TechNewsReel
Live

France's Bloctel Breach Exposes 3 Million Phone Numbers After Service Closure

A cybercriminal accessed the data of millions who registered with the government service specifically to avoid telemarketing calls.

TechNewsReel Newsroom · August 18, 2026

France's official government service for blocking telemarketing calls, Bloctel, has suffered a massive data breach that exposed approximately 3 million phone numbers. The incident is particularly severe because it targets a database of citizens who explicitly registered to avoid unsolicited contact.

According to reports from France Info and Ouest-France, a cybercriminal accessed the phone numbers shortly after the service was closed. The breach occurred during a volatile transition period for the country's telemarketing regulations, leaving the data of millions of privacy-conscious individuals vulnerable to exploitation.

The Shift to Prior Consent

Bloctel served as the primary mechanism for French citizens to oppose telephone solicitation. However, the service was phased out following the Law of June 30, 2025, which mandated a fundamental shift in how telemarketing operates in France. The government moved away from the "opt-out" model—where users had to register to stop calls—toward a "prior consent" or "opt-in" regime.

This new legal framework, which became officially effective on August 11, 2026, requires telemarketers to obtain explicit permission from a consumer before initiating a call. The breach took place as the Bloctel service was being shuttered to make way for this new regulatory environment.

Implications for Privacy

The irony of the breach is stark: the very people who took proactive steps to protect their privacy from unsolicited calls are now the primary victims. By accessing this specific database, malicious actors have acquired a high-value target list of active phone numbers.

For scammers and cybercriminals, this list is more than just a directory; it is a verified collection of active lines belonging to individuals who are likely sensitive to privacy. This makes them prime targets for sophisticated phishing attacks or social engineering schemes that mimic official government communications to gain further personal information.

What Remains Unconfirmed

While the scale of the breach is confirmed at approximately 3 million numbers, the exact nature of the vulnerability that allowed the access remains unclear. It is not yet known if the cybercriminal accessed the data through a legacy system that was not properly decommissioned during the service's closure or via a separate security flaw.

Users are advised to remain vigilant against an increase in unsolicited calls and SMS messages, as the leaked data is likely to be traded or sold on underground forums specializing in personal identifiable information (PII).

Sources

Get a notification when a big story breaks. A few a day at most — no spam.