2026 Bloctel — DGCCRF confirms professional-account theft of 3M phone numbers (600k Bloctel registrants)
Data compromised
3 million telephone numbers, including 600,000 Bloctel registrants. DGCCRF: no names, addresses, or other personal data disclosed. Affected Bloctel subscribers emailed.
Technical writeup
Regulator-confirmed incident — DGCCRF communiqué n°949, Paris, 12 August 2026. Fraudulent access to a professional account let a cybercriminal retrieve files containing 3 million phone numbers, of which 600,000 were Bloctel registrants. Investigations found only telephone numbers exposed — no names or addresses. The compromised professional account was blocked; other professional accounts were checked. DGCCRF states the Bloctel database itself was not compromised. CNIL notified. Bloctel emailed affected registrants. The incident occurred as Bloctel ended on 11 August 2026 under the 30 June 2025 law replacing the opposition list with an opt-in consent regime for commercial calls. recordsAffected 3000000 reflects the recovered file size (600k Bloctel subset in prose).
Root cause
Fraudulent access to a professional Bloctel account used to retrieve files of telephone numbers; Bloctel core database itself not compromised per DGCCRF