INDOTEL investigates Claro data exposure affecting mobile customers

A major cybersecurity incident has emerged in the Dominican Republic, with leading mobile service provider Claro Dominicana confirming that personal information of an undisclosed number of individual mobile customers has been exposed without authorization. The country’s top telecommunications regulator, the Dominican Telecommunications Institute (INDOTEL), has launched active monitoring of the case and is coordinating closely with the National Cybersecurity Center (CNCS) and other relevant enforcement bodies to unpack the full details of the breach.

Per the initial disclosure from Claro Dominicana, the compromised dataset includes customers’ mobile phone numbers, national identity card numbers, and the specific type of mobile service each affected user has contracted with the company. INDOTEL has noted that this description of exposed information comes directly from the provider, and all details are currently undergoing independent verification as part of the official ongoing inquiry.

In its official statement on the incident, Claro Dominicana shared that the company’s in-house cybersecurity specialist team detected the unauthorized access and immediately activated pre-established incident response protocols. The team launched a full verification process to map the full scale of the exposure and cross-check which specific user records were impacted. Critically, the provider emphasized that the exposed data cannot be used on its own to gain access to customer accounts, carry out fraudulent financial transactions, or access the private content of users’ personal communications.

To date, Claro Dominicana has not released any public information about the total number of affected customers, nor has it shared details about how the exposure occurred or the source of the unauthorized access. The company has committed to continuing upgrades to its data security infrastructure and protocols, and has advised customers to follow published guidance for protecting personal digital information.

For its part, INDOTEL’s monitoring mandate covers more than just the breach itself: regulators are also reviewing the accuracy of Claro’s exposure scope disclosures, evaluating the containment measures the provider has implemented to stop further unauthorized access, and checking that Claro is delivering clear, timely guidance and information to affected users. The regulator has also stressed that preserving all digital evidence from the incident is a top priority, to ensure investigating authorities have full, timely access to all materials needed to identify responsible parties.

Given that exposed personal identification data is frequently exploited by bad actors for phishing scams, fraud schemes, and identity theft attempts, INDOTEL has issued a public warning for all customers to remain vigilant against unsolicited suspicious communications, including phone calls, text messages, and emails. Regulators have advised users against sharing sensitive personal data such as account passwords, two-factor authentication verification codes, and banking details, even when the contacting party appears to have accurate knowledge of the user’s personal information. All requests for personal information should be verified through Claro Dominicana’s official customer service channels, and any suspicious activity should be reported immediately to the provider or local law enforcement and cybersecurity authorities.

INDOTEL has also urged the public to avoid downloading, sharing, or distributing any files that claim to contain the exposed customer data, while the investigation into the breach remains active. Unsubstantiated claims about the scale and scope of the incident have begun circulating online, and neither Claro Dominicana nor investigating authorities have independently verified these additional claims. At this stage, the investigation remains focused on confirming the exact number of affected users and verifying which specific personal records were actually compromised.