CSIDB logo
Incident

Orange SA

Incident posture

Attack window
Jul 2025
Location
France
Status
Ongoing
CIA posture
Available to members
Updated
2026-08-17 20:09

Linked entities

Victim
Orange SA
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Jul 2025
Disclosed
Jul 2025
Resolved
Pending

Summary

The Orange Group detected a cyberattack on one of its information systems and, together with its cyberdefense unit, isolated potentially affected services, which disrupted certain management platforms and services for some business customers and a few consumer users mainly in France. Response teams are informing and assisting those affected while working to restore the main services. A formal complaint has been filed with authorities, and the investigation has found no evidence that internal or customer data was exfiltrated.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

On Friday, 25 July, the Orange Group detected a cyberattack on one of its information systems. As soon as the attack was identified, the Group's teams, in collaboration with Orange Cyberdefense, mobilized to isolate potentially affected services and minimize any impact. These isolation measures caused disruption to certain management services and platforms for some Business customers. The disruption also affected a few Consumer services, primarily located in France. The Group's dedicated teams began informing and assisting the affected customers immediately.

The teams have identified and are currently implementing solutions that, while under heightened vigilance, will allow the Group to gradually restore the main affected services by the morning of Wednesday, 30 July. A formal complaint has been lodged with the relevant authorities, who have been notified of the incident. Orange is collaborating closely with those authorities throughout the investigative process. At this stage of the investigation, there is no evidence to suggest that any internal or customer data has been exfiltrated. The Group continues to maintain the highest level of vigilance on the matter. For obvious security reasons, Orange has stated that it will not provide further comments on the incident.

Sources

Sources available to members: 1 source.

CSIDB