The numbers, and their real status
This case doesn't follow the same shape as files built entirely on an unverified claim. Here, the company confirmed the intrusion, notified France's data-protection authority (CNIL) and filed a criminal complaint — as solid a factual base as this site documents for an incident this recent. What's missing is the exact scale: SFR has released no official figure, and the only public total comes from the hacker.
Timeline
🔗ZeroBytes: a resemblance, not proof
AFP writes that the attack "appears to have been orchestrated by the same group" behind the DGFiP (French tax authority) breaches documented in our ZeroBytes case file. That's a resemblance, not an established attribution. The only material link is an identical signature on both forum posts — which rules out neither coincidence nor a copycat reusing the name.
Who's affected — and who probably isn't
According to every source available as this page went live, the incident affects fiber subscribers of SFR and its RED by SFR brand, through a tool dedicated to managing fiber connections. No reliable source currently mentions mobile-only customers or box subscriptions separate from fiber. If your only SFR contract is a mobile line with no associated fiber plan, nothing in the current public record indicates you are affected by this specific incident.
A second breach in under a year
This isn't the first incident affecting RED by SFR customers: an earlier breach, in late 2024, exposed customer IBANs. The recurrence — two breaches in under two years at the same carrier — fits the pattern documented in our global scam report: France remains one of the most targeted countries worldwide, and the telecom sector is no exception.
What it changes for you, whatever the final number
Address, email and phone number are enough to make a contact sound credible: a call posing as an SFR technician for a "fiber intervention following the incident," a text asking you to "secure your line" through a link. That's exactly the mechanism documented in From Leak to Scam: the leak is only step one — the scam that follows uses the data to look legitimate.
Frequently asked questions
Is the SFR breach confirmed?
The intrusion itself, yes: SFR confirmed it to AFP on August 20, 2026, detected on July 2. The CNIL was notified and a criminal complaint filed. The number of lines affected (2.1 million), however, is not confirmed by SFR — it comes from a claim by the hacker group ZeroBytes, posted on a forum on July 17, unverifiable at this stage.
Are mobile and box internet customers affected?
According to every source available so far, the incident affects only SFR and RED by SFR fiber subscribers, through a fiber-connection management tool. No reliable source currently mentions mobile-only customers or box subscriptions separate from fiber.
What should SFR fiber customers do?
Passwords and banking data are not affected, according to SFR. The useful precaution concerns the data that is genuinely exposed — address, email, phone number — enough to make a call or message impersonating SFR, a fiber technician, or a security authority sound credible. Verify any request through SFR's official channels, never through the link or number provided in the message you received.
Related reading
Egidio — The Threat Laboratory, "SFR: France's second-biggest carrier confirms a fiber breach," egidio.app/en/laboratoire/sfr-fiber-data-breach/. Licensed CC BY 4.0.
Free to reuse, including commercially, with attribution. Reuse terms.