verified field types
Email Address
Passport Number Critical
Phone Number

Breach Impact

Direct institutional cost to Carrefour has been measurable but not severe, and is shared with the upstream MVNE Effortel, which absorbed much of the operational and reputational fallout. Carrefour Mobile took its customer-facing site offline for containment, which interrupted account management and recovery for affected subscribers. The company engaged outside cybersecurity and forensic investigators and notified affected customers directly. The incident reinforces a pattern of supply-chain risk in MVNO operations, where retail brands rely on third-party network enablers for back-end systems. Carrefour itself has previously been subject to GDPR enforcement by France's CNIL, which raises the stakes if Belgian regulators take a closer look.

Exploitation & Downstream Threats

• SIM swap attacks where phone numbers are present | • Targeted phishing campaigns using exposed email addresses

Principal Risk Advisory

What this means for a principal

A consumer-service breach: contact and account data supports phishing, account takeover and profile enrichment. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.

What You Should Do

  1. Freeze credit at all three bureaus and monitor for new-account and tax-refund fraud.
  2. Guard against SIM-swap and vishing: add a carrier port-out PIN and verify any 'support' calls independently.
  3. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping and footprint neutralization: cross-reference against broker-available data and suppress still-removable elements, prioritizing address and phone, since this record re-seeds broker networks.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).

Protect Yourself

Check If You're Affected

Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation