Eurofiber France experienced a cyberattack on November 13, 2025, in which threat actors exploited a vulnerability in the company's ticket management platform. The breach resulted in the exfiltration of data related to Eurofiber France and its regional brands, including Eurafibre, FullSave, Netiwan, and Avelia, as well as the cloud division operating under Eurofiber Cloud Infra France. The incident was limited to the French business unit, with no impact on Eurofiber's operations or customers in Belgium, Germany, or the Netherlands. Sensitive information such as banking details and critical data stored in other systems was not compromised, and the vulnerability has since been patched.
Following detection, Eurofiber implemented enhanced security measures on the affected platforms and worked with cybersecurity experts to support impacted clients. The company notified all affected customers and reported the incident, which included an extortion-related component, to French authorities CNIL and ANSSI. Operational impact was minimal, with customer-facing services remaining fully functional, and additional steps have been taken to prevent further breaches and strengthen overall system security.

See attribution, scope, and your downstream exposure.
5 events from the most recent confirmed update back to the earliest known activity.
Following the breach, Eurofiber France notified French authorities including CNIL and ANSSI and filed a report related to the extortion attempt. The reporting reflected the company's position that attackers had stolen data and demanded payment to prevent its publication.
Eurofiber France disclosed the incident publicly, stating that stolen data did not include banking details or other critical data and that the breach was limited to its French unit and related brands. The company said it would notify affected customers about the compromise.
After the breach, a threat actor using the name 'ByteToBreach' claimed on a data leak forum to have stolen ticket-system uploads from about 10,000 business and government clients. The actor alleged the data included screenshots, VPN configuration files, credentials, source code, certificates, archives, and SQL backups.
Shortly after detecting the intrusion, Eurofiber France secured the compromised ticketing platform and ATE portal, closed the exploited vulnerability, and implemented strengthened security measures. The company said customer-facing services remained operational, though some internal and partner-facing systems saw limited impact.
On 2025-11-13, attackers exploited a vulnerability in Eurofiber France's ticket management system, affecting only the company's French operations, including its cloud division and regional brands. The intrusion led to data theft and was later described by the company as linked to an extortion attempt.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
6 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcecsoonline.com
Open sourcescworld.com
Open sourcego.theregister.com
Open sourcebleepingcomputer.com
Open sourceeurofiber.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.