Freedom Mobile Reports Customer Data Breach Following Unauthorized Access
Freedom Mobile has disclosed a data breach involving unauthorized access to customer personal information, marking the second incident affecting the carrier in recent months.
According to a notice published on March 18, 2026, the unauthorized activity occurred between January 12 and January 18, 2026, within the company’s customer account management platform.
Freedom confirmed that impacted customers were notified via email or text message.
How the Breach Occurred
Freedom stated that a third party gained access by using the credentials of a subcontractor.
“Our investigation determined that a third party used the credentials of a subcontractor to gain access to the personal information of some of our customers.”
The company has since disabled the compromised account and implemented additional measures to address the security gap. Freedom also indicated it is actively monitoring affected accounts for suspicious activity.
The total number of impacted customers has not been disclosed.
What Information Was Accessed?
Freedom confirmed that the following personal information may have been exposed:
- First and last names
- Home addresses
- Email addresses
- Dates of birth
- Phone numbers (home and/or mobile)
- Freedom Mobile account numbers
The company stated that passwords and payment information were not accessed.
At this time, Freedom says it has no evidence that the exposed data has been misused.
Customer Guidance
Freedom is advising customers to:
- Be cautious of unsolicited emails or text messages
- Avoid clicking suspicious links or downloading unexpected attachments
- Monitor accounts for unusual activity
Even without payment data exposure, datasets containing names, contact details, and dates of birth can be leveraged in phishing, SIM swap attempts, and identity fraud campaigns.
A Pattern of Recurring Incidents
This is not Freedom’s first data security event.
- October 2025: Unauthorized access to the same customer management platform
- December 2025: Public notice regarding the earlier breach
- 2019: A security flaw exposed data belonging to approximately 15,000 customers
The recurrence of incidents involving the same platform may raise broader questions about third-party access controls, vendor oversight, and identity security within telecom environments.
Why This Matters
Telecommunications providers maintain high-value datasets that can enable:
- Targeted phishing
- SIM swap fraud
- Account takeover attempts
- Identity-based social engineering
Credential misuse — particularly involving subcontractor or vendor access — remains one of the most common initial access vectors in modern breaches.
Organizations that rely on third-party service providers should regularly review:
- Privileged access controls
- Vendor credential management
- Multi-factor authentication enforcement
- Monitoring and logging of account activity



