TL;DR: A hacker dumped 61GB of data stolen from Russell Cellular (the largest Verizon authorized retailer in the U.S. with 750+ stores) onto a hacker forum on March 17, 2026. The database contains 6.3 million customer and employee records: names, phone numbers, account numbers, device IMEIs, contract details, and employee credentials (some in plaintext). Asking price: $1,200. The biggest risk? SIM-swap attacks. If you've ever bought a phone through a Verizon authorized retailer, your account number and device IMEI could be in that dump. Set up a Port-Out PIN with Verizon right now.
$1,200 for 6.3 Million People's Data
On March 17, 2026, a threat actor operating under the handle "Sorb" posted 61 gigabytes of data to a hacker forum. The listing: 209 database tables from Russell Cellular, containing 6.3 million records. The price: $1,200 [1].
That's $0.00019 per person. Your name, phone number, account number, and device IMEI (the unique identifier for your phone) for less than the cost of a penny split a hundred ways.
Russell Cellular isn't a household name, but it's the largest Verizon authorized retailer in the country. More than 750 locations across the U.S. Over 2,000 employees. If you've walked into a Verizon store that wasn't a corporate-owned location, there's a decent chance it was a Russell Cellular store [2].
Cybernews researchers verified the data. Their assessment: the leaked information "appears to be structured and legitimate in appearance" [1].
What's in the Dump
The 209 database tables include [1][2][3]:
- Customer PII: full names, phone numbers, email addresses
- Account details: account numbers, contract terms, tariff plans, invoice and tracking numbers
- Device identifiers: IMEI numbers, serial numbers, ESN codes, specific device models
- Employee credentials: usernames, passwords (some in plaintext), access roles
Read that last bullet again. Employee passwords. In plaintext. In 2026.
Security analysts flagged this as a "Tier 1" strategic threat. It's not just about spam emails. The combination of real account numbers and device IMEIs gives attackers the exact information they need for SIM-swap attacks: taking over your phone number by convincing a carrier to transfer it to a new SIM card [3].
The SIM-Swap Problem
Here's why this breach is worse than a typical name-and-email dump.
A SIM-swap attack works like this: an attacker calls your carrier, pretends to be you, and convinces them to transfer your phone number to a new SIM. Once they control your number, they intercept every text message and phone call, including the two-factor authentication codes for your bank, crypto exchange, email, and anything else that sends codes via SMS.
The usual obstacle? Attackers need your account number and device details to pass identity verification. Russell Cellular just handed that out to anyone with $1,200.
The FBI's Internet Crime Complaint Center reported over $68 million in SIM-swap losses in 2023 alone. With 6.3 million records' worth of account numbers and IMEIs floating around hacker forums, that number is about to look quaint.
Verizon's Non-Answer and Russell Cellular's Silence
Verizon's official statement: "Our teams are actively investigating the matter and working with the retailer to understand the extent of the issue and its impact" [4].
That was in March. It's late April now. No follow-up.
Russell Cellular has been even less forthcoming. According to the original forum post, the seller claimed Russell Cellular was "unresponsive" when contacted about the vulnerability before the data went up for sale [3]. A Reddit user who claimed to be a Russell Cellular employee reported that as of late March, employees had not been asked to reset their compromised credentials [4].
Let that land. Employee passwords, some in plaintext, are sitting on a hacker forum, and the company reportedly didn't even tell its own staff to change them.
Law firm Schubert Jonckheer & Kolbe, which announced an investigation on April 9, noted that Russell Cellular "has not yet begun notifying impacted individuals, which may have violated state and federal laws" [5]. Migliaccio & Rathod LLP opened a separate investigation on April 13 [6].
Verizon eventually sent breach notification letters to affected customers on April 10, acknowledging that "an unauthorized actor had accessed or acquired certain customer information" from its authorized retailer [2].
What to Do Right Now
Set Up a Port-Out PIN
Call Verizon (dial *611 from your Verizon phone) or log into My Verizon and set a Port-Out PIN. This prevents your number from being transferred to another carrier or SIM without the PIN. It's free and takes two minutes. Do it now.
Stop Using SMS for Two-Factor
Switch every account that matters (bank, email, crypto) from SMS-based 2FA to an authenticator app (Authy, Google Authenticator) or a hardware key (YubiKey). SMS codes are worthless if your number gets hijacked.
Freeze Your Credit
Free at all three bureaus: Equifax, Experian, TransUnion. Takes five minutes per bureau. Blocks anyone from opening new accounts in your name.
Watch for Targeted Phishing
Attackers now have your real phone model, account number, and contract details. Expect convincing "Verizon account update" texts and emails. Don't click links. Go directly to verizon.com or call *611.
The Authorized Retailer Blind Spot
This breach exposes a structural problem in how wireless carriers handle customer data. Verizon didn't get breached. Russell Cellular did. But the data is identical: your Verizon account number, your device IMEI, your personal information. It all flows through the same systems.
Authorized retailers are the front door for most carrier interactions. They activate phones, process upgrades, handle account changes. They need access to the same customer databases that corporate stores use. But their security practices? That's between them and their IT team.
Verizon has over 6,000 authorized retail locations run by third parties. T-Mobile and AT&T have similar networks. Each one is a potential weak link with access to millions of customer records. And when one gets breached, the carrier's response is "we're investigating." The customer is left holding the bag.
Russell Cellular stored employee passwords in plaintext. That's not a sophisticated attack surface. That's Security 101 failure. The kind of thing that suggests nobody was auditing these retailers' data protection practices with any seriousness.
Your Phone Company's Weakest Link
6.3 million records. $1,200 asking price. Employee passwords in plaintext. No notification for weeks. A company-wide credential reset that apparently never happened.
If you've ever done business at a Verizon authorized retailer (and most Verizon stores are authorized retailers), assume your data is out there. Set up a Port-Out PIN. Switch off SMS-based 2FA. Freeze your credit.
The breach happened on March 17. It's been over five weeks. The data has been available for purchase that entire time. Whatever protection you're going to set up, set it up today.
References
- Security Magazine: Verizon Retail Customer Database Allegedly for Sale by Hackers: 6.3M Customers at Risk (March 2026)
- PR Newswire: Russell Cellular Under Investigation for Data Breach of Over 6 Million Records (April 2026)
- BrinzTech: 6.3 Million Customer Records of Russell Cellular on Sale (March 2026)
- PhoneArena: Millions of Verizon customers have a new worry hanging over their heads (March 2026)
- Schubert Jonckheer & Kolbe: Russell Cellular Under Investigation for Data Breach (April 2026)
- Migliaccio & Rathod LLP: Russell Cellular Data Breach Investigation (April 2026)
Published: April 23, 2026