Egidio
Case file · August 21, 2026

SFR: France's second-biggest carrier confirms a fiber breach

SFR confirmed on August 20 that it detected an intrusion on July 2 into a tool used to manage its fiber connections. Between the two dates, seven weeks passed before customers were warned. This page separates what SFR has confirmed from what a hacker has only claimed.

⚠️ Read this before anything else. Unlike some other case files on this site, the intrusion itself is not a bare claim: SFR confirmed it to the AFP news agency. What remains unconfirmed is the scale — the number of lines affected comes solely from the hacker — and the attribution to the group ZeroBytes, which AFP itself frames only as a hypothesis.

The numbers, and their real status

July 2
Date SFR's security team detected the intrusion. Confirmed.
AFP wire, 08/20/2026. Retrieved 08/21/2026.
Aug 20
Date SFR began warning customers — seven weeks after detection.
AFP wire, 08/20/2026. Retrieved 08/21/2026.
2.1M
Lines claimed by the hacker group ZeroBytes. SFR confirms no total.
Data-resale forum post, 07/17/2026, reported by multiple outlets. Retrieved 08/21/2026.
0
Passwords or banking data affected, according to SFR.
AFP wire, 08/20/2026.

This case doesn't follow the same shape as files built entirely on an unverified claim. Here, the company confirmed the intrusion, notified France's data-protection authority (CNIL) and filed a criminal complaint — as solid a factual base as this site documents for an incident this recent. What's missing is the exact scale: SFR has released no official figure, and the only public total comes from the hacker.

Timeline

CONFIRMED
July 2, 2026
SFR's security team detects an intrusion into a tool used to manage and analyze fiber connections, identified in the trade press as an internal portal named "NOVA."
CLAIMED
July 17, 2026
A post signed "ZeroBytes" appears on a data-resale forum, claiming extraction of 2,104,093 lines from the NOVA tool. AFP describes these claims as "unverifiable at this stage."
CONFIRMED
August 20, 2026
SFR confirms the incident to AFP: address, email and phone number of fiber subscribers affected; passwords and banking data excluded. The incident is reported to the CNIL, a complaint is filed with the public prosecutor. Affected customers begin receiving email notices — seven weeks after detection.

🔗ZeroBytes: a resemblance, not proof

AFP writes that the attack "appears to have been orchestrated by the same group" behind the DGFiP (French tax authority) breaches documented in our ZeroBytes case file. That's a resemblance, not an established attribution. The only material link is an identical signature on both forum posts — which rules out neither coincidence nor a copycat reusing the name.

Who's affected — and who probably isn't

According to every source available as this page went live, the incident affects fiber subscribers of SFR and its RED by SFR brand, through a tool dedicated to managing fiber connections. No reliable source currently mentions mobile-only customers or box subscriptions separate from fiber. If your only SFR contract is a mobile line with no associated fiber plan, nothing in the current public record indicates you are affected by this specific incident.

📌 Worth watching — this fiber/mobile distinction could change if SFR or the CNIL release further detail. This page will be updated accordingly.

A second breach in under a year

This isn't the first incident affecting RED by SFR customers: an earlier breach, in late 2024, exposed customer IBANs. The recurrence — two breaches in under two years at the same carrier — fits the pattern documented in our global scam report: France remains one of the most targeted countries worldwide, and the telecom sector is no exception.

What it changes for you, whatever the final number

Address, email and phone number are enough to make a contact sound credible: a call posing as an SFR technician for a "fiber intervention following the incident," a text asking you to "secure your line" through a link. That's exactly the mechanism documented in From Leak to Scam: the leak is only step one — the scam that follows uses the data to look legitimate.

🔒 The habit that protects you regardless of the final scale of this breach: never follow a link or call back a number provided in an unsolicited message, even if it cites your name, address, or line number. Always contact SFR through channels you already know are official. That's what Medusa, Egidio's engine, does by linking channels together — see how it works.

Frequently asked questions

Is the SFR breach confirmed?

The intrusion itself, yes: SFR confirmed it to AFP on August 20, 2026, detected on July 2. The CNIL was notified and a criminal complaint filed. The number of lines affected (2.1 million), however, is not confirmed by SFR — it comes from a claim by the hacker group ZeroBytes, posted on a forum on July 17, unverifiable at this stage.

Are mobile and box internet customers affected?

According to every source available so far, the incident affects only SFR and RED by SFR fiber subscribers, through a fiber-connection management tool. No reliable source currently mentions mobile-only customers or box subscriptions separate from fiber.

What should SFR fiber customers do?

Passwords and banking data are not affected, according to SFR. The useful precaution concerns the data that is genuinely exposed — address, email, phone number — enough to make a call or message impersonating SFR, a fiber technician, or a security authority sound credible. Verify any request through SFR's official channels, never through the link or number provided in the message you received.

📌 Last checked: August 21, 2026, based on an AFP wire from August 20, 2026. This page will be updated if SFR, the CNIL, or another authority releases an official figure. Verifiable information to report: contact@egidio.app.

Related reading

Cite this page Egidio — The Threat Laboratory, "SFR: France's second-biggest carrier confirms a fiber breach," egidio.app/en/laboratoire/sfr-fiber-data-breach/. Licensed CC BY 4.0.

Free to reuse, including commercially, with attribution. Reuse terms.