Back to blog
Famous hacksFrancedata breach

SFR 2024-2025: Two Breaches in One Year, the Second via an Internal Management Tool

Published on 2026-08-176 min readCleanIssue

> TL;DR: French telecom SFR suffered two separate security incidents a little over a year apart: a data breach affecting 3.6 million customers in September 2024, tied to the compromise of an internal management tool, then a new incident in December 2025 exposing personal data again (names, addresses, phone numbers), with no banking data affected according to the operator.

The first incident: September 2024

The initial attack did not stem from a flaw in SFR's public website, but from the compromise of an internal management tool — software or access used by support or sales teams to view and administer customer accounts. This type of tool, often less scrutinized by external audits than a public website or mobile app, frequently carries broad access to customer data anyway.

The second incident: December 2025

A little over a year after the first incident, SFR announced a new cyberattack with theft of personal information — names, addresses, phone numbers. The operator stated that banking data was not affected this time. The fact that a second incident occurred so soon after the first raises questions about how thorough the corrective measures applied after 2024 actually were.

The core lesson: internal tools are an attack surface in their own right

Security audits often focus on public-facing surfaces: the website, the customer API, the mobile app. Internal management tools — CRMs, support back-offices, admin dashboards — are just as critical, because:

  • They often grant broader access to customer data than the public interface itself (global search, bulk export, direct account modification).
  • They are used by many accounts (support teams, external contractors), which multiplies the number of accounts that could be compromised via phishing or password reuse.
  • They sometimes escape regular penetration testing cycles, wrongly treated as a secondary risk compared to public-facing surfaces.
  • Two incidents in one year: what does the recurrence reveal?

    A second security incident in such a short window suggests that post-incident corrective measures did not address the root cause, or only covered part of the exposed scope. This is a common trap: fixing the specific vulnerability that was exploited without auditing every similar access point (other internal tools, other privileged accounts) sharing the same structural flaw.

    What CleanIssue checks for

    Our audits explicitly cover internal tools and back-offices, not just public-facing surfaces: access control for support accounts, mass search/export capabilities, and the presence of MFA on privileged access — the precise gaps that enabled this type of incident.

    Key takeaways

  • An internal management tool with access to customer data is an attack surface that must be audited on the same footing as the public website.
  • Fixing one incident without auditing every similar access point exposes the organization to a rapid recurrence.
  • Search and bulk-export capabilities in back-offices must be limited and monitored, not just protected by a password.
  • Building HR, payroll, or recruiting software? CleanIssue performs security audits for HR SaaS in real-world conditions, no source code access needed. For a first read of your exposure, start with an external review of your application.

    Sources

    Written by CleanIssue
    Reviewed on 2026-08-17

    Editorial analysis based on official vendor, project, and regulator documentation.

    Related services

    If this topic maps to a real risk in your stack, these are the most relevant CleanIssue audits.

    Need an external review of your HR SaaS?

    Share your product, stack, and client context. We will come back with the right review scope.

    Discuss your audit