Skip to main content
Back to overview
High

SFR Customer Data Breach via Contractor's Database and Order Management System

French telecommunications operator SFR, parent company of SFR Réunion, detected a security incident on September 3, 2024, involving a breach in a customer database used by one of its contractors.

Key points

  • French telecommunications operator SFR, parent company of SFR Réunion, detected a security incident on September 3, 2024, involving a breach in a customer database used by one of its contractors. The breach also affected its customer order management
  • SFR Customer Data Breach via Contractor's Database and Order Management System

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Internal actor · Confidentiality impact

Possible insider activity

03

Potential impact

Potential data exposure

Confidentiality

Published
Mar 1, 2024
Updated
Aug 5, 2026
Confidence
High
Evidence
7 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Possible insider activity

Watch exposure paths that could affect data, operations or third-party trust.

  • Source type: possible insider or internal misuse

Business impact

Potential data exposure
Impact area
Confidentiality
Likely asset
User or customer data, Server or cloud data store

Mentioned entities

SfrData DisclosureContractorFrenchSFRSFR RIBANsInternational Mobile Subscriber IdentityIMSIFrance

Quick context

Questions about this signal

What happened in this signal?

French telecommunications operator SFR, parent company of SFR Réunion, detected a security incident on September 3, 2024, involving a breach in a customer database used by one of its contractors. The breach also affected its customer order management system, leading to the exposure of personal data for an estimated 50,000 to 3.6 million customers. The compromised information included names, contact details (address, phone number, email), contract numbers, and for some customers, International Bank Account Numbers (IBANs) and International Mobile Subscriber Identity (IMSI) phone numbers. SFR initiated necessary measures upon detection, notified affected individuals, and informed relevant authorities, including France's National Commission for Information Technology and Civil Liberties (CNIL).

When was this signal reported?

Shadow Tier lists Mar 1, 2024 as the signal date.

Which organization is connected to this signal?

Sfr is the organization connected to this public signal.

Explore Sfr