[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f23hze6hvz4xy4":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":29,"seoTitle":15,"seoTitleEn":30,"seoDescription":15,"seoDescriptionEn":31,"logoUrl":32,"isVerified":4,"isSensitive":4,"isSpamList":33,"isMalware":33,"company":34},"68e3266eda11adda48825128","bouygues-telecom","Bouygues Telecom Data Breach","bouyguestelecom.fr","2025-08-04T00:00:00.000Z","2025-09-24T06:37:56.000Z","2026-07-02T04:54:04.483Z","2026-07-18T23:46:21.191Z","Third party breach","",[],5685771,"known",null,"unknown","Critical",[23,24,25,26,27,28],"Bank account numbers","Dates of birth","Email addresses","Names","Phone numbers","Physical addresses","\u003Cp>Bouygues Telecom is one of the major telecommunications operators in France. The cyber attack detected on August 4, 2025, affected the company's customer data; among approximately 6.4 million customer records, there were 5.7 million unique email addresses, contact information, dates of birth, and bank account number fields such as IBAN.\u003C\u002Fp>\u003Cp>This record should be handled with high sensitivity because it simultaneously carries the identity and payment context of telecom customers. According to company statements, card information and account passwords were not affected; however, IBAN, name, address, and phone information could provide strong social engineering material in fake bank or operator calls.\u003C\u002Fp>\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\u003Cp>The data classes monitored in Bouygues Telecom records should be treated as bank account numbers, dates of birth, email addresses, name-surname information, phone numbers, and physical addresses. Bank account numbers, especially when in IBAN format, can be used in fake bank, invoice, refund, or payment verification messages. Dates of birth are permanent personal data that can be used in identity verification questions, age-based targeting, and profile enrichment. Email addresses can be used for targeted phishing, password reset schemes, and account matching across different services. Name-surname information makes fake support, fake delivery, fake invoice, and customer service messages more convincing.Phone numbers allow for personalized fraud scenarios to be set up via SMS, calls, and messaging applications. Physical addresses can be used in delivery, billing, subscription, and local service-themed social engineering messages.\u003C\u002Fp>\u003Cp>The context of the telecom operator makes it easier for attackers to reach the user under the pretense of billing, SIM change, number portability, subscription update, or bank refund. IBAN information alone may not be sufficient to withdraw payment; however, it can be used to gain trust in fake call center and fraud scenarios.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>This record is related to the domain bouyguestelecom.fr and the August 2025 event. The scope is limited to bank account numbers, birth dates, email addresses, full names, phone numbers, and physical addresses. Password or bank card information should not be among the verified fields for this record.\u003C\u002Fp>\u003Cp>Fields that are not present in this record should not be described as if they have leaked. Fields such as full card number, account password, official ID, private message, device content, or health information should only be included in the risk assessment if they are explicitly present in the record. The text is based on verifiable data classes and the known boundaries of the incident.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>Bouygues Telecom customers, people who use the same phone number for banking and official transactions, subscribers whose IBAN information is visible on their bills, and users open to line change requests are at primary risk.\u003C\u002Fp>\u003Cp>Users who use the same email address across different services, repeat their old passwords, and share their phone and address information across many shopping or community accounts are at higher risk. The connection between a pseudonym and real identity in corporate or community accounts can create additional social engineering risks.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Users should verify calls received on behalf of an operator or bank through the official application and customer service number. For requests that try to persuade you with IBAN or date of birth, one-time codes, card information, internet banking passwords, or identity documents should not be shared.\u003C\u002Fp>\u003Cp>Users in the positive match field should update their passwords on accounts where they use the same or similar passwords, enable two-factor authentication where possible, and check recent sessions. Caution should be exercised against unexpected calls, deliveries, returns, support, and verification messages on records containing phone numbers, addresses, payment information, or sensitive community information.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>In the long term, the habit of using a password manager, unique passwords, two-factor authentication, and removing unnecessary personal information from accounts reduces risk. Reusing the same email address across different platforms makes it easier to combine data from different breaches; using a separate email or alias for critical accounts can be considered.\u003C\u002Fp>\u003Cp>Telecom accounts should be considered critical because they serve as SIM and verification channels. Users should check for a strong password, two-factor authentication, SIM change alerts, and official communication preferences on their operator account; they should also regularly monitor bank transactions.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>LeakData check indicates whether the queried email address is present in this record. A positive result does not necessarily mean that all data fields definitely belong to that user; however, it is a sufficient warning for precautionary measures. A negative result only indicates that there is no match in this dataset, and does not eliminate the possibility of appearing in other breaches.\u003C\u002Fp>\u003Cp>A positive result indicates that the email address is present in the Bouygues Telecom customer dataset. Due to the bank account and telecom context, this record should be assessed with high priority; a negative result only means that there is no match in this dataset.\u003C\u002Fp>","Bouygues Telecom Data Breach (5.7 Million Reported Records)","Bouygues Telecom Data Breach. 5.7 Million reported records were reported. Reported data: Bank account numbers, Dates of birth, Email addresses. Review the…","\u002Fuploads\u002Flogo\u002Fbouyguestelecom_fr.webp",false,{"name":35,"sector":36,"country":37,"website":9,"websiteArchiveUrl":15,"websiteStatus":15,"websiteCheckedAt":19},"Bouygues Telecom","Telecommunications","France"]