AJC’s SWIFT CSP 2025 Season: A...
As another SWIFT Customer Security Programme (CSP) season draws to a close, AJC reflects on a dynamic and successful year...
Read MoreIn late 2025, Klarna confirmed a technical fault that exposed limited customer data through its login system. The issue stemmed from mobile numbers being recycled by network providers:
Early internal estimates suggested the issue could have affected a large number of logins, but Klarna later clarified that the true scale was significantly smaller. The flaw has now been corrected, and additional safeguards have been introduced to prevent recurrence.
The incident was caused by a verification gap linked to recycled mobile numbers. Klarna’s login logic did not validate whether a number still belonged to the same customer, allowing a newly assigned user to initiate access. Klarna has since strengthened its verification checks to ensure ownership is double-confirmed before authorising account access.
For Customers
For Klarna
Klarna’s response was prompt: the flawed login logic was corrected as soon as the issue was identified, additional verification steps such as one-time passwords (OTPs) sent via email were introduced, and the company committed to notifying anyone who may have been affected. The firm has reiterated that the incident was limited, rare, and not part of a wider security breach.
Although Klarna has resolved the issue, customers can protect themselves with a few simple steps:
These steps will help reduce the risk of unauthorised access and strengthen your account security.
The Klarna incident illustrates a broader issue that affects many digital services: mobile numbers are often used for identity verification, yet they can change hands, sometimes without users realising. This incident shows the risks of relying solely on phone-number verification. Services that depend heavily on such methods may remain vulnerable unless they adopt more robust, layered security approaches such as device recognition, email-based verification and additional authentication factors.
Although the Klarna cyber incident affected only a small number of customers, it serves as a reminder of the vulnerabilities that exist within modern digital systems. Klarna has acted quickly to secure its platform, but the event underscores the need for continuous improvement in identity verification and data protection. For customers, it’s a valuable prompt to keep accounts secure, especially when changing mobile numbers or relying on phone-based login methods.
At AJC, we understand how critical robust identity verification and digital security are, especially for organisations handling sensitive data or offering services requiring login authentication. If you want to review or strengthen your system architecture, user verification flows or security protocols, we’re here to help. Our experts can advise on best practices for:
If you have any concerns about incidents like this or need support reviewing your organisation’s security posture, get in touch.
Contact us on 020 7101 4861 or email us at info@ajollyconsulting.co.uk if you think we can help.
Sources:
Image accreditation: Microsoft Edge (October 2022). Last accessed on 11th December 2025. Available at: https://unsplash.com/photos/a-woman-using-a-laptop-1N49Cn7P0Fg
As another SWIFT Customer Security Programme (CSP) season draws to a close, AJC reflects on a dynamic and successful year...
Read MoreJanuary 2026 has shaped up to be a month that reinforces the importance of taking time to ensure personal and...
Read MoreOperational resilience has become a central theme in UK risk and regulatory conversations. Boards, regulators and risk teams speak of...
Read More