We use cookies on this website.

By clicking "Accept," you agree to the storage of cookies on your device to improve your browsing experience, analyze site usage, and contribute to our marketing efforts. See our privacy policy for more information.

Bloctel Data Breach: 3 Million Phone Numbers Leaked—What SMEs Need to Check

A hacker claims to have obtained approximately 3 million phone numbers from Bloctel, which were made available for download on August 6, 2026—a few days before the service was shut down. For an SME, the real risk isn’t a leaked password—it’s a surge in fraudulent calls and text messages targeting your staff.

Bloctel Data Breach: 3 Million Phone Numbers Leaked—What SMEs Need to Check

In summary: A malicious actor claims to have obtained nearly 3 million phone numbers linked to Bloctel, the anti-cold-calling service, and published them on August 6, 2026. These numbers provide scammers with a ready-made list for fraudulent calls and text messages, posing a direct risk to your teams that handle money transfers or access credentials.

What Happened

On August 6, 2026, a hacker going by the name of Cybernox posted a file online that he claims is an excerpt from Bloctel, the public service that allows individuals to opt out of telemarketing calls. According to specialized media outlets that examined the sample (ZATAZ, Universfreebox, KultureGeek, cyberattaque.org), the data consists primarily of phone numbers and internal identifiers, comprising approximately 3 million records.

Two useful clarifications. A single user may have registered multiple numbers, so 3 million entries do not mean 3 million distinct individuals. And at this point, neither Bloctel, nor the organization that manages it, nor the DGCCRF has officially confirmed the incident. The claim comes at a particular time: Bloctel is set to close on August 11, 2026, to be replaced by a system under which a company must obtain your consent before calling you for commercial purposes.

Does this apply to me?

The good news is that this file does not contain any passwords, IBANs, or banking information. Therefore, there is no risk that an account will be hacked directly as a result of this data breach.

The real risk lies elsewhere. A valid phone number is the raw material for phone and text message scams. If an executive, an accountant, or an executive assistant has ever listed their work number on Bloctel, that number could end up on the list. Scammers use these numbers to call, posing as a vendor, the bank, IT support, or the executive themselves. AI-cloned voices make these calls even more believable, as seen in cases of CEO fraud using deepfake voice technology. A recognized number never proves the caller’s identity.

What to Do Now

1. Alert the people who are at risk. Accounting, management, the switchboard, and administrative staff: these are the targets of fraudulent calls. Make it clear to them that there will likely be an increase in suspicious calls or text messages in the coming weeks, and that a displayed number is no guarantee of authenticity.

2. Enforce payment approval procedures. Any wire transfer, change to an IBAN, or change to a supplier’s contact information must be cross-checked through a known channel (confirmation via the official phone number, approval by two people). No urgent request received by phone justifies bypassing this rule.

3. Report and block. Report fraudulent text messages by texting 33700. Do not ask anyone to call back an unknown number that keeps calling. If your work cell phones support it, enable the call-blocking feature.

Not sure about your exposure?

Get an update from an IT Systems expert

A quick assessment of your exposure and the steps you should take. No obligation.

Request an exchange

In a nutshell

The Bloctel data breach exposes phone numbers, not passwords. The danger lies in the wave of fraudulent calls and text messages it could trigger, along with the associated wire transfer fraud. With a simple rule of double-verifying payments and a team that’s been alerted, this type of attack can be easily thwarted.

Frequently asked questions

How can I tell if my phone number has been leaked? There is no official tool to check for this leak. Assume that any number that was ever listed on Bloctel may have been exposed, and take the necessary precautions.

Should you change your phone number? No. A phone number alone isn't enough to hack into your accounts. The right approach is to strengthen verification for sensitive requests, not to change your phone number.

Does the end of Bloctel change anything? Yes, for the better: Starting August 11, 2026, a company must obtain your consent before calling you to make a sale. Unsolicited sales calls will become illegal, which will help you spot suspicious sales pitches more quickly.

— Samir Amara, CEO — IT Systèmes

Our latest articles

See more
software
Development & automation

"I'm afraid to install software"

In 1996, I took my first steps in computing on an Excel spreadsheet where I filed cheat codes for my favorite video games. 🕹️Le the beginning of a passion for office tools (to each his own 😅 ). There were 3,000 machines connected to the internet! 😶 But what happened next?
July 31, 2026
fishing
Cybersecurity

Phishing 2026: Definition, Examples, and Protection for Small and Medium-Sized Businesses (Comprehensive Guide)

Spear phishing, BEC, voice deepfakes: why training alone isn’t enough, the true cost of an incident (€275,000), and the security measures that will work in 2026
June 26, 2026
backup-vs-retention
Cloud & infrastructure

Comparing backup VS retention

Backup VS retention: here's the match everyone's been waiting for!!!! 🥊 (okai not at all but I needed a catchy title..🤫)
August 3, 2026