Mobileum, a California technology company serving telecom providers, has filed a data breach report with the Massachusetts Office of Consumer Affairs and Business Regulation dated October 9, 2026. The report says 45 Massachusetts residents were affected and that Social Security numbers were involved.
Mobileum’s Data Breach Investigation
Mobileum Inc. is a technology company headquartered in Cupertino, California. Its own website describes it as a provider of analytics, roaming, network security and risk management software and services for telecommunications operators around the world. A company in that line of work typically deals with other businesses rather than the general public, so the people whose information is involved in this incident may be employees, former employees, contractors, or individuals whose details passed through a business relationship. The public record does not say which of those groups applies here, and this page does not guess.
The incident became public through the data breach reports that Massachusetts publishes. Massachusetts requires organizations to notify the Office of Consumer Affairs and Business Regulation when a breach involves the personal information of its residents, and the state posts the reports it receives. The report for Mobileum is dated October 9, 2026. It lists 45 Massachusetts residents as affected and names Social Security numbers as the information involved.
That is the full extent of what the report provides. We did not find a notice on the company’s own website, a press statement, or a filing from another state regulator that expands on it. For that reason, this page does not state how the incident happened, when it began, how long it lasted, or how many people were affected in total. Those details have not been made public in the sources we reviewed, and we are not going to guess at them.
The figure in the report needs careful reading. It counts only Massachusetts residents. Organizations that notify people in several states typically file a separate report with each state regulator that requires one, and each filing counts only that state’s residents. Mobileum is a company that operates with customers around the world, which is a reason to think its workforce and business contacts are not concentrated in one state, although the report does not confirm that. A count of 45 for Massachusetts therefore says little about the overall total. It could be most of the people involved, or a small share of a much larger notification effort. Without a filing from a state that publishes a total, there is no way to tell which.
Massachusetts reports like this one are short by design. They identify the organization, the date and the number of state residents, and they usually attach a template of the letter the organization sent. They rarely describe the technical cause. That is why a page like this one can responsibly report only what the filing says, and why the details most people want, such as how the data was reached and by whom, may only emerge later through additional notices, regulator filings or court documents.
Technology and telecommunications service companies are a frequent target of cyberattacks. They hold technical access to systems that other businesses depend on, and they keep ordinary human resources and payroll records like any other employer. We are describing the general landscape only. The report does not say whether Mobileum’s own systems or an outside vendor’s systems were involved, and nothing here should be read as a finding about the cause of this incident.
Social Security numbers are among the most sensitive identifiers a person has. Unlike a password or a payment card number, a Social Security number cannot be easily changed, and it stays useful to criminals for years. Combined with a name and date of birth, it can be used to open new credit accounts, file false tax returns, or pass identity checks with banks and employers. The report does not say whether other information was also involved, and we do not assume that it was.
If you received a notice from Mobileum, read it closely and keep a copy. The letter is the best source for what applies to you, including which items of your information were involved and whether the company is offering credit monitoring or identity protection at no cost. If you think you may be affected but have not received anything, you can contact the company directly to ask whether your information was involved.
A data breach class action is one way people affected by a security incident can seek accountability from an organization that did not adequately protect their information. Whether a claim makes sense depends on facts that are still emerging in this matter, which is why speaking with a lawyer about your own situation is a reasonable step if you were notified.
When Did This Breach Occur?
The Massachusetts report is dated October 9, 2026. That is the only date the report provides. The date the incident began, the date it was discovered, and the date notice letters were mailed have not been made public in the sources we reviewed. The date of a report to a regulator is not the same as the date of the breach, and an incident can predate the filing by weeks or months.
What Information Was Breached?
The report identifies Social Security numbers as the information involved. It does not say which groups of people were affected or whether anything else was exposed. Your own notice letter is the best source for what applies to you.
What You Can Do
If you received a notice from Mobileum or believe you may be affected, consider these steps:
- Read the notice carefully and keep it, along with any enrollment details for protection services it offers.
- Place a free fraud alert or a credit freeze with Equifax, Experian and TransUnion, and get your reports free at annualcreditreport.com.
- Watch your financial accounts and tax records for activity you do not recognize, and consider an IRS Identity Protection PIN.
- Be skeptical of unexpected calls, texts or emails that mention the company, and report suspected identity theft to the Federal Trade Commission at identitytheft.gov and to your state Attorney General.
File a Data Breach Lawsuit Against Mobileum
If your personal information may have been exposed in this incident, you may have legal options. Organizations that hold sensitive personal information are expected to safeguard it, and a class action can help hold an organization accountable when it fails to do so.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.