Build1 publisher3 min readPublished
An ICCID column is what makes the unverified Claro list worth acting on
A forum post on 13 September claimed 2,889,256 Claro Dominicana customer records, each carrying the serial number of the line's SIM. Nobody has verified it, and the SIM serial is the field that should drive the response.
The Engineer · Build desk

What happened
- A forum post on 13 September claimed someone had pulled a database of 2,889,256 Claro customer records in the Dominican Republic, and the figure spread within hours after amplification on X.
- The claim has not been independently verified, and the samples in circulation do not on their own show where the data came from, how recent it is, or whether it is complete.
- No Dominican authority had announced an investigation or a notification at the time the dev.to post was written.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- decision The post puts a choice to readers: twenty minutes spent moving two-step codes off SMS if the claim is false, against waiting through the window when the data is worth most if it is true.
- exposure Anyone whose bank, email and social account recovery runs over SMS is reachable by whoever can talk a service point into moving the number to a new SIM.
- constraint Dominican customer systems that authenticate callers or reset accounts on the strength of a document number lose that as a check, whatever the forum post turns out to be.
The claimed record has nine fields, according to the dev.to writeup describing the listing [2]. Eight of them describe an account: the identity document number, the phone number, subscription details, account status, plan category, activation date, billing cycle and internal codes [2][1]. The ninth is the ICCID, the unique identifier of a single SIM card [3]. "El ICCID no es un dato de mercadeo: identifica una SIM en concreto," the post wrote [4]. In English: it is not marketing data, it points at one specific card.
The post's argument is that the ICCID is the field that lets an attacker act on the record [5]. The two attacks it describes are ordinary ones. First, the call that already knows things about you. With the document number, phone, plan and billing cycle, a caller can state your name, your cedula, your plan and your billing date, and the post notes that every security question a bank asks over the phone sits in that list [8]. Second, the SIM change: persuade a service point that you are the customer, move the number to another SIM, inherit the messages [6]. SMS is still the second factor for banks, email and social accounts in the country, so whoever holds the number can request the recovery code for everything else [7].
What is established is thin. The post says the claim has not been independently verified, and that the circulating samples cannot by themselves establish the origin of the data, its recency, its completeness, or that it came from the company's systems [9]. Confirmation also tends to arrive late: verification comes first, then the decision about what to communicate, and the post puts that at days or weeks [16]. Whatever was circulating has circulated by then. Claro Dominicana has not publicly confirmed any incident [10].
The defenses the post ranks first work whether or not any of that resolves. Move the second factor off SMS to an authenticator app where you can; the post calls this the change with the most effect per minute invested, and the only one that still protects you if your number stops being yours [12]. Ask your carrier what it takes to move your number to a new SIM. If the answer is a phone call, the post says that is the problem, and to ask for in-person presence or an extra passphrase where the operator offers one [13]. Set the SIM PIN in the phone's security menu; it takes a minute and blocks the simple case of a stolen handset with the card pulled out [14]. Do not read a code out loud, because no bank, carrier or app asks by phone for the code that just arrived [15].
For anyone running systems for Dominican customers, two assumptions change. The first is the SMS one-time code, which the post calls a borrowed factor [18]. The second is the document number. Knowing someone's cedula was never good proof of identity, and the post's line is that it now proves nothing [19]. The cedula and the phone number are not secrets, and the post says a system that verifies identity by asking for the document number checks nothing; account recovery that leans on it is public [17].
What to watch
- A statement from Claro Dominicana, or a notification from a Dominican authority, would move this from allegation to incident.
- Anyone matching sample ICCIDs against live lines would settle the origin question the post says the samples cannot answer alone.
- Carriers requiring in-person presence or an extra passphrase for SIM changes would close the path the post describes.