Free, Bouygues, SFR: the same fiber tool breached three times
In under two years, three of France's biggest carriers were compromised through
the same type of entry point: the internal tool used to manage fiber
interventions. This is no longer one isolated incident — it's a pattern, documented here
without assuming a shared perpetrator.
⚠️ This case file isn't centered on one hacker or one
company. It documents a pattern: three major French carriers, in
under two years, compromised through the same type of entry point — an internal tool for
managing fiber-connection interventions. Each incident has its own independently confirmed
facts; the resemblance between them is our reading, not a shared official attribution.
Three carriers, the same blind spot
24M
Free — subscriber contracts exposed, IBANs
compromised for some customers (October 2024). Combined CNIL fines of €42M in
January 2026.
CNIL, January 2026.
4.5M
Bouygues Telecom — French customers potentially
affected, claimed via the internal "TECH360" tool (May 2026). Confirmed by the
carrier on May 11.
Trade press alerts, May 2026.
2.1M
SFR — lines claimed via the "NOVA" tool (July
2026). The intrusion is confirmed by SFR; this total is not.
AFP wire, 08/20/2026.
2 of 3
Incidents in 2026 alone. The third (Free) dates to 2024 — the
recurrence is accelerating, not fading.
As of 08/21/2026.
Timeline
CONFIRMED
October 2024
Free / Free Mobile — cyberattack exposing data
linked to 24 million subscriber contracts, IBANs compromised for some customers.
Combined CNIL fines of €42 million (€27M Free Mobile + €15M Free), issued on
January 13, 2026.
CONFIRMED
May 11, 2026
Bouygues Telecom acknowledges unauthorized
access to "TECH360," its fiber-intervention tracking tool. Attackers claim a database
of 80GB+ spanning 2022 to April 2026, and 4.5 million French residents potentially
affected: names, full postal addresses, emails, phone numbers, dates of birth. No
passwords or banking data, according to the carrier.
CONFIRMED
July 2 – August 20, 2026
SFR detects an intrusion into "NOVA," its
fiber-connection management tool, and confirms it seven weeks later. 2.1 million lines
claimed by hacker group ZeroBytes, never confirmed by SFR. Full case file:
SFR: what's confirmed and what
isn't.
🔧Why this exact tool, and not another
A fiber connection requires a technician — employee or subcontractor — to pull up a
customer's exact address, intervention history and contact details within seconds, often
in the field, without a reliable connection. These tools are built for speed of access,
not fine-grained permission control. A compromised account — yours or a subcontractor's
— therefore opens access far wider than that person's actual role would justify.
What it changes for you
The common thread across all three incidents isn't the amount stolen — in all three
cases, the carriers state that passwords and most banking data weren't affected. The real
risk is the raw material for a credible contact: a call posing as a fiber
technician "following an incident," citing your exact address and line history. That's
exactly the mechanism documented in
From Leak to Scam.
🔒 The habit that protects you regardless of the carrier: never
follow a link or call back a number provided in an unsolicited message, even if it cites
your exact data. Always call your carrier back through a channel you already know is
official. See how Medusa links channels
together.
Frequently asked questions
Why does the same fiber tool keep showing up in three separate incidents?
Managing fiber connections requires giving technical teams broad access to customer
records: name, address, contact details, sometimes account identifiers. These tools are
built for speed, not fine-grained access control. A single compromised account opens
access far wider than that person's role would justify.
Are these three incidents connected?
No public source establishes a technical or common-author link between the Free
(2024), Bouygues Telecom (May 2026) and SFR (July 2026) leaks. What's documented here is
the resemblance of the mechanism, not a shared attribution.
What should customers of any of these three carriers do?
Check your carrier's website for an official notification. The real risk is a
credible call impersonating a fiber technician or customer service, citing your real
data — not direct theft of money.
📌 Last checked: August 21, 2026. Verifiable
information to report: contact@egidio.app.
Cite this pageEgidio — The Threat Laboratory, "Free, Bouygues, SFR: the same fiber tool breached three times," egidio.app/en/laboratoire/french-telecom-fiber-tool-pattern/. Licensed CC BY 4.0.
Free to reuse, including commercially, with attribution. Reuse terms.