More than 2.1 million customer records stolen in SFR hack - are you at risk?
Exposed customer information could give scammers the details they need to make convincing calls, emails or texts
SFR has confirmed a data breach that exposed personal information belonging to some of its fibre customers.
The incident was detected by SFR's security teams on July 2 and it involved an internal tool used to manage and analyse fibre connections.
The operator said it immediately took steps to stop the access. It disabled the account used to access the tool, blocked and monitored the IP addresses involved and carried out further security investigations.
According to Cyberattaque.org, a database containing around 2.1 million records was accessed, although SFR has not confirmed the figure.
SFR has also notified France's data protection authority, the CNIL, and said it has filed a complaint with the public prosecutor.
What information was exposed?
SFR said the affected data may include: title, first and last name, address, mobile phone number, contract ID and technical information relating to the fibre line.
However, SFR said passwords and banking information were not affected.
Are you at risk?
SFR has notified customers who they believe were impacted.
If you are an SFR customer, you should pay attention to any communication you receive claiming to come from SFR. Scammers may also use this information to make convincing calls, emails or texts while pretending to represent other organisations, using personal details about you to gain your trust.
Watch out for:
Calls from someone claiming to be an SFR technician
Emails or text messages asking you to click on a link
Requests for passwords or verification codes
Requests for payment
Someone claiming they need to replace your box
Someone arranging a supposed fibre repair or intervention at your home
Knowing personal information about you does not prove that the person contacting you is from SFR.
For example, in a recent Crédit Agricole phishing campaign, scammers used stolen customer information to pose as bank employees and convince some victims to transfer money.
What should you do?
If you receive a suspicious call, SMS or email, do not give out passwords, payment details or verification codes.
Do not click on links in unexpected messages. If someone claims to be from SFR or says that you are one of the customers affected, contact SFR through its official channels rather than using a phone number or link provided by the caller or message.
The SFR incident comes as France has faced a series of high-profile data breaches.
Just a couple of days ago, the French tax authority, the Direction générale des Finances publiques (DGFiP), confirmed a third data breach in just a few months.
It followed two much larger breaches at the tax administration. One affected around 678,000 individuals and businesses, while another potentially affected more than 430,000 individuals and more than 1,000 professionals.
Other French public bodies, including France Titres and Urssaf, have also suffered major cybersecurity incidents in recent months.