CTIPilot

Salt Mobile SA peripheral-system access-misuse data incident (September 2026)

incident · incident:salt-mobile-peripheral-system-data-incident-2026-09 single-source-victim

Swiss mobile network operator Salt Mobile SA confirmed on 2026-09-11 that it identified misuse of an existing access credential to an unnamed 'peripheral system,' potentially exposing customers' names, addresses, phone numbers, dates of birth and email addresses; a dark-web monitoring service separately claims roughly 1.09 million records are for sale, a figure Salt neither confirms nor denies (Salt Mobile SA; Blick, 2026-09-11/12).

Coverage timeline
1
first 2026-09-15 → last 2026-09-15
Peak priority
notable
1 notable
Sources cited
4
4 hosts
Sections touched
1
active-threats
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
1
pinned v19.2 · see below

Hunting pivots

ATT&CK techniques

ATT&CK techniques

1 technique observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-09-15/salt-mobile-peripheral-system-data-incident · ATT&CK page ↗

Persistence TA0003

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-09-15/salt-mobile-peripheral-system-data-incident · ATT&CK page ↗

Privilege Escalation TA0004

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-09-15/salt-mobile-peripheral-system-data-incident · ATT&CK page ↗

Stealth TA0005

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-09-15/salt-mobile-peripheral-system-data-incident · ATT&CK page ↗

Story timeline

  1. 2026-09-15Salt confirms misuse of an existing access credential to an unnamed 'peripheral system', up to 1.09 million Swiss mobile customers' records reportedly at risk
    active-threatsSwitzerland's third-largest mobile operator rules out a hack but says customer data may be exposed through a vague 'peripheral system'

Where this entity is cited

  • active-threats1

Source distribution

  • 20min.ch1 (25%)
  • blick.ch1 (25%)
  • salt.ch1 (25%)
  • watson.ch1 (25%)

explore in graph

Entries about Salt Mobile SA peripheral-system access-misuse data incident (September 2026) (1)

2026-09-15 · view entry permalink →

NOTABLENATOB2

Salt confirms misuse of an existing access credential to an unnamed 'peripheral system', up to 1.09 million Swiss mobile customers' records reportedly at risk

Salt Mobile SA, "the third-largest telecommunications provider in Switzerland" (translated from German) (watson.ch, 2026-09-12), posted a customer notice on 2026-09-11 stating that, after online allegations of a possible customer data leak, its checks "ruled out an intrusion into Salt's systems and identified misuse of an existing access to a peripheral system" (translated from French) (Salt Mobile SA, 2026-09-11). Salt's spokesperson Viola Lebel confirmed to Blick that "unauthorized access to Salt's systems could be ruled out" (translated from German) (Blick, 2026-09-12); 20 Minuten reports that it also "remains unclear what Salt means by the affected 'peripheral system' and whether it is its own system or a connected one" (translated from German), a question Salt referred back to its ongoing investigation (20 Minuten, 2026-09-11). Because that system's reach into Salt's data is described as limited, Salt states passwords, banking details and customer usage history cannot be affected; the personal-data categories that could be exposed are first and last name, postal address, mobile phone number, date of birth and email address (Salt Mobile SA, 2026-09-11).

Salt has notified affected customers and "the relevant authorities" but has not disclosed how many customers are affected, when the access was misused, or whether data was actually copied or published (20 Minuten, 2026-09-11). As early as late August 2026, dark-web monitoring service Brinztech had reported "an illegal sales campaign" (translated from German) offering a dataset of more than 1.09 million customer records "attributed to the Swiss telecommunications provider Salt Mobile" (translated from German); Salt "will neither confirm nor deny" that figure (watson.ch, 2026-09-12). Customers have separately reported, on social media, an increase in unsolicited fraud calls in the days around the disclosure (watson.ch, 2026-09-12); no source establishes that those calls referenced the callers' specific personal data. No ransomware group or named threat actor has claimed the incident, and no CVE or specific initial-access flaw has been disclosed by any party.

"Peripheral system" is Salt's own vague framing and could denote an internal subsidiary system, an outsourced CRM or marketing platform, or a partner-integration endpoint; no source found in this run resolves that ambiguity, so this entry does not assume a supply-chain vector beyond what Salt itself has stated: misuse of an existing, legitimate access grant.

This ruled out an intrusion into Salt's systems and identified misuse of an existing access to a peripheral system. (translated from French)

Given this peripheral system's limited access to Salt data, sensitive data (such as passwords, banking details or customer history) cannot in any case be affected. (translated from French)

Salt Mobile SA (victim's own customer notice) 2026-09-11

Unauthorized access to Salt's systems could be ruled out, confirms spokesperson Viola Lebel to Blick. (translated from German)

Blick, quoting Salt spokesperson Viola Lebel

It also remains unclear what Salt means by the affected 'peripheral system' and whether it is its own system or a connected one. (translated from German)

20 Minuten 2026-09-11

As early as late August, the portal Brinztech reported on dark-web actors who had 'launched an illegal sales campaign' offering a huge dataset of more than 1.09 million customer records 'attributed to the Swiss telecommunications provider Salt Mobile.' (translated from German)

the third-largest telecommunications provider in Switzerland (translated from German)

watson.ch 2026-09-12
incident15 Sep 04:45Zsingle-source · victim disclosureOpen finding ↗