MTN Irancell
| Primary URL | Location | Industry | mtnirancell[.]ir |
Country
Iran
|
Telecommunications
|
|---|
Profile
MTN Irancell operates as a major mobile telecommunications provider within Iran, delivering core services including voice communication, mobile data, and digital solutions to its subscriber base. The company functions as a significant entity in Iran's competitive telecom sector, serving a substantial portion of the domestic market with its network infrastructure and customer offerings. Its operational scale is evidenced by the approximate 20 million subscribers whose personal data was implicated in a major security incident, indicating a vast footprint and the handling of extensive sensitive information across the population. The nature of its services inherently involves the collection and management of highly personal customer details such as national identification numbers, contact information, and residential addresses, positioning it as a critical custodian of private data within the national digital ecosystem.
A defining and publicly documented event in the organization's history is the large-scale data exposure incident that began on July 1, 2016. During this period, an active Telegram bot provided unauthorized third-party access to the personal records of about 20 million MTN Irancell subscribers for roughly 20 hours. The compromised data included names, phone numbers, addresses, and national ID codes, information that had reportedly originated from a prior breach and was being misused by advertisers. Independent security researchers verified the bot's functionality, demonstrating the immediate and severe risk of identity theft, financial fraud, and targeted scams posed by the public availability of such comprehensive records. This incident underscores the critical data security challenges faced by large-scale telecom operators and the potential for legacy data breaches to resurface and cause widespread harm through new technological vectors. The event remains a notable case study in the mishandling of subscriber information and the vulnerabilities that can persist within customer databases.
