A Large-Scale Cyberattack
Bouygues Telecom has confirmed that it was the victim of a cyberattack detected on August 4, 2025. The intrusion allowed an identified cybercriminal group to access personal data belonging to 6.4 million customer accounts, making it one of the largest data breaches ever suffered by a French telecom operator.
According to the information provided by the operator, the attack targeted specific internal resources. Bouygues Telecom's technical teams claim to have quickly contained the intrusion and implemented additional security measures.
What Data Was Exposed?
Bouygues Telecom has published an official FAQ detailing the nature of the exposed data. The compromised items include:
- Contact details (names, postal addresses, phone numbers, email addresses)
- Contractual information related to subscriptions
- Civil status data
- Business information for professional customers
- IBAN numbers (International Bank Account Numbers)
The operator clarifies, however, that credit card numbers and passwords were not compromised. Nonetheless, the presence of IBAN among the exfiltrated data raises legitimate concerns about the risks of bank fraud and targeted phishing.
Response and Official Notifications
Bouygues Telecom has informed several French authorities:
- The ANSSI (National Agency for the Security of Information Systems)
- The CNIL (National Commission on Informatics and Liberties)
- The judicial authorities, a criminal investigation is underway
Affected customers were informed directly via SMS and email. The operator has also set up a dedicated support system and advises its subscribers to:
- Never share their identifiers or sensitive data with individuals claiming to be Bouygues Telecom
- Regularly check their bank statements
- Report any suspicious activity to their bank
A Telecom Sector Under Pressure
This leak occurs in a context of increased attacks against European telecom operators. At the end of July 2025, Orange also revealed an intrusion into its network. These successive incidents illustrate the intensification of threats facing the sector, attributable to both organized cybercriminal groups and state actors.
The modus operandi described by some sources reports a multi-step attack: initial compromise via spear-phishing targeting administrator accounts, exploitation of a vulnerability on a VPN gateway, followed by lateral movement to customer databases. Polymorphic loaders using dynamic key AES encryption are reported to have been deployed to evade detection.
Practical Advice for Customers
If you are or have been a customer of Bouygues Telecom, here are the recommended actions to take:
- Monitor your bank accounts and report any unusual activity
- Beware of calls, text messages, or emails requesting personal information, even if they seem to come from Bouygues Telecom
- Change your passwords associated with your Bouygues account and any service using the same email address
- Enable two-factor authentication (2FA) on all your sensitive online accounts
- If in doubt, check the website Have I Been Pwned to verify if your email address appears in known breaches
The investigation is still ongoing, and Bouygues Telecom has committed to keeping its customers and authorities informed as new information is discovered.