Confidence
6- Information type
- The event tests how a major telecom operator protects subscription identity, contract and IBAN data, warns customers and handles regulator-visible breach obligations.
Related details
Bouygues Telecom disclosed on August 6, 2025 that a cyberattack allowed unauthorized access to personal data tied to 6.4 million customer accounts, said the situation was resolved, notified CNIL, filed a judicial complaint and began informing affected customers by email or SMS.
Public record
Bouygues Telecom said it detected the attack on August 4, contained it quickly, notified CNIL and judicial authorities, and that the affected data included contact, contract, civil-status or company data and IBANs while passwords and card numbers were not impacted.
Public record
CNIL says French public electronic-communications service providers must notify personal-data breaches to CNIL and, in some cases, affected people; the CNIL page describes unauthorized access to personal data as a covered violation when linked to telecom service activity.
regulatory
Bouygues Telecom's official key figures support its scale as a major French fixed and mobile operator, including 27.1 million mobile customers at year-end 2025 and 5.5 million fixed customers at March 31, 2026.
Public record
BleepingComputer independently reported the 6.4 million-account exposure, the affected data categories, the absence of exposed card numbers or passwords, customer fraud risk and the unresolved uncertainty around attacker identity and misuse.
news
TechCrunch reported Bouygues Telecom as a major French phone carrier and framed the disclosure around customer-account data, IBAN exposure, CNIL notification and uncertainty over the remediation timeline.
news
Last updated: 2026-08-27
