In brief — On August 20, 2026, SFR confirmed a new data breach potentially affecting 2.1 million fibre customers, after unauthorised access was detected on July 2 to an internal tool called NOVA. The hacker group ZeroBytes, already associated with the hacking of French tax authority systems, is mentioned as a lead, though their involvement is not confirmed. The exposed data reportedly includes IP addresses, MAC addresses, and router models — but not banking details.

A breach detected in early July, revealed seven weeks later

SFR confirmed to Agence France-Presse that it had identified a 'security incident' that could have led to the temporary exposure of certain data related to its subscribers' fibre lines. The unauthorised access was reportedly detected on July 2, 2026, but the operator only began notifying affected customers on August 20, seven weeks later — a delay deemed long by several observers for a personal data breach.

The suspected role of the ZeroBytes hacker group

The lead pointing to the cybercriminal group ZeroBytes is once again being discussed, though its involvement has not been established at this stage of the investigation. This same group had already claimed, in mid-July 2026, to have infiltrated an internal SFR tool containing data on 2.1 million customers — a claim that could not be independently verified at the time. ZeroBytes is also the group behind the hacking of the French tax authority systems, which fuels hypotheses of a similar modus operandi.

What data may have been leaked?

According to published information, the entry point was an internal tool used by SFR to manage and analyse fibre connections, named NOVA. The hackers claim to have begun extraction on June 30, for a claimed total of 2,104,093 lines. The published samples reportedly show IP addresses, MAC addresses, and internet router models.

At this stage, no banking data appears to be affected by this specific leak, unlike other incidents that have occurred in recent years at French telecom operators. However, the figure of 2.1 million stolen lines is based solely on the hacker's claim and has not been fully independently confirmed: therefore, caution should be exercised before considering it official.

A recurring phenomenon among French telecom operators

This case is part of a series of cyberattacks that have targeted French telecom operators in recent years, with leaks sometimes affecting several million subscribers and, depending on the case, including banking details. It illustrates the constant pressure exerted by groups specialising in exfiltration and resale of personal data on dark web forums.

What to do if you are an SFR fibre customer?

Check if you have received an official letter or email from SFR regarding this leak. Remain vigilant against phishing attempts (fraudulent SMS or emails) that could exploit the exposed data — line number, router model — to appear credible. Never communicate your login credentials or banking details in response to an unsolicited message, even if it appears to come from your operator. If in doubt, contact SFR customer service directly via official channels rather than replying to the received message.