We use cookies on this website.

By clicking "Accept," you agree to the storage of cookies on your device to improve your browsing experience, analyze site usage, and contribute to our marketing efforts. See our privacy policy for more information.

Bloctel Data Breach: 3 Million Phone Numbers Leaked—What SMEs Need to Check

A hacker claims to have obtained ~3 million phone numbers from Bloctel (August 6, 2026). The real risk for small and medium-sized businesses: a surge in fraudulent calls and text messages targeting your teams.

Bloctel Data Breach: 3 Million Phone Numbers Leaked—What SMEs Need to Check

In summary: A malicious actor claims to have obtained nearly 3 million phone numbers linked to Bloctel, the anti-cold-calling service, and published them on August 6, 2026. These numbers provide scammers with a ready-made list for fraudulent calls and text messages, posing a direct risk to your teams that handle money transfers or access credentials.

What Happened

On August 6, 2026, a hacker going by the name of Cybernox posted a file online that he claims is an excerpt from Bloctel, the public service that allows individuals to opt out of telemarketing calls. According to specialized media outlets that examined the sample (ZATAZ, Universfreebox, KultureGeek, cyberattaque.org), the data consists primarily of phone numbers and internal identifiers, comprising approximately 3 million records.

Two useful clarifications. A single user may have registered multiple numbers, so 3 million entries do not mean 3 million distinct individuals. And at this point, neither Bloctel, nor the organization that manages it, nor the DGCCRF has officially confirmed the incident. The claim comes at a particular time: Bloctel is set to close on August 11, 2026, to be replaced by a system under which a company must obtain your consent before calling you for commercial purposes.

Does this apply to me?

The good news is that this file does not contain any passwords, IBANs, or banking information. Therefore, there is no risk that an account will be hacked directly as a result of this data breach.

The real risk lies elsewhere. A valid phone number is the raw material for phone and text message scams. If an executive, an accountant, or an executive assistant has ever listed their work number on Bloctel, that number could end up on the list. Scammers use these numbers to call, posing as a vendor, the bank, IT support, or the executive themselves. AI-cloned voices make these calls even more believable, as seen in cases of CEO fraud using deepfake voice technology. A recognized number never proves the caller’s identity.

What to Do Now

1. Alert the people who are at risk. Accounting, management, the switchboard, and administrative staff: these are the targets of fraudulent calls. Make it clear to them that there will likely be an increase in suspicious calls or text messages in the coming weeks, and that a displayed number is no guarantee of authenticity.

2. Enforce payment approval procedures. Any wire transfer, change to an IBAN, or change to a supplier’s contact information must be cross-checked through a known channel (confirmation via the official phone number, approval by two people). No urgent request received by phone justifies bypassing this rule.

3. Report and block. Report fraudulent text messages by texting 33700. Do not ask anyone to call back an unknown number that keeps calling. If your work cell phones support it, enable the call-blocking feature.

‍

Not sure about your exposure?

Get an update from an IT Systems expert

A quick assessment of your exposure and the steps you should take. No obligation.

Request an exchange

‍

In a nutshell

The Bloctel data breach exposes phone numbers, not passwords. The danger lies in the wave of fraudulent calls and text messages it could trigger, along with the associated wire transfer fraud. With a simple rule of double-verifying payments and a team that’s been alerted, this type of attack can be easily thwarted.

Frequently asked questions

How can I tell if my phone number has been leaked? There is no official tool to check for this leak. Assume that any number that was ever listed on Bloctel may have been exposed, and take the necessary precautions.

Should you change your phone number? No. A phone number alone isn't enough to hack into your accounts. The right approach is to strengthen verification for sensitive requests, not to change your phone number.

Does the end of Bloctel change anything? Yes, for the better: Starting August 11, 2026, a company must obtain your consent before calling you to make a sale. Unsolicited sales calls will become illegal, which will help you spot suspicious sales pitches more quickly.

— Samir Amara, CEO — IT Systèmes

Our latest articles

See more

ASP: The Data Breach Explained, and What an SME Should Check Immediately Afterward

The Services and Payment Agency (ASP) has confirmed a data breach affecting more than 143,000 recipients of the “Coup de pouce énergie” assistance program, with IBANs and Social Security numbers exposed. For an SME, this incident highlights a risk that is easy to check internally: a vulnerability in document access that a public or private website may have without realizing it.
September 25, 2026
AI and Cybersecurity Illustration
Cybersecurity

AI and Cybersecurity: The 3 Key Challenges for SMEs and Mid-Sized Companies

AI and Cybersecurity: Securing Your Use of AI, Using It to Defend Yourself, and Countering AI-Powered Attacks. A Guide for Small and Medium-Sized Businesses.
September 25, 2026
Illustration of an agent-based infrastructure operator
Cybersecurity

Agent-Based Infrastructure Operator: Definition and Role

An agent-based infrastructure operator designs, secures, and continuously operates the layer that enables AI agents to act within the information system. Definition, components, a Microsoft 365 example, and eight questions to help you choose an operator.
September 24, 2026
Illustration: iA Agent
Cybersecurity

Agent-Based AI: Definition, How It Works, and Applications

Agent-based AI refers to AI systems capable of pursuing a goal autonomously: they gather information, plan steps, take action within software, and adjust their plan based on the outcome. Definition, operation, risks, governance, and business applications.
September 24, 2026
Abstract illustration of cybersecurity
Cybersecurity

Brevo: The Data Breach Explained, and What an SME Should Check Immediately Afterward

Brevo, the French email marketing platform used by tens of thousands of small and medium-sized businesses, suffered two security incidents in early September 2026: a breach via an authentication vulnerability, followed by the theft of a technical key that allowed malicious code to be injected into client websites. This week, Trezor and Paymium confirmed the extent of the impact on their users. Here’s what an SME that uses Brevo—or one of its widgets—needs to check.
September 24, 2026
Illustration: Protecting Your Small Business from Cyber Threats
Cybersecurity

How to Protect Your Small Business from Cyberattacks in 2026

Technical prevention, business continuity planning (BCP)/disaster recovery planning (DRP), and cyber insurance: the three lines of defense to protect your small business from cyberattacks in 2026.
September 24, 2026