TechNewsReel
Live

Three Million Phone Numbers Exposed in Breach of France's Bloctel Service

A cybercriminal accessed a professional marketing account to steal millions of numbers just before the government closed the opt-out system.

TechNewsReel Newsroom · August 14, 2026

A cybercriminal has exposed three million telephone numbers after gaining fraudulent access to a professional account linked to Bloctel, France's former opt-out service for unsolicited marketing calls. The breach occurred shortly before the government permanently shuttered the service to implement a stricter regulatory framework for commercial communications.

According to the DGCCRF, the breach did not result from a direct compromise of the Bloctel database itself. Instead, the attacker targeted a professional account used by a telephone marketing business to interface with the system. While three million numbers were accessed, the DGCCRF confirmed that no other personal data, such as names or physical addresses, were exposed during the incident.

The Shift to Opt-In

Bloctel served as a government-run mechanism designed to protect French consumers by allowing them to formally opt out of cold calls. However, the system was officially closed on August 11, 2026. This closure marks a significant policy shift in France, as the country transitioned from an opt-out model to a mandatory opt-in regime. Under the new rules, businesses are now required to obtain explicit prior consent from individuals before making any commercial calls.

Industry Implications

This incident underscores a critical vulnerability in how third-party professional accounts are used to access government-managed data. By targeting a business partner rather than the central database, the attacker bypassed primary security layers to harvest a massive volume of contact information. For the affected users, the breach creates a heightened risk of phishing, smishing, and fraudulent calls. The irony of the breach is particularly sharp, as the data was stolen from a system specifically designed to shield citizens from these exact intrusions.

Future Outlook

As France moves forward with its opt-in system, regulators and security experts will likely scrutinize the authentication protocols used by professional accounts accessing public registries. While the Bloctel service is now defunct, the leaked data remains a permanent asset for bad actors. Users should remain vigilant against unsolicited communications, as the transition to an opt-in system does not erase the data already compromised in this breach.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.