2026-09-15 · view entry permalink →
Salt confirms misuse of an existing access credential to an unnamed 'peripheral system', up to 1.09 million Swiss mobile customers' records reportedly at risk
Salt Mobile SA, "the third-largest telecommunications provider in Switzerland" (translated from German) (watson.ch, 2026-09-12), posted a customer notice on 2026-09-11 stating that, after online allegations of a possible customer data leak, its checks "ruled out an intrusion into Salt's systems and identified misuse of an existing access to a peripheral system" (translated from French) (Salt Mobile SA, 2026-09-11). Salt's spokesperson Viola Lebel confirmed to Blick that "unauthorized access to Salt's systems could be ruled out" (translated from German) (Blick, 2026-09-12); 20 Minuten reports that it also "remains unclear what Salt means by the affected 'peripheral system' and whether it is its own system or a connected one" (translated from German), a question Salt referred back to its ongoing investigation (20 Minuten, 2026-09-11). Because that system's reach into Salt's data is described as limited, Salt states passwords, banking details and customer usage history cannot be affected; the personal-data categories that could be exposed are first and last name, postal address, mobile phone number, date of birth and email address (Salt Mobile SA, 2026-09-11).
Salt has notified affected customers and "the relevant authorities" but has not disclosed how many customers are affected, when the access was misused, or whether data was actually copied or published (20 Minuten, 2026-09-11). As early as late August 2026, dark-web monitoring service Brinztech had reported "an illegal sales campaign" (translated from German) offering a dataset of more than 1.09 million customer records "attributed to the Swiss telecommunications provider Salt Mobile" (translated from German); Salt "will neither confirm nor deny" that figure (watson.ch, 2026-09-12). Customers have separately reported, on social media, an increase in unsolicited fraud calls in the days around the disclosure (watson.ch, 2026-09-12); no source establishes that those calls referenced the callers' specific personal data. No ransomware group or named threat actor has claimed the incident, and no CVE or specific initial-access flaw has been disclosed by any party.
"Peripheral system" is Salt's own vague framing and could denote an internal subsidiary system, an outsourced CRM or marketing platform, or a partner-integration endpoint; no source found in this run resolves that ambiguity, so this entry does not assume a supply-chain vector beyond what Salt itself has stated: misuse of an existing, legitimate access grant.
This ruled out an intrusion into Salt's systems and identified misuse of an existing access to a peripheral system. (translated from French)
Given this peripheral system's limited access to Salt data, sensitive data (such as passwords, banking details or customer history) cannot in any case be affected. (translated from French)
Unauthorized access to Salt's systems could be ruled out, confirms spokesperson Viola Lebel to Blick. (translated from German)
It also remains unclear what Salt means by the affected 'peripheral system' and whether it is its own system or a connected one. (translated from German)
As early as late August, the portal Brinztech reported on dark-web actors who had 'launched an illegal sales campaign' offering a huge dataset of more than 1.09 million customer records 'attributed to the Swiss telecommunications provider Salt Mobile.' (translated from German)
the third-largest telecommunications provider in Switzerland (translated from German)