SFR fibre data breach 2026: was my address or phone number leaked
If you are a customer of SFR fibre, here’s what is being claimed, and what it would mean for you.
SFR has confirmed that in July 2026 someone reached an internal tool used for fibre connections. Addresses, emails and phone numbers linked to SFR and RED by SFR fibre lines may have been visible; passwords and bank details were not. SFR has not said how many customers were affected.
— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Editor’s note: The claims described below originate from a ransomware group’s leak-site posting and have not been independently verified by GalaxyWarden. A listing of this kind is an assertion made by the group during an extortion attempt. It is not evidence that a breach occurred, and we report it as a claim rather than as a finding.
SFR fibre customer?
See what’s already exposed about you — free, 15sWe check your email against known public breach records and the sites that publish your address, then show you what to do about each one. We don’t hold this company’s data. No account, no card.
Here for work? Check a company domain’s exposure.
On 2 July 2026 SFR found that someone had gained unauthorised access to a company tool used to manage and analyse fibre connections. That access could have made visible information linked to fibre subscriber lines. SFR itself gives postal address, email address and telephone number as examples. Passwords and bank details were not involved.
SFR cut the access, added protections, told France's privacy regulator and filed a complaint with prosecutors. Around 20 August 2026 it began sending notices to affected SFR and RED by SFR fibre customers. It has not confirmed any total. Figures of about 2.1 million records come from the attackers, not from the company.
The part most coverage leaves out
Almost every report leads with what was not taken: your password, your card, anything that opens your SFR account or moves money. That is true. It is also the least useful part of the story if you have fibre with SFR or RED.
Advertisement
Know the day any company files a breach.
Every SEC 8-K Item 1.05 and state breach notification — dated, sourced, and delivered by email + a JSON API the day it posts. Track any company, not just the ones in the news.
GalaxyWarden Signals and RecentBreaches share common ownership.
What this kind of access leaves behind is a list of households — how to write to them, how to call or email them, and the fact that they are fibre customers. Some reporting adds names, titles, contract numbers and technical details of the line. SFR has not published a full field-by-field list, but it has said the data was the kind tied to fibre lines, not login secrets.
That combination is what a stranger can actually use. A text about a fault on your fibre can mention a real address. Someone at the door can claim they were sent about your connection. None of that needs your password. The reassuring headline and the practical risk are the same facts, read two ways.
What to actually expect
- A letter or notice from SFR or RED by SFR if the company treats you as affected. Those started around 20 August 2026. We cannot check whether you were included, and a leaked-data search is unlikely to settle it either.
- Emails, texts or calls that mention this incident or a problem with your fibre. They may show a real name, number or address so they look official.
- Someone at your door presenting as an SFR technician or partner. The useful pair here is a home address plus the fact you have fibre.
- No genuine bank or card alert that comes from this claimed breach. SFR says financial data was not involved. A message claiming your payment details were in “the SFR hack” is using the news, not what the company has confirmed.
What you can and cannot fix
If your address, email or phone number was among the fibre-line data this tool could see, that copy cannot be taken back. It is out. Nobody can honestly recall it. Changing your SFR password does not unsay an address, and SFR has not claimed it can delete what left.
What still helps, in order:
- Treat unexpected contact about your fibre or this leak as untrusted until you have checked through something you already use — the number or app on a bill you already have, not a link or callback in the message.
- Do not give anyone a password, a one-time code, a bank detail or a copy of your ID because of this incident. SFR has said those were not involved. Anyone who asks for them is not repairing the leak.
- Tell the people who share your home. The convincing version of this story often reaches whoever picks up the phone or opens the door.
- Cut back what people-search and directory sites publish about you. A leaked address and phone number become far more useful when they can be joined to relatives, employers and previous addresses. Those public listings, unlike the stolen file, can actually be removed. That is the lever you still have. The breach itself is not.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
For security and vendor-risk teams: get an alert the day a vendor you watch files a breach with a US regulator or the SEC — the filing itself, dated and sourced, plus an API. GalaxyWarden Signals →
A staff address in a leak usually means a third party was breached, not you — check your own domain’s exposure. Exposure Monitoring →
Report details & sourcing
Related breaches
Eastlink data breach August 2026: what the customer emails actually mean
Eastlink emailed some current and former customers on 28 August 2026 about accounts that may have be…
Tixel data breach: your email and mobile number may have been accessed
Tixel emailed customers on 28 August 2026 to say their email address and mobile number may have been…
Manchester Airports Group data breach: 8.7 million customer records accessed
Manchester Airports Group has confirmed that an unauthorised party accessed customer data from airpo…