[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f10x9ojx7atz7z":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":27,"seoTitle":15,"seoTitleEn":28,"seoDescription":15,"seoDescriptionEn":29,"logoUrl":30,"isVerified":4,"isSensitive":4,"isSpamList":31,"isMalware":31,"company":32},"68e3266eda11adda488252f6","orange-romania","Orange Romania Data Breach","orange.ro","2025-02-24T00:00:00.000Z","2025-02-27T05:39:42.000Z","2026-07-03T23:23:17.190Z","2026-07-18T23:55:31.290Z","Third party breach","",[],556557,"known",null,"unknown","High",[23,24,25,26],"Email addresses","Partial credit card data","Phone numbers","Subscription details","\u003Cp>The Orange Romania data breach is related to the exposure of customer and subscription data belonging to the Romanian telecom operator in the February 2025 period. The scope is approximately 556,557 email addresses. This record was treated as a telecom customer and subscription data breach; the company, country, sector, website, and data class fields were realigned to the verified scope. It was marked as sensitive due to phone, subscription, and partial card data.\u003C\u002Fp>\u003Cp>The text was rewritten to directly explain risk, scope, and actions to the user. The website domain was saved as orange.ro; since the protocol was not added, a format that would cause https to appear twice on the link side was not used. The industry was corrected from finance to telecommunications, and the country was corrected from United States to Romania.\u003C\u002Fp>\u003Ch2>Types of Leaked Data and Their Risks\u003C\u002Fh2>\u003Cp>The types of data seen in this record are email addresses, phone numbers, partial credit card data, and subscription details. The password field was not verified; partial card data alone was not considered sufficient for making payments. Unverified payment card, bank account, private message, health record, or additional profile fields were not added to the data class list; only supported fields were retained.\u003C\u002Fp>\u003Cp>Phone and subscription information can be used in fake operator calls, invoices, SIM changes, or campaign messages. An email address alone poses a risk of unwanted messages; when combined with phone, address, IP, date of birth, password, travel plan, partial card data, or device data, it becomes easier for an attacker to generate messages specific to the user. The risk assessment was made according to this combined effect.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The scope was confirmed with record 556,557 dated February 2025. Confirmed areas were preserved while unconfirmed areas were excluded. The event was not combined with datasets with similar names, events from different periods of the same company, or incorrect industry references.\u003C\u002Fp>\u003Cp>The registration was limited to the domain orange.ro and the context of Orange Romania; it was not merged with other Orange countries. The domain name, company name, and sector information were kept in the narrowest accurate context possible. In cases of uncertainty, the verified flag or website domain was set accordingly; thus, the user was not shown any uncertain brand responsibility.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>User groups at risk may include Orange Romania customers, those with a subscription account, and individuals whose phone number is in the system. Matching users should also evaluate other accounts where they use the same email, phone, username, or password pattern outside the relevant service.\u003C\u002Fp>\u003Cp>Telecom data provides direct context for SIM swapping and billing fraud. If there is context from corporate email, educational account, hotel reservation, telecom subscription, gaming community, open-source donations, or tracking software, the social engineering risk may increase. Details that appear correct alone are not a sign of trust.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Affected users must verify their invoice, campaign, SIM replacement, and card update requests through official Orange Romania channels. For records with a password field, all accounts using the same password should be updated; for records without a password field, the focus should be on the risks of email, phone, fake notifications, privacy, and identity matching.\u003C\u002Fp>\u003Cp>Instead of clicking on the links in the message, the address of the relevant service should be typed manually or the record in a trusted password manager should be used. Messages about shipping, account alerts, game rewards, support, donor notifications, travel reservations, security notifications, or subscription renewals should not be accepted without verification from an independent channel.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Strong account recovery, SIM swap protection, and card activity notifications should be kept enabled on telecom accounts. Users should regularly clean up old accounts, unnecessary profile fields, duplicate usernames, and old phone and address information. A unique password for each service and two-step verification where possible should be a basic rule.\u003C\u002Fp>\u003Cp>From the perspective of service providers, data minimization, strong password protection, monitoring of access logs, deletion of unnecessary fields, and readiness of user notification processes are required. Telecom companies should protect subscription and card data as high-risk customer information. Accurate scope explanation is also part of the security work; exaggerated or incomplete information can mislead the user into taking the wrong action.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>The user should first check this record using the email address. If a match is found, it should be assumed that the phone, subscription, and partial card information may be at risk; operator calls should also be verified. The absence of a match does not completely rule out the use of a different email or the reuse of an old password; critical accounts should also be reviewed.\u003C\u002Fp>\u003Cp>This record was verified and left as sensitive; the industry and country error was corrected. In this adjustment, data fields were left as English canonical classes, the description visible to the user was written in Turkish and original, unverified fields were not added, and the sensitivity flag was used only when supported by the risk context.\u003C\u002Fp>","Orange Romania Data Breach (556.6 Thousand Reported Records)","Orange Romania Data Breach. 556.6 Thousand reported records were reported. Reported data: Email addresses, Partial credit card data, Phone numbers. Review the…","\u002Fuploads\u002Flogo\u002Forange_ro.webp",false,{"name":33,"sector":34,"country":35,"website":9,"websiteArchiveUrl":15,"websiteStatus":15,"websiteCheckedAt":19},"Orange Romania","Telecommunications","Romania"]