Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > Hacker Claims 46 Million Claro Brazil Phone Numbers Linked to Tax IDs

Hacker Claims 46 Million Claro Brazil Phone Numbers Linked to Tax IDs

By: Morgan Cipher Senior Privacy Journalist

Last updated: September 7, 2026

Human Written
Hacker Claims 46 Million Claro Brazil Phone Numbers Linked to Tax IDs
  • A hacker known as GordonFreeman claims he broke into Claro Brazil’s system through an exposed API.

  • The alleged leak reportedly links 46,033,380 phone numbers to Brazilian CPF ID numbers.

  • Claro Brazil has not confirmed the breach, and no outside expert has verified it yet.

Threat actors keep finding new ways to target telecom companies around the world. A cyber threat tracker called VECERT Analyzer recently flagged fresh activity on a dark web forum. The post appeared on a site known as DarkForums. It came from a hacker who goes by the name GordonFreeman.

According to the post, the hacker broke into a system tied to Claro Brazil. Claro is one of the largest telecom providers in Brazil. The hacker claims the breach came through an exposed API, a tool that lets systems talk to each other online.

If real, the breach could put tens of millions of people at risk. Analysts have labeled the case a telecom data breach involving an exposed API and PII exposure. The claim has not spread far yet, but researchers are already watching it closely.

Details of the Alleged Breach

According to the post, GordonFreeman says the target system held about 90.8 million records in total. The hacker claims to have pulled out close to half of that total before anyone noticed. That works out to roughly 46,033,380 records taken from the system. The actor says their activity got detected partway through the extraction process.

The alleged dataset spans records dating back to around 2004, reaching up to 2026. It reportedly comes as a .DB file that measures about 6.1 GB in size. The hacker also shared a smaller sample of two million records as apparent proof. Analysts stress this claim comes only from the hacker’s own post so far.

No one has confirmed that the exposed API truly belonged to Claro. No one has confirmed the data is recent or still active either. It remains unclear if the 46 million records match unique, active customers.

Analysts have not identified the exact endpoint the hacker allegedly used. The precise vulnerability behind the claimed breach is also unknown right now. Even the timeline of when the alleged access happened stays unclear.

Data Allegedly Exposed in the Leak

Analysts say the leaked data mainly links two details together. Each record reportedly pairs a phone number with a CPF number. A CPF number works like a Brazilian version of a Social Security number. That kind of pairing makes the data especially valuable to scammers. Criminals can use paired data like this to build a convincing fake identity.

They could pretend to be a bank, a delivery service, or even Claro itself. Combining phone numbers with government ID numbers raises serious fraud risks. Someone could use the data to intercept one-time passwords sent by text. They could also use it to trick victims into revealing more personal details.

Analysts classify this pattern as a high-value combination for social engineering attacks. The claimed correlation between phone numbers and CPF records makes the alleged leak more dangerous. Still, no independent party has opened and verified the actual file yet. Until that happens, the scale of the real risk stays a guess.

Cybersecurity teams are urged to treat the claim seriously despite the lack of confirmation. Security experts recommend that telecom companies review their public and private APIs right away. They should check for endpoints that skip proper authentication steps entirely.

Teams should also look for broken object-level access issues, sometimes called BOLA problems. Reviewing rate limits on API traffic can help catch unusual spikes early. Companies should also audit logs tied to CPF-based and phone number-based searches.

Checking for leaked tokens, API keys, and service accounts remains important too. Any recent changes in account permissions deserve a much closer look. Security teams should also flag sudden mass data access or strange outbound traffic.

Vendors, gateways, and third-party accounts connected to the network need review as well. Firewalls and API gateways should get a fresh security check soon. Rotating secrets and passwords can reduce damage if a breach gets confirmed later.

For everyday users, the advice stays simple and practical. Brazilian Claro customers should watch for strange calls or messages claiming to be from the company. They should avoid sharing personal details over unexpected calls or texts.

Enabling two-factor authentication on important accounts adds another useful layer of safety. Users should also monitor their bank and phone accounts for unusual activity regularly. Small habits like these can lower the damage even if the breach turns out real.

Claro Brazil has not released any statement confirming or denying the claim. Independent researchers have not verified the leaked sample either, as of now. The situation remains fully unconfirmed, and the claims come only from the hacker’s dark web post.

No investigator has proven the intrusion happened at Claro’s own systems directly. Anyone concerned about their digital identity should still take basic precautions now.

A dark web actor claims to sell 2 million records allegedly linked to China’s Tianyancha, including corporate details, emails, and phone numbers. However, the dataset remains unverified, and Tianyancha has not confirmed any security breach.

VECERT Analyzer continues tracking this claim through its centralized threat monitoring system. The platform runs a public dashboard at analyzer.vecert.io for ongoing updates. A separate monitoring console at monitor.vecert.io tracks related cyber threat activity too. Readers can follow both channels for updates as this story develops further.

Share this article

You might also like

Berlin District Blocks CrowdStrike Probe After Rhysida Ransomware Attack

Berlin District Refuses CrowdStrike Security Scan After Rhysida Ransomware Attack

Berlin’s Senate Chancellery hired CrowdStrike to search for signs of a recent ransomware hack. The Lichtenberg district refuses to let…

September 7, 2026
Shipup Cyberattack Exposes Customer Data From Micromania and Easypara

Shipup Cyberattack Exposes Retail Customer Data in Supply Chain Security Breach

Cyberattack on delivery tracking service Shipup has revealed the names, emails, and phone numbers of the customers of Micromania and…

September 4, 2026
French Ministry Hit by Cyberattack as Hacker Claims Thousands of Records Stolen

France Confirms Cyberattack on Environment Ministry as Hacker Claims Data Theft

A hacker claims to have stolen two databases tied to France’s Ministry of Ecological Transition. The alleged files contain data…

September 3, 2026

About the Author

Morgan Cipher

Morgan Cipher

Senior Privacy Journalist

Morgan combines a journalist’s curiosity with a security specialist’s precision. His reporting on data breaches, privacy laws, and encryption tech has been featured in several tech publications. At TorWire, he focuses on real-world threats and how to counter them, always with an eye on what’s next in digital privacy.

Comments (0)

No comments.