When eSIM Providers and Carriers Get Breached: What Leaks and Why (2026)

Every breach notification letter follows the same template. We take your privacy seriously. The following categories of your information may have been affected. Then comes the list, and the list is the interesting part: it is a complete inventory of what the company decided to know about you. This article walks through the major carrier incidents of the last five years and draws the conclusion those letters never draw: the size of a breach is decided years earlier, on the day the signup form is designed.

Carrier breaches are not rare events

The incidents covered in this article alone add up to more than 300 million exposed customer records. AT&T lost identity data on about 73 million current and former customers, then call metadata on roughly 109 million. T-Mobile lost records on more than 76 million people in 2021 and another 37 million accounts in 2023. Optus exposed about 9.8 million Australians, roughly a third of the country. SK Telecom leaked the SIM authentication keys of some 23 million subscribers.

These are not obscure regional operators cutting corners. They are among the largest telecoms in the United States, Australia and South Korea, with security budgets most companies can only dream about. When a company holds identity records on tens of millions of people, those records eventually get out. The useful question is not whether your carrier can suffer a breach, but what a carrier data breach costs you personally, and that depends entirely on what the company knew about you in the first place.

AT&T in 2024: two breaches, two different lessons

AT&T disclosed two separate incidents in 2024, and together they map the whole problem.

In March 2024, a dataset covering about 73 million current and former customers surfaced on a dark web forum. AT&T confirmed it included full names, email and mailing addresses, dates of birth, Social Security numbers and account passcodes. The data appeared to date from 2019 or earlier, meaning it had circulated for years before the confirmation. Former customers took the biggest hit: roughly 65 million people who had already left AT&T were still sitting in its systems with their SSNs attached.

In July 2024, AT&T disclosed a second incident. Using stolen credentials, attackers pulled the call and text records of nearly all of its wireless customers, about 109 million accounts, from the company's environment on a third party cloud platform, Snowflake. The compromised account had no multifactor authentication. No names or Social Security numbers were taken this time, but the records showed which numbers contacted which, how often and for how long, across roughly six months of 2022. Metadata at that scale reconstructs a person's social graph, which is why the US Department of Justice twice let AT&T delay disclosure on national security grounds.

Lesson one: your data outlives your customer relationship. Lesson two: your data is only as safe as your carrier's least careful vendor account.

T-Mobile: what a breach series looks like

T-Mobile is the clearest evidence that money spent after a breach does not prevent the next one. In August 2021, an attacker spent months moving through its network and left with records on more than 76 million people: names, dates of birth, Social Security numbers, driver's license numbers. Around 40 million of those affected were former or even prospective customers, people who had merely applied for a credit check.

T-Mobile agreed to a 350 million dollar class action settlement in 2022. In January 2023, it disclosed the next incident: an attacker had been quietly pulling data through an exposed API since late November 2022 and collected profile data on 37 million accounts, including names, emails, phone numbers, birth dates and account details, before being detected and cut off in early January. In 2024, the FCC closed a settlement covering T-Mobile's breaches from 2021 through 2023: 15.75 million dollars to the US Treasury plus a matching 15.75 million dollar internal security investment.

None of this is unusual incompetence. It is what defending a giant identity database looks like in practice. The defender has to win every single day. The attacker has to win once.

Optus and SK Telecom: passports and SIM keys

The 2022 Optus breach in Australia showed exactly what KYC regulation puts inside a carrier database. Data on about 9.8 million current and former customers was taken through a poorly protected API, and for roughly 2.8 million of them it included government ID document numbers: passports, driver's licences, Medicare numbers. Those documents were on file because Australian law requires identity verification to activate a SIM. Optus ended up paying for passport replacements, and the episode pushed a national debate about how long telecoms should be allowed to retain identity documents at all.

SK Telecom in April 2025 leaked a different and in some ways scarier layer. Malware inside the network of South Korea's largest carrier exposed phone numbers, IMSI identifiers and USIM authentication keys tied to about 23 million subscribers. Authentication keys are what make SIM cloning and interception attacks practical, so this was not an identity theft problem but a network security one. SK Telecom offered free SIM replacements to its entire subscriber base and was hit with a record fine from Korea's privacy regulator, reported at about 97 million dollars.

The scoreboard: verified incidents side by side

Every row below comes from public disclosures, regulator statements or major security press reporting.

Why carrier databases keep leaking

It would be comforting to blame individual negligence, but three structural forces guarantee this keeps happening.

None of these forces yields to a better firewall. They are properties of holding the data at all, which is why the fix has to happen at the collection step, not the storage step.

Travel eSIM providers: smaller targets, not safe ones

To be fair: no travel eSIM data breach on the scale of the carrier incidents above has been publicly documented so far. But smaller does not mean safe, and researchers who examined the ecosystem did not like what they found.

In 2025, a team from Northeastern University presented the first peer reviewed study of the travel eSIM ecosystem at the USENIX Security Symposium. They purchased profiles from 25 providers, including the biggest consumer brands, and documented traffic silently routed through networks in countries the customer never chose, and reseller panels exposing customer IMSI numbers. In one case, a reseller could see device location to within about 800 meters and push SMS messages to users. Becoming a reseller required nothing more than an email address and a payment method.

The takeaway is not that travel eSIMs are broken. It is that they inherit the same structural rule: whatever a platform knows about you is visible to everyone the platform trusts, and one day, possibly, to whoever breaks in. A mainstream eSIM app knows your name from the payment card, your email, your purchase history and your device. How much a provider keeps is exactly what separates them, and it is the core question in our comparison of no-KYC eSIM providers.

Data minimization: the defense that survives the breach

Every defense above the data layer can fail, and in the incidents above, every one did: stolen credentials, a vendor account without MFA, an API without proper authorization. The only thing that cannot leak, under any failure mode, is a field that was never collected. Walk the layers:

This is the difference between "we protect your data" and "we do not have your data". The first is a promise about the future behavior of people you have never met. The second is arithmetic.

The honest limits of no-KYC

A no-KYC eSIM is minimization, not a cloak, and it is worth being precise about the residue that remains. The payment leaves its own trail: Bitcoin and most other chains are public ledgers, and a determined analyst can follow coins from an exchange account with your name on it to a purchase. Monero is the exception by design. The order itself exists: a plan, a timestamp, an ICCID, and if you connect that ICCID to your identity somewhere else, you have linked what the provider could not. And the network still sees a device: an IMEI, a tower location while connected. No provider can change radio physics.

So the defensible claim is narrower than the marketing many providers use, and stronger for it: with a no-KYC provider, a breach of the provider cannot produce your name, address or documents, because they were never in the system. That is all it is. It is also a lot.

Where Cypher eSIM stands

Cypher eSIM is built on the assumption that every database eventually gets attacked, including ours. So the database is boring by design. There is no account system and no email field. You buy on cypheresim.com behind an opaque order token, or through the Telegram bot, and pay in crypto: USDT on TRC-20, BEP-20, Arbitrum or Solana, plus BTC, ETH, SOL, USDC, DAI, XMR and TON. What gets stored is the order: the plan, the amount, the ICCID of the eSIM. Coverage spans 180 plus countries, data only today, with voice and SMS rolling out in August 2026.

The same honesty applies to us: no-KYC is not anonymity, and nobody should promise you 100 percent anonymity, including us. What we can promise is arithmetic. If our order database leaked tomorrow, it would contain no names, no emails, no phone numbers and no documents, because it never had them. When you evaluate any provider, ours included, skip the question "is my data safe" and ask the one that actually predicts your worst case: "what data do you even have". A provider that answers slowly has already answered.

FAQ

Has a travel eSIM provider suffered a major data breach?

Nothing on the scale of the AT&T or T-Mobile breaches has been publicly documented for a travel eSIM marketplace so far. Researchers have shown structural weaknesses instead: a 2025 USENIX Security study of 25 providers found reseller panels exposing IMSI numbers and, in one case, device location. The ecosystem is young, not immune.

What exactly leaked in the AT&T breaches?

Two separate things. The March 2024 dark web dataset held names, addresses, dates of birth, Social Security numbers and account passcodes for about 73 million people. The July 2024 Snowflake incident exposed call and text metadata for about 109 million accounts: numbers, timing, frequency, but not content or names.

If a provider is no-KYC, does that mean nothing about me can leak?

No. The order record still exists, and your payment can carry its own trail, since most blockchains are public. Monero reduces that trail by design. What no-KYC removes is the identity layer: a breached no-KYC database contains no names, documents or emails to steal.

Why do carriers collect so much identity data in the first place?

A mix of law and habit. Many countries mandate identity verification for SIM activation, credit checks require SSNs in the US, and retention rules can force carriers to keep records for years. That is why breach victims so often include people who left the carrier long ago, or never signed up at all.

What should I ask a provider before buying an eSIM?

Not "is my data safe", which no one can honestly answer, but "what data do you have about me and how long do you keep it". The answer defines your personal worst case in advance of any breach.

Breaches are weather now, not anomalies. You cannot control your carrier's patch schedule, vendor contracts or API hygiene. You can control how much of you stands in the blast radius. Pick providers that never asked.

Browse eSIM plans by country