This file describes the category of data behind the carrier incidents at 25-0804 and 25-0909, because the category explains why they matter more than a contact-details breach.
Three Separate Obligations Converge On One Record
Subscriber identification rules in many jurisdictions require an operator to verify identity, so identity document details are held. Billing requires a payment instrument — a card, or in much of Europe a direct debit mandate with an IBAN. Service delivery requires an address.
Each is individually justified. Together they produce a record set comparable to what a retail bank holds at account opening, accumulated by an organisation whose regulator is a communications authority.
The Security Regime Does Not Match The Data
Financial institutions carry supervision, capital and operational resilience requirements — DORA at 25-0117 being the clearest recent example. Those exist because of what banks hold and what happens if it moves.
A carrier holding functionally similar identity and payment data sits outside that regime. This desk is not arguing carriers should be regulated as banks; it is recording that the data followed the obligation and the supervision did not follow the data.
And Carriers Are Also The Recovery Channel
The uncomfortable compounding factor: a mobile number is the second factor for a great many accounts. An operator therefore holds both the identity data needed to impersonate a customer and the channel used to verify them.
The identity-boundary files at 25-0512 and 25-0813 record what happens when the recovery path is the weak point. A carrier breach supplies the material for exactly that attack, against the carrier’s own subscribers.
It describes the data category behind the carrier incidents in this database, supported by the sources listed below. It is not a claim about any specific operator’s controls. Corrections: corrections@forensicpost.com.