← SFR

2026 SFR — fibre connection-tool breach (detected Jul 2); company confirms PII; ~2.1M rows claimed

2026 2.1M records affected Share on X

Data compromised

Per SFR customer notice (AFP / The Local / Cyberattaque.org): civility, name, postal address, mobile phone, contract ID, and fibre-line technical data; passwords and banking data not concerned. Actor/reporter figure of 2,104,093 rows (Fibre/RED) remains unconfirmed by SFR’s headcount silence

Technical writeup

Verified company confirmation — August 20, 2026 (AFP customer letters; Cyberattaque.org; The Local; Sud Ouest). French telecom SFR (Altice) told affected fibre subscribers that security teams detected a July 2, 2026 incident targeting a tool used to manage and analyse fibre connections; access was cut, the account used was deactivated, source IPs blocked, and CNIL notified. Officially acknowledged fields include name/civility, postal address, mobile phone, contract identifier, and fibre-line technical data; passwords and banking details were not concerned. SFR has not published a customer census. This confirmation aligns with the July 17 forum claim already indexed here (NOVA portal / 2,104,093 rows) without SFR explicitly confirming the NOVA name or the 2.1 million figure in the notice. recordsAffected remains 2104093 as the best public actor/reporter count, clearly labeled as not company-attested.

Root cause

Company-confirmed unauthorized access to a fibre connection management/analysis tool detected July 2, 2026 (customer letters / AFP); earlier forum claim named NOVA and ~2.1M rows

References