-
A threat actor going by “saotome” has reportedly listed over 850 million China Mobile subscriber records for sale on a cybercrime forum for just $1,950.
-
The alleged database contains names, ID numbers, phone numbers, billing details, and even 5G and roaming settings.
-
No cybersecurity firm or official body has confirmed the breach, and China Mobile has not made any public statement.

A cybercrime forum post is raising serious concerns about the data security of hundreds of millions of mobile users. A threat actor has reportedly listed what they claim is a massive database of China Mobile subscriber records. The post was flagged in September 2026 by Dark Web Informer. The claim has not been verified, and no cybersecurity company or official body has confirmed it.
The seller, using the forum handle “saotome,” is asking for $1,950 in cryptocurrency. That is a strikingly low price for a dataset of this claimed size.
What the Seller Claims the Database Contains
According to the forum post, the dataset holds records tied to China Mobile subscribers. The alleged fields cover a wide range of personal and account information.
On the personal side, the database reportedly includes full names, national ID numbers, gender, dates of birth, and ages. Account details allegedly in the data include mobile phone numbers, IMSI identifiers (unique numbers tied to SIM cards), provincial and regional codes, identity verification status, service plans, monthly fees, and contract information.
The seller also claimed the data includes network details. These reportedly cover network type, 5G status, VoLTE (voice-over-network) support, and roaming settings. On top of that, the post claimed billing records are included. Those allegedly cover data usage, voice minutes, SMS counts, account balances, unpaid charges, and loyalty points. Activation dates, last recharge dates, and last account activity were also reportedly listed.
However, the forum post included only a sample of the data. A sample alone does not prove the records are real. It also does not prove they actually came from China Mobile. The post did not explain how the database was obtained, which raises further doubts.
Why the Scale of this Claim Stands Out
The sheer size of the alleged dataset is what makes this claim hard to ignore. China Mobile reported 1.004 billion mobile customers at the end of 2024. By June 2025, that number had climbed past 1.005 billion. More recent figures from Marbridge Consulting put the total at just over 1.011 billion mobile customers as of June 2026.
An 850-million-record dataset, if real, would cover a large portion of that base. But the size of China Mobile’s subscriber base is not proof that the advertised database is genuine. These are two separate facts.
It is also worth noting that $1,950 is an unusually low asking price. Databases of this size, if authentic, typically command far higher prices on cybercrime markets. The low price tag adds another layer of uncertainty to the claim.
No Confirmation, but Separate Security Concerns Exist
No independent cybersecurity researcher or major news outlet has confirmed the specific 850-million-record claim at this time.
That said, China Mobile has faced separate security-related scrutiny in the past. In June 2025, cybersecurity firm Seqrite reported a malware campaign targeting China Mobile Tietong, a China Mobile subsidiary. Attackers delivered the malware through a file disguised as an internal training program.
Separately, a 2025 report by iVerify examined how Chinese telecommunications infrastructure handles sensitive mobile traffic. Other alleged Chinese data exposures have also surfaced, including a claim involving 280 million China Housing Provident Fund records.
U.S. authorities have also investigated China Mobile and other Chinese telecoms over potential security risks, according to Reuters. CERT-EU has also flagged related concerns around Chinese telecom infrastructure in a 2025 threat intelligence report.
None of these reports, however, establish that China Mobile’s subscriber database was accessed or stolen. They show a pattern of concern around the company’s infrastructure, but they are separate from the current forum claim.
For now, the alleged sale of 850 million China Mobile subscriber records remains an unverified claim. The true origin of the dataset, the identity behind the seller, the authenticity of the sample, and the actual number of affected subscribers are all still unknown. Neither China Mobile nor any cybersecurity firm has publicly commented on the specific forum post.