In brief: in early August 2026, attackers claimed to have obtained a Bloctel database containing around 3 million phone numbers registered on France's list for opting out of sales calls. The public reports cited below do not establish every detail of the claim. Such a list could nevertheless be used for spam and scams. If you registered with Bloctel, take sensible precautions, check suspicious numbers and run a free scan to review your wider exposure.
What reportedly happened to Bloctel?
Bloctel was the French service where people registered their numbers to object to unsolicited sales calls. The alleged incident concerns a database associated with that service.
According to an alert from FrenchBreaches, reported by Frandroid, attackers claimed to have obtained approximately 3 million numbers and shared them on a forum. Reports describe an alleged business account without two-factor authentication and access to numbers in plain text. These are reported claims, not independently established technical findings in this article.
Keep three distinctions in mind:
- The authenticity and exact scope of the claimed database require confirmation.
- Public reports mainly describe phone numbers and technical identifiers, not necessarily names or email addresses.
- France's switch to consent-based sales calls on 11 August 2026 is a separate legal change. See what changes for telephone marketing.
Why the new rules do not eliminate the risk
A list of phone numbers can give fraudsters another source of potential targets. Being on an opt-out list does not mean that every number is still active or that each person will receive scam calls, but it is a reason to stay alert.
Possible consequences include:
- unsolicited calls and text messages;
- smishing, such as fake parcel, refund or banking messages;
- caller ID spoofing, where a displayed number resembles a trusted organisation's;
- circulation or enrichment of illicit contact lists.
Rules for legitimate telephone marketing do not make stolen files disappear, and criminals may ignore those rules entirely.
How can you tell whether you are affected?
The cited reports do not provide a reliable public check that establishes whether an individual number is in the alleged Bloctel file. Do not download a stolen database to check it.
A practical approach is to:
- Take precautions if you previously registered with Bloctel, without treating registration as proof of exposure.
- Record the displayed number and circumstances of suspicious calls. A sudden increase in calls does not, by itself, prove a connection with this incident.
- Check other known sources of exposure, such as public directories, brokers and supported breach records, through the Data Knight scan.
Breach search services have limited coverage. The absence of a Bloctel result does not establish that your number is safe.
What to do now
- Never share verification codes, banking details or identity documents because an unexpected caller asks for them.
- Enable your phone's spam filter or silence unknown callers if that suits your needs.
- Keep the date, time, displayed number and a short account of the conversation.
- Report abusive commercial practices through SignalConso. Use the relevant fraud reporting or police channel where appropriate.
- Treat parcel, refund and blocked-account texts cautiously. Open the organisation's official website yourself instead of following a suspicious link.
Our guides to parcel text scams and spam after a breach cover these situations in more detail.
Check a suspicious number with Stop nuisance calls
Data Knight is not a call blocker. The free Stop nuisance calls tool lets you enter a French number without creating an account and obtain available information such as:
- line type and ARCEP numbering indicators, including relevant NPV ranges;
- the operator originally allocated the number range, which is not necessarily the current operator or the business making the call;
- community reports and web reputation information, when available;
- a text summary to help prepare a SignalConso report.
The tool does not identify a private individual or prove who placed a call. It cannot reliably detect caller ID spoofing. Its purpose is to help you document and report a suspicious call.
Review your wider exposure
A free scan can help you look beyond a single incident. Depending on the sources and identifiers supported, the report covers:
- known breach records associated with your identifiers;
- public web pages mentioning your details;
- data broker sources relevant to your profile.
Phone coverage differs between sources and should not be assumed to match email coverage. A match also needs to be checked before concluding that it belongs to you.
You can then request removal from identified organisations where the GDPR applies and an erasure ground is available. This does not delete copies already stolen or circulated by criminals. For a broader starting point, see how to check for a data breach.



