Menu
Browse

Cyber Incident Victim: Lycamobile

Date:

Sep 2023

Location:

United Kingdom

Summary

A cyberattack disrupted Lyca Mobile's prepaid mobile services, impacting customer and retailer access to top-ups and affecting national and international calling in most of its markets, excluding the United States, Australia, Ukraine, and Tunisia. The company initiated an investigation with third-party experts and notified authorities to assess potential exposure of encrypted personal data while restoring most services, though some operational issues remained unresolved. The incident prompted assurances of data security due to encryption measures, though the attack's nature was undisclosed.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 2 techniques
Threat Actors Type Location
0 actors Available to members Available to members

Description

On September 24, 2023, Lyca Mobile, a global mobile virtual network operator serving over 15 million customers across 60 countries, experienced a cyberattack that disrupted critical services. The company first detected operational issues over the weekend following the attack, which prevented customers and retailers from processing prepaid top-ups through official channels. The incident also impaired national and international calling capabilities in most of its markets. Service disruptions were widespread but did not affect Lyca Mobile’s operations in the United States, Australia, Ukraine, or Tunisia. The company promptly initiated an internal investigation and engaged third-party technical experts to assess the breach’s scope and origin. It concurrently notified relevant regulatory bodies and law enforcement agencies in all impacted jurisdictions. While service restoration efforts began immediately, Lyca Mobile withheld specific technical details about the attack vector or perpetrator.

Cyber Incident Image

Lyca Mobile prioritized determining whether customer data was compromised, emphasizing that all records were fully encrypted but acknowledging the possibility of unauthorized access. The investigation focused on verifying the integrity of personal information while maintaining communication with cybersecurity partners and authorities. By October 1, 2023, the company had restored core services across all affected markets, though residual operational challenges persisted in certain areas. No evidence confirming data exfiltration or theft had been disclosed publicly at the time of reporting. The incident underscored the operational vulnerabilities inherent to MVNOs reliant on leased network infrastructure, though Lyca Mobile’s containment response demonstrated coordinated engagement with external experts and regulators throughout the recovery phase.

Sources
Sources available to members
1 source