SFR Confirms New Data Breach Affecting Fiber Subscribers
SFR confirmed this Thursday, August 20, 2026, that it had been the victim of a data breach affecting its fiber subscribers. The incident dates back to July 2 and is directly linked to an internal line connection management tool. Here is what we know about this security incident.
A fiber connection management tool at the center of the incident
SFR has started sending emails to its subscribers to warn them about this new data breach. It refers to an incident detected on July 2, 2026 by the operator's security teams and targeting a fiber connection analysis management tool. The letter sent to RED by SFR customers, which I was able to review, clearly indicates which personal data is involved:
- Title, first name, and last name
- Postal address
- Mobile phone number
- Contract identifier
- Technical data related to the line
The operator specifies: "Your passwords and banking information are not affected." - An important clarification, because we have already seen this with Free in the past, but also with... SFR. Indeed, in September 2024, a breach targeting an order management tool had exposed RED by SFR customers' IBANs.

The cybercriminal behind this attack got hold of a valid account that they compromised. In fact, SFR says it deactivated the account used to access the tool, then blocked and monitored the IP addresses responsible for the accesses. In other words, this would not be the exploitation of a vulnerability, but rather a legitimate account that was misused. Yes, this is the same pattern observed during the recent incidents at DGFiP.
NOVA, 2,104,093 records, and an unattributed claim
So, who is behind this intrusion? Was it ZeroBytes, the same hacker already behind the leaks targeting government services? For now, there is no official information on that, but there are still some clues. On July 17, 2026, two weeks after the intrusion was detected, a post appeared on a cybercriminal forum. The authors claim to have compromised an internal SFR portal named NOVA, used to view and manage information related to fixed-line subscribers, network equipment, and fiber infrastructure.
This is consistent with the letter sent by SFR. And above all, the message was signed... ZeroBytes! The post claimed the extraction of more than 2.1 million data rows (2,104,093 rows extracted to be exact). The same message states that the intrusion began on June 30, 2026 before being stopped... probably on July 2.
Beyond identity and contact details, the records would reportedly associate other technical information with each subscriber (MAC address, box serial number, ONT identifier, IPv4 addresses, etc.). This may correspond to what SFR grouped under the label "Technical data related to the line".
With this data, a scammer could try to impersonate a fake SFR advisor or a fake fiber technician. Indeed, they could have highly convincing details: a subscriber's name, their exact address down to the floor, their plan, the model of their router, and the status of their line. In short, everything needed to run a convincing scam.
Bottom line: verify any intervention at your home directly with the operator before opening the door...

