Skip to content

SFR confirms hack exposing customer personal data

Person using a smartphone and laptop showing a warning sign, seated at a wooden table with a router and credit card.

SFR has confirmed a hack detected in July. The incident gave cybercriminals access to customers’ personal data.

If you are an SFR or RED Fibre customer, you could be affected by a hack suffered by the operator. SFR confirmed that it identified a security incident on 2 July. “SFR detected a security incident following an act of cybercrime, the consequences of which may have included the temporary accessibility of data linked to Fibre subscribers’ lines, such as their address, email address or telephone number,” SFR told AFP.

The operator has not disclosed how many customers were affected by the hack. However, those claiming responsibility for the attack reportedly refer to more than 2.1 million items of personal data. The information involved includes title, surname, first name, address, mobile telephone number, contract identifier and technical data relating to the line. The incident did not, however, result in the theft of passwords or banking information.

SFR hack: data potentially exposed

After identifying the attack, SFR says it “immediately” took the necessary action to prevent unauthorised access to its customers’ data. “In particular, we disabled the account used to access the tool, blocked and placed under surveillance the IP addresses behind the unauthorised access. Thorough analyses were carried out to identify the source of the incident, and we strengthened the monitoring measures for our systems and our security intelligence,” the operator said.

Risks for affected SFR and RED Fibre customers

Nevertheless, the possibility that this data is now in the hands of hackers creates a risk for the people affected. The leaked details could, for instance, be used to run highly convincing phishing campaigns, as messages may contain very specific information. SFR has not named the people behind the attack. However, it is reportedly claimed by ZeroBytes, the hacker who has also claimed attacks against the tax authority and the Ministry of Education.

Complaint filed following the security incident

“In accordance with the applicable regulations, this incident has been reported to the French data protection authority, the CNIL, and a complaint has been filed with the public prosecutor,” SFR said.

Comments

No comments yet. Be the first to comment!

Leave a Comment