StarHub says its customers' personal data, including email addresses and mobile phone numbers, has been found on a dump site. However, the Singaporean telecoms company insists that none of its customer databases or data systems have been compromised.

See also: Angry Conti ransomware collaborator leaks information
The data breach was discovered during a “preemptive online monitoring” on July 6 by its cybersecurity team, StarHub said in a statement late Friday disclosing the breach.
On its website informing customers of the incident, the telco said it needed “time” to investigate the incident and assess the impact before confirming the breach was made public. However, the relevant authorities were immediately informed of the breach.
In a statement to local media, StarHub said an illegally uploaded file containing the leaked data was found on a third-party data dump website. It added that the information appeared to date back to 2007.
See also: CISA: Collaboration with Microsoft, Google, Amazon to combat ransomware
The file contained mobile phone numbers, email addresses and ID numbers for 57,191 customers who had signed up with StarHub before 2007, it said. In addition to broadband and mobile devices, the telco also offers pay-TV services in Singapore. All of the affected customers were from its consumer businesses, according to its website.
When asked, a StarHub spokesperson did not say which of its customers were affected or whether they were still customers. It also declined to disclose how often it conducted its online surveillance, citing security reasons, saying only that the telco conducts such activities “regularly.”.
He did not provide details when asked whether the company has determined the cause of the breach, saying only that there is currently no evidence of a breach in its existing systems.
See also: Energy group ERG hit by ransomware attack
According to StarHub, no credit card or bank account details were compromised and there is currently "no indication" that the leaked data was "maliciously used.".
It also noted that none of the company’s “information systems or customer database” were compromised. On its website, it said its investigation into the breach “verifies the integrity of our network infrastructure.”.
The telco said an incident management team assessed the breach and digital forensics and cybersecurity consultants investigated the incident.
The telco said it has begun “gradually notifying” affected customers via email. StarHub said it expects it will take two weeks to notify all affected customers. It also “attempted” to remove the data file from the dump site, but did not say whether it was successful.
StarHub CEO Nikhil Eapen said: “Data security and customer privacy are serious matters for StarHub and I apologize for any concern this incident may cause to our affected customers. We will keep our customers updated with any further updates.”
Information source: zdnet.com
