Skip to main content
Back to overview
Medium

Bouygues Telecom Data Breach Affects 6.4 Million Customers

Weekly Cybersecurity Intelligence Report Cyber Threats & Breaches 4 Aug – 11 Aug, 2025 The week of August 4-11, 2025 witnessed a significant escalation in cyber threat activity, marked by sophisticated supply chain…

Key points

  • 6.4 million customers affected.
  • Compromised data includes contact details, contractual information, civil status data, company information for professional customers, and International Bank Account Numbers (IBANs).
  • Credit card numbers and account passwords were not compromised.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Ransomware

Malware, Social, Hacking activity

03

Potential impact

Potential operational disruption

Confidentiality, Availability

Published
Aug 4, 2025
Updated
Jul 22, 2026
Confidence
Medium
Evidence
4 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Malware, Social, Hacking activity

Watch phishing, executive impersonation and account-takeover exposure.

  • Source type: supplier or third-party involvement

Business impact

Potential operational disruption
Impact area
Confidentiality, Availability
Likely asset
User or customer data, Server or cloud data store

Mentioned entities

BouyguestelecomData DisclosureMillion Customers Weekly Cybersecurity IntelligenceBreachesAugKeyMicrosoft Exchange and SharePointNotableWinRARRussian

Quick context

Questions about this signal

What happened in this signal?

Weekly Cybersecurity Intelligence Report Cyber Threats & Breaches 4 Aug – 11 Aug, 2025 The week of August 4-11, 2025 witnessed a significant escalation in cyber threat activity, marked by sophisticated supply chain attacks, zero-day exploitations, and critical infrastructure targeting. Key developments include massive data breaches affecting telecommunications providers, airlines, and financial institutions, alongside emergency government directives addressing critical vulnerabilities in Microsoft Exchange and SharePoint systems. Notable incidents include the exploitation of a WinRAR zero-day by Russian threat actors, large-scale Salesforce CRM compromises, and continued targeting of critical infrastructure by Chinese state-sponsored groups. >> Outpace Attackers With AI-Based Automated Penetration Testing 1. Bouygues Telecom Data Breach – August 4, 2025 Overview French telecommunications giant Bouygues Telecom suffered a major cyberattack that compromised the personal data of 6.4 million customers. The breach was detected on August 4, 2025, but the company did not immediately disclose the full scope of the incident until August 6. Technical Explanation The attackers gained unauthorized access through what appears to be a sophisticated network intrusion targeting the company’s customer database systems. The breach methodology suggests a multi-stage attack involving initial access through phishing or credential compromise, followed by lateral movement to reach core customer data repositories. The attack vector demonstrates advanced persistent threat capabilities, with attackers maintaining access long enough to systematically extract large volumes of customer data. Contact details and contractual information Civil status data and company information for professional customers International Bank Account Numbers (IBAN) Notably, the breach did not include credit card numbers or account passwords. The exposure of IBAN data is particularly concerning as these can be used for unauthorized direct debit attempts and financial fraud. Technical Details MITRE ATT&CK Framework Mapping: Initial Access (T1566): Likely spearphishing or credential-based compromise Persistence (T1505): Web shell or backdoor deployment Discovery (T1083): File and directory discovery for data location Collection (T1005): Data from local systems Exfiltration (T1041): Exfiltration over command and control channel Investigation ongoing, specific technical indicators not yet publicly released Attack patterns suggest sophisticated threat actor with telecom sector targeting experience Immediate containment and system isolation Customer notification and fraud monitoring services Reporting to French CNIL data protection authority CISO Takeaway This incident highlights the critical importance of robust network segmentation and advanced threat detection in telecommunications environments. The delay in public disclosure (detected August 4, disclosed August 6) underscores the need for rapid incident response procedures and regulatory compliance frameworks. CISOs should evaluate their third-party risk management programs and ensure comprehensive data classification and protection controls are in place. U.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities catalog OpenAI AI models exploited zero-days to reach Hugging Face in benchmark test Public PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522 Zimbra 10.1.20 patches multiple security issues, including a critical command injection bug Qilin Ransomware Affiliates Abuse CVE-2026-0257 to Gain Unauthorized VPN Access Dutch Intelligence Warns Russia Uses Hacked IP Cameras for Military Espionage Critical 7-Zip Flaw Allows Code Execution by Opening Crafted XZ-Compressed Files. Update it now! CVE-2026-42533: Critical NGINX Bug Could Turn HTTP Requests Into Server Takeovers AI Agents Turned Into Attackers: Hugging Face Reveals Autonomous Intrusion Campaign Volexity Uncovers Zero-Day Campaign Targeting SonicWall VPN Appliances Attackers Can Take Over WordPress Sites Using Newly Released wp2shell Exploits OpenSSL Fixes HollowByte Memory Exhaustion Bug Daxin: 13-Year-Old China-Linked Malware Found Still Active on Manufacturer's Network U.S. CISA adds Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities catalog Ernst & Young (EY) Investigates Data Breach Involving Third-Party Support Tickets A cyberattack hit Nichirei, one of Japan's largest food companies New Russian Campaign Uses Fake Webex and Zoom Installers to Deploy Starland RAT U.S. CISA adds KNX Association KNX Protocol Connection Authorization Option 1 and Oracle flaws to its Known Exploited Vulnerabilities catalog French firm Bouygues Telecom suffered a data breach impacting 6.4M customers Bouygues Telecom suffered a cyberattack that compromised the personal information of 6.4 million customers. French telecommunications company Bouygues Telecom suffered a cyberattack that resulted in the compromise of personal information of 6.4 million customers. Bouygues Telecom, part of the Bouygues industrial group, is one of France’s leading telecom providers, offering mobile, internet, and IPTV services. Founded in 1994, the company is the country’s third-oldest mobile operator. The telecom firm serves over 23 million customers and continues to invest heavily in expanding and improving its 5G infrastructure. On August 4, Bouygues Telecom detected a cyberattack that allowed a third party to access personal data linked to certain subscriptions. The company is notifying affected customers by email or text, and has taken swift action to stop the attack and enhance its system security.

When was this signal reported?

Shadow Tier lists Aug 4, 2025 as the signal date.

Which organization is connected to this signal?

Bouyguestelecom is the organization connected to this public signal.

Explore Bouyguestelecom
Which attack pattern is relevant?

This signal is connected to current ransomware incidents based on its reported incident context.

Explore current ransomware incidents