Paris – 12.08.2026: The French protection service Bloctel has become the target of a cyberattack. According to the Directorate-General for Competition, Consumer Protection and Fraud Prevention (DGCCRF), around three million phone numbers were leaked. This is particularly frustrating for those affected: they had used the service to protect themselves from unwanted marketing calls.
The authority stated that the attackers had obtained neither names and addresses nor email addresses or other associated personal information linked to the stolen numbers. Based on current knowledge, no complete user data sets were disclosed. However, phone numbers can also be misused on their own, for example for mass marketing calls, fraudulent contact attempts or messages that feign a personal connection.
It was initially not publicly explained how the access was technically gained, when it was discovered or whether the numbers have already been shared or used. There is also no confirmed information on the identity of those responsible. The DGCCRF refers to a cybercriminal. The authority initially provided no further details on possible investigations.
Bloctel had for years been the state-supervised register in which consumers could enter their phone numbers to object to their use for marketing calls. Companies had to check the list before such campaigns and remove registered numbers from their calling databases. The service was supervised by the DGCCRF; most recently, it was operated by the company Consoprotec under a public service concession.
The attack coincides with a fundamental shift in French consumer protection. Since 11 August 2026, marketing calls have generally only been permitted if consumers have given their explicit prior consent. This ends the previous opt-out model, under which citizens themselves had to take action to fend off such calls. Bloctel ceased operations when the new rules came into force.
Companies must now be able to provide clear, verifiable consent that can be withdrawn at any time. Such consent may be valid for no more than one year; the relevant records must be retained for at least three years. Violations of the rules may be punished with substantial fines.
Former Bloctel users are advised to remain particularly vigilant regarding unknown calls and text messages. An isolated phone number contains less information than a complete customer data set. However, it may be sufficient to multiply unwanted contacts or lure recipients into responding. According to the DGCCRF, no further personal data was disclosed in the attack.
Sources
- Franceinfo: Report on the cyberattack on Bloctel
- DGCCRF: Rules on telemarketing since 11.08.2026
- Legifrance: Decree No. 2026-662 of 23.07.2026
- Bloctel: Notice on the end of the service
Artikel mit Hilfe künstlicher Intelligenz erstellt (Transparenzhinweis im Sinne von Artikel 50 der Verordnung (EU) 2024/1689 – EU AI Act).