[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fvoe5t7nec1mt":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"publishedAt":13,"modifiedDate":14,"contentUpdatedAt":15,"source":16,"sourceUrl":17,"sourceUrls":18,"pwnCount":20,"affectedCount":20,"affectedCountStatus":21,"affectedCountLowerBound":13,"affectedCountUnit":22,"hasEnglishDescription":4,"contentLocale":23,"availableLocales":24,"translations":26,"severity":29,"dataClasses":30,"description":36,"seoTitle":37,"seoDescription":38,"logoUrl":39,"isVerified":4,"isSensitive":4,"isSpamList":40,"isMalware":40,"company":41},"6a46ce5b5c6cfeabcece5f47","bmobile TSTT 2023","bmobile TSTT (2023) Data Breach","bmobile-tstt-2023","bmobile.co.tt","2023-10-09T00:00:00.000Z","2026-07-02T20:47:22.977Z",null,"2026-09-17T16:27:41.515Z","2026-07-19T00:10:01.939Z","Third party breach","https:\u002F\u002Fnewsday.co.tt\u002F2023\u002F11\u002F06\u002Ftstt-ceo-fired-after-data-breach\u002F",[17,19],"https:\u002F\u002Fguardian.co.tt\u002Fnews\u002Ftstt-ceo-fired-6.2.1852026.1264c12652",800977,"known","unknown","en",[23,25],"tr",{"en":27,"tr":28},{"slug":9},{"slug":9},"High",[31,32,33,34,35],"Email addresses","Names","Phone numbers","Physical addresses","Government issued IDs","\u003Cp>The bmobile TSTT data breach is a critical customer data incident associated with the Trinidad and Tobago-based telecom service bmobile, linked to the domain bmobile.co.tt, and under the main operator TSTT, dated for the period of October 2023. The record was added as a singular incident supported by a volume of 800,977 records. The record contained email addresses, names, phone numbers, physical addresses, and official ID fields; unsupported claims of passwords, payment cards, bank accounts, call content, or SMS content were excluded to avoid misleading the user.\u003C\u002Fp>\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\u003Cp>In the verification assessment, the bmobile name, TSTT corporate context, bmobile.co.tt domain name, October 2023 timeframe, 800,977 record volume, and the occurrence of customer contact\u002Fidentity fields together in the same incident were considered. The presence of name, phone, address, and identity fields together in telecom records poses a higher risk than ordinary marketing lists. Since the official data confirmation regarding the incident was not clear, the record was not marked as verified; however, because the data fields and volume were supported in multiple sources within the same context, it was retained as a separate customer data incident.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The bmobile TSTT data breach creates risks for users including SIM replacement, telecom support fraud, fake billing, account updates, and targeted phishing. When the phone number, name, address, and ID field are used together, attackers can impersonate a real customer representative. The user may be asked for a one-time code, ID photo, SIM renewal approval, bill payment, or account verification link. Due to the telecom context, the risk is not limited to email fraud; targeting can also be done via phone calls and text messages.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>In this case, the visible data classes consist of persistent and high-impact fields. The phone number is used both as a communication channel and as a verification tool for many accounts. The physical address and name personalize the message. Official identity fields can be abused in account recovery or fake subscription operations. Registration call logs, message contents, or account passwords were not expanded as if they existed; however, even the existing fields provide a strong foundation for SIM swapping and help desk social engineering.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>bmobile or TSTT customers should check unexpected SIM renewal, billing, package change, account verification, or identity update messages directly through known official channels. One-time codes, ID documents, payment information, or account login requests received by phone should not be shared. Additional verification should be reviewed for email, banking, social media, and messaging accounts associated with the mobile line. If there are SIM change and account activity alerts in the operator account, they should be enabled. A caller who knows the real phone number and address should not be considered trustworthy.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>For institutions, the bmobile TSTT data breach demonstrates the risk of relying on static personal information in telecom customer verification. A person who knows a name, phone number, address, or ID field should not be directly accepted as a customer. Additional verification should be applied in call centers, stores, SIM changes, number porting, package updates, and billing transactions. Suspicious SIM changes, communication information updates, and payment redirection requests should be completed with second-channel confirmation. Employees should be informed that social engineering attempts prepared with real customer data have a high persuasive power.\u003C\u002Fp>\u003Cp>In the bmobile TSTT data breach record, the scope was limited to supported fields. The record was kept as 800,977 customer entries; there were no claims of call content, SMS content, payment card, bank account, or account access. The incident was considered sensitive because the official ID field was supported; however, it was not expanded as if there were detailed document copies or financial transaction data. Nevertheless, the combination of name, phone, address, and ID fields poses a critical risk to telecom account security.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>The overall risk level has been assessed as critical; because the bmobile TSTT data breach combines telecom line security with identity and communication areas. The most practical steps for users searching for the bmobile data breach are to check the operator account directly through the official channel, enable SIM swap alerts, not trust code requests received via phone, use additional verification on important accounts linked to the mobile line, and independently verify bill\u002Fidentity update links. The record has been prepared to explain the real telecom security impact without adding unsupported data types.\u003C\u002Fp>","bmobile TSTT (2023) Data Breach (801 Thousand Reported Records)","bmobile TSTT (2023) Data Breach. 801 Thousand reported records are reported. Reported data: Email addresses, Names, Phone numbers. Review the scope, risks…","\u002Fuploads\u002Flogo\u002Fbmobile-tstt-2023.svg",false,{"name":42,"sector":43,"country":44,"website":10,"websiteArchiveUrl":45,"websiteStatus":45,"websiteCheckedAt":13},"bmobile \u002F TSTT","Telecommunications","Trinidad and Tobago",""]