Porting from Colt

Incident Report for Simwood

Update

27 days since Colt responded to their cyber-security incident which, after eventually admitting they have consistently down-played, they continue to be unable to process number ports. Please continue submitting them as we are queuing this side.
Posted Sep 08, 2025 - 08:22 UTC

Update

Colt continue to not process number ports despite down-playing the cyber-security incident which they initially responded to 21 days ago.
Posted Sep 02, 2025 - 09:25 UTC

Update

Colt are keen to emphasise on their status page (https://www.colt.net/status/) how this didn't affect customer systems. They have also marked their cyber-incident page at https://www.colt.net/go/cyber-incident/ to "noindex" to hide it from search engines, and it isn't linked anywhere on their website. None of them mention number portability either, which they continue to not do, despite us now being in day 16.
Posted Aug 28, 2025 - 12:24 UTC

Update

Colt have contacted us to say that "all port-in and port-out activities are currently on hold until next week, as we’re still working internally to stabilize the situation"
Posted Aug 27, 2025 - 07:54 UTC

Update

Colt are still not processing number ports.

Please continue to submit porting orders normally, we have a queue and are chasing them daily.
Posted Aug 26, 2025 - 10:10 UTC

Update

An excellent blog has been published documenting the events so far at https://doublepulsar.com/colt-technical-services-gets-ransomwared-via-sharepoint-initial-access-some-learning-points-617da7e27ebc

Colt are still not processing number ports.
Posted Aug 24, 2025 - 11:42 UTC

Update

Other than restating their status page to say this was a cybersecurity incident from day one (formerly an "IT issue"), and their compromised documents being mid-auction, there is no update here. Their porting desk appear to have stopped the daily updates and are still not processing orders.
Posted Aug 22, 2025 - 11:58 UTC

Update

There is no update here other than Colt's porting team have advised there will be no imports or exports "until further notice". We continue to queue POV and porting orders for them.
Posted Aug 19, 2025 - 12:51 UTC

Update

Colt are still unable to process number ports, we assume as a consequence of their well publicised cyber-attack. A list of compromised files, which is asserted to be the files compromised by the attacks is at (https://www.klos.com/~john/colt_filename_tree.txt)

This list contains a number of interoperability documents between Simwood and Colt. The list also contains documents that appear to be Number Portability Order Forms, although it is unclear as to whether these relate to Simwood customers. NPORs will contain some information about the Subscriber changing providers, e.g. name, address, and telephone numbers. Additionally, there is other information clearly of a sensitive nature on the list, but that does not, as far as we can tell, relate to Simwood and its customer’s relationships.

At this time, we understand that Colt are working to prevent further disclosure, however, this is all the detail we have at this time. Our customers should engage their Data Protection Officers regarding the consequences of the attack on Colt as a matter of urgency.
Posted Aug 18, 2025 - 14:23 UTC

Update

There is no news to report here although the now admitted attack is being actively reported on, e.g. https://www.bleepingcomputer.com/news/security/colt-telecom-attack-claimed-by-warlock-ransomware-data-up-for-sale/
Posted Aug 15, 2025 - 16:45 UTC

Update

Colt have now confirmed an ongoing cyber-incident (https://www.colt.net/status/). At the moment voice traffic on existing ported numbers seems unaffected.
Posted Aug 14, 2025 - 17:06 UTC

Monitoring

Colt have advised that they are unable to complete any import or export porting orders until further notice. Their Status page (https://www.colt.net/status/) suggests an IT issue while online speculation (https://cyberplace.social/@GossiTheDog/115022343170487477) is of an undisclosed cyber attack. We will advise when we have further news.
Posted Aug 14, 2025 - 13:55 UTC
This incident affects: Operations Desk.