Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Leaks » French Telecom SFR Faces New Security Scare Over Alleged 15,817-Record Data Leak

French Telecom SFR Faces New Security Scare Over Alleged 15,817-Record Data Leak

Last updated:September 30, 2026
Human Written
  • A hacker known as Syrv4x reportedly posted a database with 15,817 SFR customer records on a cybercrime forum.

  • The leaked data allegedly includes names, home addresses, phone numbers, and fibre installation appointment details.

  • This claim surfaced weeks after SFR confirmed a separate, much larger breach affecting fibre customers in August.

Hacker Claims Over 15,000 SFR Customer Records have Been Leaked

French telecom giant SFR may be facing a fresh data leak. A hacker reportedly posted customer records on a cybercrime forum on September 29, 2026. The claim has sparked new concern about the company’s security, especially since it follows another confirmed breach just weeks earlier.

New Leak Claim Surfaces on a Hacker Forum

Cybersecurity watchers spotted a new post on September 29, 2026. A hacker using the name Syrv4x claimed to have a fresh SFR database for sale. According to Cyberattaque.org, the database holds 15,817 records tied to SFR’s fibre customers.

The leaked information reportedly includes full names and home addresses. It also allegedly contains phone numbers, subscribed plans, order numbers, and scheduled technician visit dates. This mix of details could give scammers a convincing picture of each customer’s account.

Several cybersecurity accounts on X shared the same claim shortly after it appeared, echoing the 15,817 figure. However, SFR has not confirmed this specific leak yet. France’s data protection authority, the CNIL, has also stayed silent on it so far.

That means the leak remains unverified for now, and its authenticity still needs checking. Independent researchers would need to examine the dataset before anyone can call it a real breach.

This Isn’t SFR’s First Data Scare this Year

This new claim arrives shortly after SFR admitted to a separate, confirmed incident. In August, SFR said an act of cybermalveillance had exposed data belonging to its fibre customers.

According to TF1 Info, the exposed information included home addresses, email addresses, and phone numbers. SFR stated that passwords and banking details were not affected by that incident. The company also said it notified CNIL and filed a formal complaint over the matter.

That August breach was far bigger in scale. Our research tells us a hacker claimed to have pulled around 2.1 million lines from an internal SFR tool. This number came from the attacker himself, so experts caution against treating it as an officially confirmed total. Multiple known media groups also covered the incident, noting it revived concerns about social engineering risks tied to leaked customer data.

The new 15,817-record leak looks different from the August breach. It appears to focus on subscription details and fibre appointment bookings instead. Right now, nobody knows for certain if the two leaks connect, or if the newer database is even genuine. SFR customers are left waiting for clearer answers from the company.

Leaked Records Could Fuel Scams and Fake Calls

Even an unverified leak can put people at risk if any of the data turns out to be real. Names, addresses, phone numbers, and appointment details give scammers useful material to work with.

Similar concerns have emerged from other reported data leaks, including Israeli bank card data leaked on Telegram by a threat group, where financial information was reportedly exposed through the threat group’s Telegram activity.

The CNIL warns that criminals often reuse stolen personal data in phishing campaigns. They send fake emails or texts that look convincing because they contain real details about the victim. This trick makes scam messages much harder to spot at first glance.

Customers should stay alert for unexpected calls or texts referencing their SFR account, subscribed plan, or installation schedule. A message that already knows your order number or appointment date can feel trustworthy, even when it isn’t. Scammers could exploit this leak either way, whether it proves genuine or not, by posing as SFR technicians or support agents.

The CNIL also recommends turning on extra authentication protections wherever your accounts allow it. Two-factor authentication adds a second checkpoint that makes stolen passwords far less useful to attackers. Customers should also avoid clicking links inside unexpected messages, even ones that look official.

For now, the 15,817-record SFR leak should be treated as a reported claim, not a fully confirmed breach. SFR, the CNIL, or independent security researchers would need to weigh in before anyone confirms the leak’s source, its true scope, or whether the records are authentic. Until then, staying cautious with any SFR-related message remains the safest move for customers.

Share this article

About the Author

Memchick E

Memchick E

Digital Privacy Journalist

Memchick is a digital privacy journalist who investigates how technology and policy impact personal freedom. Her work explores surveillance capitalism, encryption laws, and the real-world consequences of data leaks. She is driven by a mission to demystify digital rights and empower readers with the knowledge to protect their anonymity online.

View all posts by Memchick E >
Comments (0)

No comments.