Desk live·
ForensicPost
Breaches/Telecom/File 25-0909

SFR Discloses Breach Involving Banking Details Weeks After Bouygues

SFR disclosed a breach involving banking details in September 2025, weeks after Bouygues Telecom. Two of a country’s four major operators, in the same quarter.

Constructed geometry · not a chart of case data
JurisdictionFrancethe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetSFR
ActorUnattributed
S. Rosler11 min readConfidence: medium2 sources reviewed

SFR, another of France’s major mobile operators, disclosed a data breach involving banking details in September 2025, following the Bouygues Telecom incident at 25-0804 the previous month.

Sector Clustering, Filed For The Fourth Time

This desk set out the mechanism at 25-0512: a group that works one industry at a time is reusing research, because within a sector the vendors, outsourcers, support scripts and system vocabulary repeat.

UK retail in April and May. UK healthcare through the year. Enterprise SaaS tenants from mid-2025 at 25-0923. And now two French carriers in consecutive months.

The corpus has not established a common actor here and does not assert one. What it can say is that the pattern is now regular enough that a peer incident in your sector should be read as a warning with a short expiry.

National Operator Markets Concentrate The Problem

France has four principal mobile operators. Two disclosed breaches within about a month, which means a large fraction of the national adult population sits in one of the two affected datasets — and some people are in both.

That is the aggregation problem at 25-1010 arriving through market structure rather than through supplier consolidation. Where a sector has four participants, two incidents approach population-scale coverage.

Graded Medium

The Bouygues figures are well established; the SFR incident is more thinly reported in the material we reviewed. We have no affected count, no confirmed field list beyond banking details, and no established intrusion route.

How we reported this

Compiled from public reporting and European incident briefings, listed below. Affected volume is not established. We do not assert a common actor with 25-0804. Corrections: corrections@forensicpost.com.

Sources
  1. Cyber Brief 25-12 — November 2025CERT-EU
  2. Biggest data breaches in FranceCorbado
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary