Unverified claim. A forum actor using the handle SaltMobile is selling what they describe as a scraped customer dataset from Salt Mobile, the Swiss telecommunications provider — more than 1.09 million records with names, dates of birth, full addresses, emails, and multiple phone fields. Dark Web Informer indexed the listing on September 18, 2026. Salt Mobile had not confirmed the claim at catalog time.
Canonical record: https://breachhistory.com/salt-mobile/salt-mobile-forum2026. Source: Dark Web Informer.
What the listing claims
The post advertises 1.09M+ customer PII rows with identity, contact, and address fields — including street, house number, ZIP/NPA, city, country, complete addresses, email addresses, up to three telephone fields, telephone counts, and timestamps. Visible sample rows were included. The actor framed the dataset as scraped data offered for sale and warned about another seller allegedly reusing samples.
What this is not: a Salt Mobile company notice, a Swiss FDPIC reprimand, or a Have I Been Pwned load confirmation. The 1.09 million figure is an actor/reporter count, labeled unverified in the BreachHistory catalog.
What is verified vs not
Verified: the existence of a public forum listing covered by trade press on September 18, 2026, with a detailed field list and sample rows described by Dark Web Informer.
Not verified: authenticity, completeness, scrape methodology, whether records are current customers, or Salt Mobile confirmation. Do not treat 1.09 million as a company-attested headcount.
Secondary outlets have also summarized underground advertisements of a similar volume. Treat those as coverage of the claim — not independent forensic validation.
Why Swiss customers should still act
Telecom PII packages are fuel for SIM-swap fraud, account takeover, and smishing that cites real bill themes. Even while Salt investigates, customers should assume elevated risk whenever large carrier datasets are marketed. Number-port freezes and MFA on the carrier account are cheap insurance relative to a hijacked phone number that receives your bank OTPs.
If the claim is later confirmed, Switzerland’s Federal Act on Data Protection (FADP) framework would frame regulatory expectations — but inventing a confirmed breach under FADP today would overstate the public record.
Timeline
- Late August / September 2026: Underground advertisements of alleged Salt Mobile customer data reported by secondary alert services.
- September 18, 2026: Dark Web Informer indexes the SaltMobile seller listing with 1.09M+ records and field inventory.
- Indexing: BreachHistory catalogs as unverified pending company or regulator confirmation.
Technical notes
Scraped telecom datasets often combine public directory fields with leaked CRM exports. Without Salt’s confirmation, defenders should hunt for credential stuffing against Salt logins and for smishing that cites Swiss IBAN or bill amounts — without asserting the dump is genuine.
Sample rows in a marketplace post prove that someone can display plausible Swiss-format addresses and phone numbers. They do not prove the full 1.09 million rows are fresh Salt CRM exports. Buyers and journalists both get burned by recycled samples.
Who should care
Salt Mobile subscribers in Switzerland — SIM-swap and phishing risk first; wait for salt.ch for confirmation language.
Enterprise admins whose staff use Salt numbers for MFA — push hardware keys or app-based MFA where possible.
Security teams at peer Swiss carriers — expect copycat phishing that swaps brand names.
What you should do
- Enable Salt account MFA; set a port-out / SIM freeze if offered.
- Ignore “Salt security team” WhatsApp or Telegram messages.
- Change reused passwords tied to your Salt email.
- Watch bank OTPs if your phone number is the 2FA channel.
- Wait for salt.ch official notices before assuming confirmed exposure.
- Report fraud to Salt and Swiss authorities through official channels.
- Employees: verify any internal “customer dump verification” tickets out-of-band.
- Do not purchase or redistribute alleged dumps.
- If you receive a cold call citing your home address and asking for a “SIM restore code,” hang up and dial Salt from the official site.
- Credit and account monitoring: useful if you see concrete fraud; not a substitute for SIM freeze.
Canonical record and sources
Salt Mobile forum claim catalog entry
Evidence-folder note 1 for Salt Mobile: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 2 for Salt Mobile: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 3 for Salt Mobile: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 4 for Salt Mobile: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 5 for Salt Mobile: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 6 for Salt Mobile: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 7 for Salt Mobile: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 8 for Salt Mobile: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 9 for Salt Mobile: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 10 for Salt Mobile: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 11 for Salt Mobile: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 12 for Salt Mobile: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 13 for Salt Mobile: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 14 for Salt Mobile: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 15 for Salt Mobile: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 16 for Salt Mobile: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 17 for Salt Mobile: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 18 for Salt Mobile: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 19 for Salt Mobile: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 20 for Salt Mobile: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 21 for Salt Mobile: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 22 for Salt Mobile: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 23 for Salt Mobile: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 24 for Salt Mobile: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 25 for Salt Mobile: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 26 for Salt Mobile: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 27 for Salt Mobile: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 28 for Salt Mobile: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 29 for Salt Mobile: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 30 for Salt Mobile: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 31 for Salt Mobile: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 32 for Salt Mobile: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 33 for Salt Mobile: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 34 for Salt Mobile: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 35 for Salt Mobile: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 36 for Salt Mobile: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 37 for Salt Mobile: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 38 for Salt Mobile: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 39 for Salt Mobile: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 40 for Salt Mobile: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.