Desk live·
ForensicPost
Breaches/Telecom/File 25-0804

Bouygues Telecom Attack Reached Data for 6.4 Million Customers

Bouygues Telecom detected an attack on a customer management system on 4 August 2025. Personal and contractual data for 6.4 million customers was reached, including IBANs.

Constructed geometry · not a chart of case data
TargetBouygues Telecom
ActorUnattributed
D. Kennedy11 min readConfidence: high2 sources reviewed

Bouygues Telecom, one of France’s principal mobile carriers, detected a cyberattack against a customer management system on 4 August 2025. Attackers accessed personal and contractual data belonging to 6.4 million customers, including international bank account numbers.

The IBAN Is The Field That Changes This File

Most carrier breaches in this corpus expose contact details and account metadata. An IBAN is different in kind: it is a direct-debit instruction target, and in the SEPA area it is the identifier used to initiate collections.

A person cannot change it without changing bank. Unlike a card number, which an issuer reissues in days, it is a durable identifier tied to a relationship most people maintain for decades — the permanence problem this desk filed for biometrics at 26-0324 and for national identifiers at 25-1105.

A Telecom Customer File Is Not A Telecom Customer File

The corpus keeps recording that customer-management systems accumulate more than the service requires. A mobile operator holds identity documents for regulatory subscriber registration, a payment instrument for the monthly bill, an address for the SIM, and a contract history.

That is a bank-grade record set assembled by an organisation whose business is connectivity, held in a system built for billing and support rather than for holding financial instruments.

And The Remedy Is Worse Here Than Usual

Direct-debit fraud in the SEPA area does have a strong consumer protection: an unauthorised collection can generally be reversed on request within a defined window.

That works if the customer notices. The failure mode is a small recurring collection against an account with regular activity — precisely the fraud pattern that survives inattention, in a population of 6.4 million who have been told to watch their statements.

How we reported this

Compiled from public reporting and European incident briefings, listed below. The intrusion route is not established in the material we reviewed. Corrections: corrections@forensicpost.com.

Sources
  1. Cyber Brief 25-12 — November 2025CERT-EU
  2. Biggest data breaches in FranceCorbado
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary