Cyber Incident Victim: DELTA Mobiel
Date:
Dec 2022
Location:
Netherlands
Summary
A data breach at DELTA Mobiel and Caiway Mobiel compromised customer information from their order systems, including names, addresses, email addresses, birth dates, phone numbers, and bank account details. While passwords, credit card data, and customer IDs remained secure, the stolen personal data poses risks of identity fraud and phishing. Affected customers were directly notified and advised to remain vigilant against suspicious communications. The companies disabled their order platforms, reported the incident to regulatory authorities, and engaged cybersecurity experts and law enforcement to investigate. The breach occurred despite existing security measures, with updates provided via dedicated informational pages.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On December 5, 2022, DELTA Fiber identified a data theft incident affecting customers of its subsidiaries DELTA Mobiel and Caiway Mobiel. Unauthorized parties exfiltrated personal data from the companies’ order systems, compromising customer names, addresses, email addresses, birth dates, telephone numbers, and bank account numbers. The breach exposed customers to heightened risks of email and telephone fraud, identity theft, and phishing attempts due to the sensitivity of the combined stolen datasets. Notably, the attackers did not access passwords, credit card information, or customer identification numbers, eliminating the need for password resets. DELTA Fiber acknowledged the theft occurred despite active cybersecurity measures, though the specific intrusion method or attacker identity remained undisclosed. The companies temporarily disabled their mobile service order pages to prevent further exploitation of the compromised systems.

DELTA Fiber initiated a coordinated response, personally notifying affected customers to raise awareness of potential fraud vectors. The Dutch Data Protection Authority (Autoriteit Persoonsgegevens) received mandatory breach notifications in compliance with regulatory obligations. Cybersecurity firm Tesorion was engaged to assist with incident analysis and remediation, while law enforcement agencies including police and judicial authorities collaborated in the investigation. The company publicly expressed regret over the incident and directed customers to dedicated informational pages (delta.nl/datadiefstal and caiway.nl/datadiefstal) for updates. Operational containment measures focused on securing the order environment, though no restoration timeline for the disabled platforms was provided. The response prioritized mitigating misuse of stolen data through customer alerts while maintaining transparency about the breach’s confirmed scope and limitations.
