Attacker was able to take over every Lebara phone number due to an error on the website
Phone numbers of Lebara customers could easily be copied via the site. On the site, the process to transfer a telephone number to another SIM card did not work properly, a tipster tells the NOS.
Due to the security problem, it was possible to transfer any phone number to another SIM card. Lebara offers this option on the website. For this, a user would have to receive a verification SMS on both the old and the new SIM card, but that was not necessary, a tipster discovered who took it to the NOS.
It was possible to request two verification codes on just the new SIM card, eliminating the need for interaction with the other SIM card. This made it possible to transfer the telephone number of any Lebara number to a new SIM card.
The NOS has passed the problem on to Lebara. The virtual provider then resolved the issue. The module on the site to switch has been temporarily offline. The provider says there is “no reason to believe that the leak has been exploited”.