According to reports from UK media, Three Mobile was breached by hackers who, according to the National Crime Agency (NCA), gained access to a database containing account details from six million customers.
The posts do not mention that payment information, such as card numbers, was stolen, but the hackers gained access to customer names, addresses, phone numbers, and dates of birth.
It is believed that the hackers used the database to discover customers who were eligible for subsidized device upgrades. They then changed the details on the orders for the new phones to go to their own addresses, earning a lot of money from reselling them.
Three Mobile has seen an increase in phone thefts from upgrades in recent times, with at least eight cases of phones being stolen while in transit. They have also seen an increase in thefts taking place in retail stores.
The National Crime Agency (NCA) has arrested two men, one from Orpington, Kent, and one from Ashton-under-Lyne, Manchester, on charges relating to computer fraud involving Three Mobile. It has also arrested a third man for obstructing investigations.
These types of scams are not unknown. In 2014, employees at a company that worked with AT&T were found to have stolen account information to unlock and resell stolen phones.
Earlier this year, another UK mobile phone provider, TalkTalk, lost over £60 million as a result of a 2015 breach that exposed account details from 156,000 customers.
