A threat actor has published what they claim is a database belonging to Blackbox LTD, a company that provides digital subscription billing services for mobile operators in Saudi Arabia.
According to the post, the alleged dataset contains information related to approximately 59,903 subscribers, along with tens of thousands of transaction records. The threat actor claims the data includes phone numbers, IP addresses, geolocation information, device models, operating system versions, mobile carrier details, subscription and billing information, and technical data that could potentially be used to target telecom services.
At the time of publication, there is no independent evidence confirming that the data is authentic or that Blackbox LTD has experienced a data breach. The source, scope, and legitimacy of the claimed dataset remain unverified. As a result, the incident should be treated as an unverified threat actor claim until confirmed by the affected organization or other trusted sources.
If the claimed data were found to be genuine, it could present risks beyond subscriber privacy. Cybercriminals could potentially use such information to launch convincing phishing campaigns that impersonate mobile operators, commit subscription or billing fraud, attempt identity theft, or target user accounts through social engineering techniques.
This incident serves as an important reminder that telecommunications-related information is highly valuable to cybercriminals. Even when a reported breach has not been confirmed, users should remain cautious of unexpected phone calls, text messages, or emails requesting personal information, one-time passwords (OTPs), or urgent payments.
Users are encouraged to verify any subscription or billing request directly through their mobile operator’s official website or mobile application, avoid sharing OTPs with anyone, and enable additional security features on their online accounts whenever available.
Organizations and individuals should also exercise caution when sharing or reposting unverified breach claims. Responsible reporting requires distinguishing between confirmed cybersecurity incidents and unverified allegations until sufficient technical evidence becomes available.
