started · updated
Bloctel data breach exposes 3 million phone numbers
The French government service Bloctel, designed to prevent unsolicited telemarketing, has suffered a cybersecurity incident involving the potential exposure of approximately 3 million phone numbers. The breach occurred shortly before the service was scheduled to close on August 11 due to new telemarketing consent regulations.
Authorities confirmed that an unauthorized third party impersonated a professional user account to access and download files exchanged with the service. The breach was reportedly facilitated by the absence of two-factor authentication on the compromised professional account. While the leaked data consists of phone numbers, Bloctel stated that names, first names, and other personal identifiers were not associated with the exposed numbers.
Despite the lack of personal names, officials warned that the disclosure of phone numbers increases the risk of unwanted calls, SMS messages, and phishing attempts. The incident has been reported to the Commission Nationale de l'Informatique et des Libertés (CNIL), and affected individuals are being notified directly.