SFR, another of France’s major mobile operators, disclosed a data breach involving banking details in September 2025, following the Bouygues Telecom incident at 25-0804 the previous month.
Sector Clustering, Filed For The Fourth Time
This desk set out the mechanism at 25-0512: a group that works one industry at a time is reusing research, because within a sector the vendors, outsourcers, support scripts and system vocabulary repeat.
UK retail in April and May. UK healthcare through the year. Enterprise SaaS tenants from mid-2025 at 25-0923. And now two French carriers in consecutive months.
The corpus has not established a common actor here and does not assert one. What it can say is that the pattern is now regular enough that a peer incident in your sector should be read as a warning with a short expiry.
National Operator Markets Concentrate The Problem
France has four principal mobile operators. Two disclosed breaches within about a month, which means a large fraction of the national adult population sits in one of the two affected datasets — and some people are in both.
That is the aggregation problem at 25-1010 arriving through market structure rather than through supplier consolidation. Where a sector has four participants, two incidents approach population-scale coverage.
Graded Medium
The Bouygues figures are well established; the SFR incident is more thinly reported in the material we reviewed. We have no affected count, no confirmed field list beyond banking details, and no established intrusion route.
Compiled from public reporting and European incident briefings, listed below. Affected volume is not established. We do not assert a common actor with 25-0804. Corrections: corrections@forensicpost.com.