Consumer Banking Rights14 août 20263 min de lecture

Data breach exposes three million phone numbers in France as Bloctel closes

A cybercriminal accessed three million telephone numbers through a compromised professional account just before Bloctel's permanent closure, affecting 600,000 registered users as France transitions to stricter telemarketing rules.

807897.jpg
807897.jpg

Three million phone numbers accessed in data breach in France

Three million telephone numbers were compromised in a data breach involving Bloctel, France's telephone marketing opt-out service, just days before the platform permanently closed on August 11, 2026.

The Direction générale de la concurrence, de la consommation et de la répression des fraudes (DGCCRF), a department within the French Ministry of the Economy responsible for consumer protection and fraud control, confirmed that a cybercriminal fraudulently accessed a professional account and retrieved files containing the phone numbers. Of the three million numbers exposed, 600,000 belonged to consumers registered with Bloctel.

Professional accounts were used by businesses conducting telephone marketing to cross-check their prospecting lists against Bloctel's opt-out register. Under the previous system, companies were required to consult the Bloctel register monthly to ensure compliance, facing potential fines of up to €75,000 for companies or €15,000 for individuals who violated the rules.

The DGCCRF emphasized that the breach did not expose other personal information beyond telephone numbers.

Only telephone numbers were exposed, without any other personal data (name, address, etc.),
the authority stated, adding that
the Bloctel database itself has not been compromised.

Affected consumers whose numbers were registered with Bloctel have been notified. The compromised professional account was immediately blocked upon discovery, and all other professional accounts underwent security checks.

Rising cybersecurity concerns

The incident adds to France's mounting cybersecurity challenges. Between 2024 and 2025, more than 145 million records belonging to French citizens were exposed across various sectors including public services, healthcare, telecommunications and retail. The CNIL, France's data protection authority, received 6,167 personal data breach notifications in 2025, up from 5,629 in 2024.

Transition to new telemarketing regime

The breach occurred during a significant shift in France's approach to telephone marketing. Bloctel, which launched on June 1, 2016, replacing an earlier ineffective service called Pacitel, officially ended on August 11, 2026. The service, operated by Opposetel from 2016 to 2021 and then by Worldline France until its closure, had grown substantially over its ten-year existence. By February 2017, three million consumers were registered protecting seven million phone numbers, and by January 2025, over six million numbers were registered.

The closure came as Law n° 2025-594, enacted on June 30, 2025, and titled "Combating All Forms of Fraud Involving Public Aid," took effect. Under the new opt-in system, businesses must now obtain explicit, prior consumer consent before making commercial calls. Companies face substantially higher penalties for violations, with fines of up to €75,000 per call for individuals and €375,000 per call for companies making unauthorized marketing calls.

Under the new regulations, consent is valid for a maximum of one year and consumers can withdraw their agreement at any time. Additionally, companies may not contact the same consumer more than four times within any 30-day period.

Exceptions to the new rules include calls concerning existing contracts and certain newspaper, magazine and periodical subscriptions.

Consumer protection advice

The DGCCRF is urging consumers to exercise particular caution following the breach. The authority recommends not responding to unknown calls or messages, being wary of any links, and never providing personal information such as account details over the telephone.

Consumers should consider changing passwords where their telephone number is used as an identifier for online services. The authority also warned people to be alert to unusual requests, such as instructions to change a SIM card or update passwords.

Consumers who receive unsolicited commercial calls can report them via SignalConso, request that companies delete their data, and keep evidence such as the caller's number and the date and time of the call.

← Retour à Consumer Banking Rights