SFR and France Titres: More than 2.1 million customer records stolen in SFR hack

SFR and France Titres: More than 2.1 million customer records stolen in SFR hack

SFR Confirms Data Breach Affecting 2.1 Million Fibre Customers in France

French telecom operator SFR has disclosed a data breach exposing personal information of an estimated 2.1 million fibre customers. The incident was detected on July 2 by SFR’s security teams, who traced the unauthorized access to an internal tool used for managing and analyzing fibre connections.

Upon discovery, SFR took immediate action, disabling the compromised account, blocking associated IP addresses, and launching a security investigation. The company has reported the breach to France’s data protection authority (CNIL) and filed a complaint with the public prosecutor.

Exposed Data & Risks
The compromised records may include customers’ titles, full names, addresses, mobile numbers, contract IDs, and technical fibre line details. While passwords and banking information were not affected, the exposed data could be exploited by scammers for phishing, impersonation, or social engineering attacks. SFR has begun notifying impacted customers but warned that fraudsters may use the stolen details to craft convincing fake communications posing as SFR technicians, requesting payments, or scheduling bogus home visits.

Broader Context: France’s Rising Cybersecurity Threats
The SFR breach follows a string of high-profile incidents in France, including three recent breaches at the tax authority (DGFiP), affecting over 1.1 million individuals and businesses. Other public entities, such as France Titres and Urssaf, have also suffered major cyberattacks in recent months, underscoring a growing trend of targeted breaches in the country.

Source: https://www.connexionfrance.com/news/more-than-21-million-customer-records-stolen-in-sfr-hack-are-you-at-risk/809132

Atout France - The France Tourism Development Agency cybersecurity rating report: https://www.rankiteo.com/company/atout-france

SFR cybersecurity rating report: https://www.rankiteo.com/company/sfr

"id": "ATOSFR1787560233",
"linkid": "atout-france, sfr",
"type": "Breach",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '2.1 million',
                        'industry': 'Telecommunications',
                        'location': 'France',
                        'name': 'SFR',
                        'type': 'Telecom Operator'}],
 'attack_vector': 'Unauthorized access to internal tool',
 'customer_advisories': 'Warned customers about potential phishing and social '
                        'engineering attacks',
 'data_breach': {'number_of_records_exposed': '2.1 million',
                 'personally_identifiable_information': 'Titles, full names, '
                                                        'addresses, mobile '
                                                        'numbers, contract '
                                                        'IDs, technical fibre '
                                                        'line details',
                 'sensitivity_of_data': 'High (PII)',
                 'type_of_data_compromised': 'Personal Information'},
 'date_detected': '2024-07-02',
 'description': 'French telecom operator SFR has disclosed a data breach '
                'exposing personal information of an estimated 2.1 million '
                'fibre customers. The incident was detected on July 2 by SFR’s '
                'security teams, who traced the unauthorized access to an '
                'internal tool used for managing and analyzing fibre '
                'connections. The compromised records may include customers’ '
                'titles, full names, addresses, mobile numbers, contract IDs, '
                'and technical fibre line details. While passwords and banking '
                'information were not affected, the exposed data could be '
                'exploited by scammers for phishing, impersonation, or social '
                'engineering attacks.',
 'impact': {'brand_reputation_impact': 'Potential reputational damage due to '
                                       'phishing and social engineering risks',
            'data_compromised': 'Titles, full names, addresses, mobile '
                                'numbers, contract IDs, technical fibre line '
                                'details',
            'identity_theft_risk': 'High (phishing, impersonation, social '
                                   'engineering)',
            'payment_information_risk': 'None (banking information not '
                                        'affected)',
            'systems_affected': 'Internal tool for managing and analyzing '
                                'fibre connections'},
 'investigation_status': 'Ongoing',
 'references': [{'source': 'SFR Disclosure'}],
 'regulatory_compliance': {'legal_actions': 'Reported to CNIL, filed complaint '
                                            'with public prosecutor',
                           'regulations_violated': 'GDPR (likely)',
                           'regulatory_notifications': 'Reported to CNIL'},
 'response': {'communication_strategy': 'Notified impacted customers, warned '
                                        'about potential scams',
              'containment_measures': 'Disabled compromised account, blocked '
                                      'associated IP addresses',
              'incident_response_plan_activated': 'Yes',
              'law_enforcement_notified': 'Yes (public prosecutor)'},
 'title': 'SFR Data Breach Affecting 2.1 Million Fibre Customers in France',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.