In summary: A malicious actor claims to have obtained nearly 3 million phone numbers linked to Bloctel, the anti-cold-calling service, and published them on August 6, 2026. These numbers provide scammers with a ready-made list for fraudulent calls and text messages, posing a direct risk to your teams that handle money transfers or access credentials.
What Happened
On August 6, 2026, a hacker going by the name of Cybernox posted a file online that he claims is an excerpt from Bloctel, the public service that allows individuals to opt out of telemarketing calls. According to specialized media outlets that examined the sample (ZATAZ, Universfreebox, KultureGeek, cyberattaque.org), the data consists primarily of phone numbers and internal identifiers, comprising approximately 3 million records.
Two useful clarifications. A single user may have registered multiple numbers, so 3 million entries do not mean 3 million distinct individuals. And at this point, neither Bloctel, nor the organization that manages it, nor the DGCCRF has officially confirmed the incident. The claim comes at a particular time: Bloctel is set to close on August 11, 2026, to be replaced by a system under which a company must obtain your consent before calling you for commercial purposes.
Does this apply to me?
The good news is that this file does not contain any passwords, IBANs, or banking information. Therefore, there is no risk that an account will be hacked directly as a result of this data breach.
The real risk lies elsewhere. A valid phone number is the raw material for phone and text message scams. If an executive, an accountant, or an executive assistant has ever listed their work number on Bloctel, that number could end up on the list. Scammers use these numbers to call, posing as a vendor, the bank, IT support, or the executive themselves. AI-cloned voices make these calls even more believable, as seen in cases of CEO fraud using deepfake voice technology. A recognized number never proves the caller’s identity.
What to Do Now
1. Alert the people who are at risk. Accounting, management, the switchboard, and administrative staff: these are the targets of fraudulent calls. Make it clear to them that there will likely be an increase in suspicious calls or text messages in the coming weeks, and that a displayed number is no guarantee of authenticity.
2. Enforce payment approval procedures. Any wire transfer, change to an IBAN, or change to a supplier’s contact information must be cross-checked through a known channel (confirmation via the official phone number, approval by two people). No urgent request received by phone justifies bypassing this rule.
3. Report and block. Report fraudulent text messages by texting 33700. Do not ask anyone to call back an unknown number that keeps calling. If your work cell phones support it, enable the call-blocking feature.
In a nutshell
The Bloctel data breach exposes phone numbers, not passwords. The danger lies in the wave of fraudulent calls and text messages it could trigger, along with the associated wire transfer fraud. With a simple rule of double-verifying payments and a team that’s been alerted, this type of attack can be easily thwarted.
Frequently asked questions
How can I tell if my phone number has been leaked? There is no official tool to check for this leak. Assume that any number that was ever listed on Bloctel may have been exposed, and take the necessary precautions.
Should you change your phone number? No. A phone number alone isn't enough to hack into your accounts. The right approach is to strengthen verification for sensitive requests, not to change your phone number.
Does the end of Bloctel change anything? Yes, for the better: Starting August 11, 2026, a company must obtain your consent before calling you to make a sale. Unsolicited sales calls will become illegal, which will help you spot suspicious sales pitches more quickly.
— Samir Amara, CEO — IT Systèmes



