SFR 2024-2025: Two Breaches in One Year, the Second via an Internal Management Tool
> TL;DR: French telecom SFR suffered two separate security incidents a little over a year apart: a data breach affecting 3.6 million customers in September 2024, tied to the compromise of an internal management tool, then a new incident in December 2025 exposing personal data again (names, addresses, phone numbers), with no banking data affected according to the operator.
The first incident: September 2024
The initial attack did not stem from a flaw in SFR's public website, but from the compromise of an internal management tool — software or access used by support or sales teams to view and administer customer accounts. This type of tool, often less scrutinized by external audits than a public website or mobile app, frequently carries broad access to customer data anyway.
The second incident: December 2025
A little over a year after the first incident, SFR announced a new cyberattack with theft of personal information — names, addresses, phone numbers. The operator stated that banking data was not affected this time. The fact that a second incident occurred so soon after the first raises questions about how thorough the corrective measures applied after 2024 actually were.
The core lesson: internal tools are an attack surface in their own right
Security audits often focus on public-facing surfaces: the website, the customer API, the mobile app. Internal management tools — CRMs, support back-offices, admin dashboards — are just as critical, because:
Two incidents in one year: what does the recurrence reveal?
A second security incident in such a short window suggests that post-incident corrective measures did not address the root cause, or only covered part of the exposed scope. This is a common trap: fixing the specific vulnerability that was exploited without auditing every similar access point (other internal tools, other privileged accounts) sharing the same structural flaw.
What CleanIssue checks for
Our audits explicitly cover internal tools and back-offices, not just public-facing surfaces: access control for support accounts, mass search/export capabilities, and the presence of MFA on privileged access — the precise gaps that enabled this type of incident.
Key takeaways
Building HR, payroll, or recruiting software? CleanIssue performs security audits for HR SaaS in real-world conditions, no source code access needed. For a first read of your exposure, start with an external review of your application.
Related articles
Three adjacent analyses to keep exploring the same attack surface.
France Travail 2024: 43M French Citizens Leaked, What Really Happened
Technical breakdown of the France Travail data breach in 2024: how 43 million records were exposed, timeline, and lessons learned.
Free 2024: 24 Million Accounts Exposed, IBANs Included, and CNIL's Record Fine
A look back at the October 2024 Free/Free Mobile cyberattack: 24 million contracts exposed, IBANs leaked for dual-play subscribers, and the 42 million euro fine imposed by CNIL for security failures.
DGFiP Breached by ZeroBytes: Inside France's Biggest Tax Data Leak of 2026
France's tax authority (DGFiP) confirmed unauthorized access to its information system: impersonated agent credentials, no blanket MFA, and over 2 million people potentially exposed through the cadastral records server.
Sources
Editorial analysis based on official vendor, project, and regulator documentation.
Related services
If this topic maps to a real risk in your stack, these are the most relevant CleanIssue audits.