Telecom Egypt: RADIUS session logs leaked on DarkForums
Telecom Egypt
Overview
On April 5, 2025, DarkForums user Knox, a Supreme Leader-ranked member with 242 posts, uploaded a dataset described as a breach of Telecom Egypt, Egypt's primary telephone company. The thread credits the leak to a leaker named KILLUAX and includes sample rows from what appears to be RADIUS authentication and session accounting logs.

What was published
The sample records contain RADIUS accounting fields for broadband sessions, including:
- Usernames and email addresses
- Session start and stop timestamps
- NAS IP addresses and port identifiers
- Framed IP addresses and MAC addresses
- Connection types and session durations
The sample entries date from September 2023.

Risks for affected individuals
Telecom Egypt broadband subscribers whose session logs are included could be exposed to targeted phishing that references their connection details. The data is largely technical, but usernames and email addresses tied to accounts enable credential attacks if passwords were reused.
What remains unknown
- Telecom Egypt has not publicly commented on the claim
- The total number of records is not stated
- The full dataset is not publicly visible in the thread sample
What affected people should do
Telecom Egypt customers should treat unsolicited messages referencing their internet account with suspicion and change passwords on linked email accounts. Enabling two-factor authentication on email and financial accounts is recommended.
Sources
- https://darkforums.ru/Thread-Telecom-Egypt-te-eg-Leaked-download