leak Potential Rwanda (RW) telecom

MTN Rwanda: Kerberos account ticket hashes shared on a forum

MTN Rwanda (mtn.co.rw)

📅 24 July 2025 👁️ 1 views
CompanyMTN Rwanda (mtn.co.rw)
CountryRwanda (RW)
Sectortelecom
Breach date2025-07-24
People affected1,000,000
Data typesNot disclosed
<p>On 24 July 2025, a forum user claims to have leaked data belonging to <strong>MTN Rwanda (mtn.co.rw)</strong>, Rwanda on a hacking forum. The claimed data includes Kerberos ticket hashes. A limited sample was published to support the claim.</p> <h2>What the source reveals</h2> <p>A forum user shared Kerberos ticket hashes for an administrator account on the mtn.co.rw domain of MTN Rwanda.</p> <h2>Risks</h2> <ul> <li>Credential stuffing and account takeover attacks if password hashes are cracked and reused across multiple services</li> <li>SIM swap fraud using subscriber identity data to bypass two-factor authentication on banking and messaging accounts</li> <li>Account takeover of mobile money, digital wallets, and value-added services linked to subscriber accounts</li> <li>Call interception and location tracking if call detail records or network signalling data were exposed</li> <li>Reputational damage and erosion of customer, citizen, or stakeholder trust in the affected organisation</li> <li>Legal liability and regulatory fines under applicable data protection frameworks</li> </ul> <h2>What remains unknown</h2> <ul> <li>the total volume of data compromised and whether it includes additional categories beyond those disclosed</li> <li>the method by which the data was obtained - whether through a direct database compromise, an insecure API, or a third-party breach</li> <li>whether the data has been sold or distributed to additional parties beyond the forum post</li> </ul> <h2>Conclusion</h2> <p>While the claim has not been independently verified, the potential exposure of data from MTN Rwanda (mtn.co.rw) warrants attention. Organisations in the telecom sector should treat this incident as a reminder to audit access controls, monitor for anomalous data exfiltration, and ensure incident response plans address data publication scenarios. Affected individuals should change passwords and remain vigilant against phishing attempts.</p>