Egidio
Case file · August 21, 2026

Free, Bouygues, SFR: the same fiber tool breached three times

In under two years, three of France's biggest carriers were compromised through the same type of entry point: the internal tool used to manage fiber interventions. This is no longer one isolated incident — it's a pattern, documented here without assuming a shared perpetrator.

⚠️ This case file isn't centered on one hacker or one company. It documents a pattern: three major French carriers, in under two years, compromised through the same type of entry point — an internal tool for managing fiber-connection interventions. Each incident has its own independently confirmed facts; the resemblance between them is our reading, not a shared official attribution.

Three carriers, the same blind spot

24M
Free — subscriber contracts exposed, IBANs compromised for some customers (October 2024). Combined CNIL fines of €42M in January 2026.
CNIL, January 2026.
4.5M
Bouygues Telecom — French customers potentially affected, claimed via the internal "TECH360" tool (May 2026). Confirmed by the carrier on May 11.
Trade press alerts, May 2026.
2.1M
SFR — lines claimed via the "NOVA" tool (July 2026). The intrusion is confirmed by SFR; this total is not.
AFP wire, 08/20/2026.
2 of 3
Incidents in 2026 alone. The third (Free) dates to 2024 — the recurrence is accelerating, not fading.
As of 08/21/2026.

Timeline

CONFIRMED
October 2024
Free / Free Mobile — cyberattack exposing data linked to 24 million subscriber contracts, IBANs compromised for some customers. Combined CNIL fines of €42 million (€27M Free Mobile + €15M Free), issued on January 13, 2026.
CONFIRMED
May 11, 2026
Bouygues Telecom acknowledges unauthorized access to "TECH360," its fiber-intervention tracking tool. Attackers claim a database of 80GB+ spanning 2022 to April 2026, and 4.5 million French residents potentially affected: names, full postal addresses, emails, phone numbers, dates of birth. No passwords or banking data, according to the carrier.
CONFIRMED
July 2 – August 20, 2026
SFR detects an intrusion into "NOVA," its fiber-connection management tool, and confirms it seven weeks later. 2.1 million lines claimed by hacker group ZeroBytes, never confirmed by SFR. Full case file: SFR: what's confirmed and what isn't.

🔧Why this exact tool, and not another

A fiber connection requires a technician — employee or subcontractor — to pull up a customer's exact address, intervention history and contact details within seconds, often in the field, without a reliable connection. These tools are built for speed of access, not fine-grained permission control. A compromised account — yours or a subcontractor's — therefore opens access far wider than that person's actual role would justify.

What it changes for you

The common thread across all three incidents isn't the amount stolen — in all three cases, the carriers state that passwords and most banking data weren't affected. The real risk is the raw material for a credible contact: a call posing as a fiber technician "following an incident," citing your exact address and line history. That's exactly the mechanism documented in From Leak to Scam.

🔒 The habit that protects you regardless of the carrier: never follow a link or call back a number provided in an unsolicited message, even if it cites your exact data. Always call your carrier back through a channel you already know is official. See how Medusa links channels together.

Frequently asked questions

Why does the same fiber tool keep showing up in three separate incidents?

Managing fiber connections requires giving technical teams broad access to customer records: name, address, contact details, sometimes account identifiers. These tools are built for speed, not fine-grained access control. A single compromised account opens access far wider than that person's role would justify.

Are these three incidents connected?

No public source establishes a technical or common-author link between the Free (2024), Bouygues Telecom (May 2026) and SFR (July 2026) leaks. What's documented here is the resemblance of the mechanism, not a shared attribution.

What should customers of any of these three carriers do?

Check your carrier's website for an official notification. The real risk is a credible call impersonating a fiber technician or customer service, citing your real data — not direct theft of money.

📌 Last checked: August 21, 2026. Verifiable information to report: contact@egidio.app.

Related reading

Cite this page Egidio — The Threat Laboratory, "Free, Bouygues, SFR: the same fiber tool breached three times," egidio.app/en/laboratoire/french-telecom-fiber-tool-pattern/. Licensed CC BY 4.0.

Free to reuse, including commercially, with attribution. Reuse terms.