leak
Credible
telecom
RIMATEL: internal database compromised, customer and billing data exposed
RIMATEL
CompanyRIMATEL
Country
Sectortelecom
Breach date2026-05-15
People affected1,000,000
Data typesNot disclosed
<p>On 15 May 2026, a forum user published to have obtained access to data belonging to <strong>RIMATEL</strong>, Mauritania on a hacking forum. The claimed data includes customer personal identification records, payment receipts, transaction records. A limited sample was published to support the claim.</p>
<h2>What the source reveals</h2>
<p>An actor claims access to the internal infrastructure of RIMATEL, a Mauritanian telecom operator, with customer, payment and employee data.</p>
<h2>Risks</h2>
<ul>
<li>Identity theft and impersonation using exposed personal identification documents and biometric data</li>
<li>Financial fraud using compromised payment records, bank details, or transaction histories</li>
<li>SIM swap fraud using subscriber identity data to bypass two-factor authentication on banking and messaging accounts</li>
<li>Account takeover of mobile money, digital wallets, and value-added services linked to subscriber accounts</li>
<li>Call interception and location tracking if call detail records or network signalling data were exposed</li>
<li>Reputational damage and erosion of customer, citizen, or stakeholder trust in the affected organisation</li>
<li>Legal liability and regulatory fines under applicable data protection frameworks</li>
</ul>
<h2>What remains unknown</h2>
<ul>
<li>the total volume of data compromised and whether it includes additional categories beyond those disclosed</li>
<li>the method by which the data was obtained - whether through a direct database compromise, an insecure API, or a third-party breach</li>
<li>whether the data has been sold or distributed to additional parties beyond the forum post</li>
</ul>
<h2>Conclusion</h2>
<p>This incident confirms that RIMATEL's data has been compromised and is circulating on underground forums. Organisations in the telecom sector should treat this incident as a reminder to audit access controls, monitor for anomalous data exfiltration, and ensure incident response plans address data publication scenarios. Affected individuals should change passwords and remain vigilant against phishing attempts.</p>