On September 29, 2026, a threat actor named Syrv4x claimed to be selling a database of 15,817 SFR fiber customer records on a cybercrime forum. The alleged data includes full names, home addresses, phone numbers, subscribed plans, order numbers, and scheduled technician visit dates. SFR and the CNIL have not confirmed the leak. This follows a confirmed SFR breach in August 2026 that reportedly exposed around 2.1 million records. The two incidents may or may not be connected.
SFR has not confirmed this specific incident. France’s data regulator, the CNIL, has not publicly commented either. The claim is unverified.
That said, SFR’s recent history makes the timing harder to dismiss, and the nature of what’s allegedly in the dataset carries specific, practical risks for the customers named in it.
What the New Listing Claims to Contain
The Syrv4x post is specific about what’s in the database, making it easier to assess potential harm even before verification.
According to the listing, the 15,817 records include full names, home addresses, phone numbers, subscribed service plans, order numbers, and scheduled technician appointment dates.
That last item deserves particular attention. Scheduled technician visit dates represent something that most stolen datasets don’t include: a calendar window. If someone knows your name, your address, and that a technician is coming to your home on a specific date, they have everything they need to call you in advance, pose as that technician, and request payment, account verification, or router access “to prepare for the visit.”
This fraud risk is qualitatively different from stolen email addresses or even phone numbers in isolation. The combination of identity, location, and appointment schedule creates a ready-made social engineering script that a scammer could deploy with high credibility, since the details would match what the victim actually expects to hear.
Two SFR Incidents in Two Months
This new claim arrives in the immediate wake of a confirmed SFR security incident from August 2026.
In that case, SFR publicly acknowledged that an act of “cybermalveillance” had exposed data belonging to fiber customers. The exposed data included home addresses, email addresses, and phone numbers. SFR stated that passwords and banking details were not affected, filed a complaint with French authorities, and notified the CNIL as required under GDPR.
A threat actor claimed at the time to have pulled approximately 2.1 million lines from an internal SFR system, a figure that came from the attacker rather than the company, so it should be treated with caution. SFR did not publicly confirm the scale. French media, including TF1 Info, covered the August incident, noting that the exposed data created meaningful social engineering and phishing risks for affected customers.
The new September claim looks different. At 15,817 records, it’s far smaller. It also appears to focus specifically on subscription and appointment details rather than the broader customer profile data from August. Whether the two incidents share an origin, overlap in any records, or are entirely separate is still unknown.
What is known: SFR has had two significant public security claims within six weeks. That pattern alone is worth noting when assessing the company’s security posture. As we’ve seen in the Bank of Baroda breach in India, where a second public security incident followed years of documented gaps, repeated exposure events from the same organization often reflect structural, not incidental, vulnerabilities.
Why Unverified Claims Still Create Real Risk
Neither SFR nor the CNIL have confirmed this leak. That matters for the public record. It matters little to scammers who have already seen the listing.
The moment a dataset, real or fabricated, appears on a cybercrime forum, it becomes material social engineers can work from. Even if only part of the records are genuine, or the data is recycled from an older breach, scammers can use it to send phishing messages and make calls that seem credible because they include real details about the recipient.
The CNIL specifically warns about this pattern: criminals reuse stolen personal data in phishing campaigns because messages with correct details about the victim are much harder to spot as fraudulent than generic scam attempts.
An SFR customer who receives a call from someone who already knows their subscription plan, order number, and upcoming appointment date has strong evidence that the call is legitimate. That’s precisely the attack vector the Syrv4x data appears designed to enable.
This dynamic is consistent with the broader synthetic identity and impersonation patterns we’ve tracked through 2026; the value of stolen data isn’t just in the raw information, it’s in how convincingly it can be deployed to bypass someone’s natural skepticism.
The Telecom Sector as a Repeated Target
SFR is not an isolated case in the telecom sector. Telecommunications companies hold a specific combination of data that makes them recurring targets: identity information, billing details, device information, home addresses, and, particularly in the case of SFR’s fiber operations, physical installation and appointment records.
A telecom provider’s internal systems often also include information about whether accounts have recently changed, which subscribers are on promotional plans likely to expire, and which customers have recently had technical problems, all of which can be used to craft highly targeted phishing approaches.
The scale of French telecom data exposure in 2026 extends beyond SFR. LightReading and Telecompaper both covered the August incident in a wider European context, noting that multiple French and European carriers have faced similar pressures this year. This pattern connects to what we’ve covered on how supply chain attacks on trusted vendors can cascade across telecommunications infrastructure.
What SFR Fiber Customers Should Do Now
Whether this specific leak is confirmed or not, the practical response for SFR customers is the same.
Be suspicious of any SFR-related inbound contact for the next several weeks. This applies to calls, texts, and emails. If someone contacts you referencing your SFR account, subscription plan, order number, or appointment schedule, treat that as a heightened-risk contact, not a trusted one. What they know doesn’t prove they’re legitimate. They may have come from this dataset.
Don’t let appointment details lower your guard. If a caller or message already knows when a technician is coming, that’s not evidence the call is from SFR. It’s evidence they’ve seen your record somewhere.
Go directly to SFR’s official channels to verify anything that seems urgent. Use the number on your bill or SFR’s official website, not a number given to you in an inbound call or message.
Enable two-factor authentication on your SFR customer account and on any other accounts linked to the same email or phone number. Two-factor authentication doesn’t prevent your data from being sold in a breach, but it significantly limits what an attacker can do with your credentials.
Check if your email address appears in known breach databases. Have I Been Pwned cross-references publicly disclosed breach data. If the August SFR incident is added and your email was included, you’ll receive an alert.
For the broader steps when personal data has been exposed, credit freezes, fraud alerts, and what to expect if your information is circulating, our guide on what to do when your data is on the dark web covers the full checklist.
Report any suspected fraud to France’s national cybermalveillance platform at cybermalveillance.gouv.fr, operated by ANSSI, or to the CNIL directly if you believe your personal data has been misused.
Frequently Asked Questions
Has SFR confirmed the September 29 data leak?
No. SFR and the CNIL have not confirmed the Syrv4x listing as of October 1, 2026. The claim remains unverified.
What data is allegedly in the new leak?
Full names, home addresses, phone numbers, subscribed plans, order numbers, and scheduled technician visit dates for 15,817 SFR fiber customers.
Is this connected to the August 2026 SFR breach?
Unknown. The August breach reportedly affected around 2.1 million records. The September claim covers 15,817 records with different data types. The two may or may not share an origin.
Why are technician appointment dates specifically dangerous?
They allow scammers to call in advance and impersonate technicians, using real appointment details to bypass the victim’s natural skepticism.
What should SFR customers do?
Treat unexpected inbound SFR contact with heightened suspicion, enable two-factor authentication, use official SFR channels to verify any urgent claims, and report fraud to cybermalveillance.gouv.fr.