forumNew topic

What should I do right now to protect our company data after the telecom cyberattack?

SSonerMember
Job title
Metal manufacturing
Organization type
chain store
Joined
Dec 2023
Message
76

Doki · Corporate website · 2025

#1

We run a wholesale food business in Marseille with 8 employees, 10 corporate mobile lines, and a fixed fiber internet subscription at our office. Yesterday morning, it was announced that the major telecom provider we use across France suffered a massive cyberattack, and contract, contact, and bank account (IBAN) details of millions of customers were stolen.

We haven't received a direct statement specific to our corporate account from the provider yet, but when we log into our customer portal, our invoices, company IBAN, employee names, and line details are all stored right there. Are our company accounts or staff in immediate danger because of this provider we pay around 6,000 euros a year to?

How should we handle communications with our clients and suppliers, and what internal security measures should we implement right away?

YYağmur Y***Member
Job title
Administrative manager
Sector
Furniture manufacturing
Organization type
medium-sized business
Joined
Dec 2024
Message
2

Doki · Log management setup · 2025

Most Helpful#2

Short answer: At this stage, you should immediately reset your passwords on the provider's customer portal, contact your company bank to place an approval lock against unauthorized auto-pay and direct debits tied to your IBAN, and warn your staff about targeted phishing attacks impersonating the carrier.

Data stolen in telecom breaches usually includes IDs, billing histories, and bank details. Attackers can't directly drain your account with just an IBAN, but they can set up fraudulent direct debit (SEPA) mandates in your name. To prevent this risk, take these steps without delay: 1) Call your company's bank and require accounting approval or create a whitelist for any new direct debit creditor, 2) Change your telecom portal password and make sure it's not reused anywhere else, 3) Request an unauthorized SIM swap block from the carrier to stop attackers from porting your company lines to new SIMs.

The most common threat is spear phishing. Since attackers have your account number and invoice amounts, they could call your accounting department and point them to fake links under the guise of an "incorrect invoice refund" or "bank details update." Instruct all your staff not to trust any telecom notification received by phone or email, and that any action must only be confirmed by logging directly into the official portal.

YYiğit N***Member
Job title
Product Manager
Sector
E-commerce
Organization type
300-person organization
Joined
Sep 2024
Message
115
#3

First thing to do is call your bank and put a strict approval rule on direct debits. Make sure only pre-approved companies can withdraw funds, and any new request must go through accounting for sign-off. That's usually the loophole attackers exploit.

OOkan F***Expert
Job title
Fintech product manager
Organization type
chain store
Joined
Aug 2023
Message
146
#4

If you have SMS-based 2FA on company emails or bank accounts, move them to authenticator apps immediately. If the carrier's infrastructure was compromised, there's a real risk of SMS verification codes being intercepted via SIM swapping.

GGizem Ö***Member
Job title
QA Tester
Sector
Consulting
Organization type
regional distributor
Joined
Jul 2024
Message
257
#5

Send an urgent internal memo to all staff: do not click any links in SMS or emails that claim to be from the provider. Expect a surge in fake messages claiming "your bill is overdue" or "your line has been suspended" over the coming days.

EEsra A***Member
Job title
Technical service technician
Sector
Healthcare services
Organization type
120-person company
Joined
Dec 2025
Message
9
#6

We were with another provider that had a similar leak two months ago. Two weeks after the incident, our accounting received a fake invoice email for 840 euros that looked totally legit. It even had our actual customer number on it; we caught it at the very last second. Stay extremely alert.

HHasan U***MemberCommunity member
Joined
May 2024
Message
41
#7

Did the carrier's corporate portal hold your office's static IP forwarding rules or remote access configurations? Have you asked them for specifics on whether attackers only accessed billing data or compromised network management permissions too?

edit: fixed a few typos.

HHüsniye C***Member
Job title
Information Security Specialist
Sector
Insurance
Organization type
40-person manufacturing company
Joined
Apr 2022
Message
295

Doki · Brand identity · 2024

#8

we are on the same carrier total panic since yesterday morning. called the bank right away and locked sepa mandates. also warned our accountant not to reply to emails from unknown senders.

NNergisMember
Job title
Compliance Officer
Joined
Jan 2024
Message
104
#9

In the event that corporate identity and banking data have been leaked following a cyber incident, all formal notices issued by the carrier should be carefully archived, and bank account activity should be audited on a daily basis.

EEmre G***Member
Job title
Sales Manager
Sector
Security services
Organization type
medium-sized business
Joined
Feb 2025
Message
68
#10

After a similar leak last year, someone tried to SIM swap one of our partner's company lines. Luckily, they noticed their phone suddenly lost reception late at night and called the bank immediately to freeze the accounts. If any of your lines lose signal for no reason, act right away.

VVolkan A***MemberCommunity member
Joined
Feb 2023
Message
74
#11

thanks for poosting and like most incidents start with a leaked password, not a vulnerability.

the real issue isnt the number but what its based on. of couurse it varies if your situation is different.

ÖÖzge T***Member
Job title
Quality control inspector
Sector
Jewelry
Organization type
workshop
Joined
Feb 2023
Message
193
#12

I agree, and I'd like to emphasize that. Trying to do this alone is the most expensive way.

Everyone rushing into what to do after telecom breach gets stuck at the same point. Good luck with that.

AAytenNew member
Job title
Home cooking
Organization type
8-person team
Joined
Nov 2024
Message
28
#13

We experienced almost the exact same thing last year. If you dont write this down from the start, it leads to arguments later.

ÖÖzgür K***MemberCommunity member
Joined
Nov 2023
Message
4
#14

You're right, I've been down that road too. The real issue isn't the number, but what it's based on.

OOrhan O***Member
Job title
Board member
Sector
Seafood
Organization type
medium-sized business
Joined
Jun 2023
Message
17
#15

You're right. Everything goes well for the first three months; problems arise in the fourth.

If I were you, I'd go this route.

BBeyza T***MemberCommunity member
Joined
Nov 2024
Message
336
#16

Im a small business let me explain from my side. Hasty decisions become decisions you have to fix six months later.

If permission and scope arent in writing dont start that test. tbh correct me if Im wrong.

OOsman B***MemberCommunity member
Joined
Nov 2025
Message
252
#17

Correct.

CCaner G***MemberCommunity member
Joined
Aug 2023
Message
218
#18

There's a part I don't understand. Taking measures without an inventory leaves doors you haven't seen open.

If I were you, I'd go this route.

İİsmail K***Member
Job title
Customer service representative
Sector
E-commerce
Organization type
120-person company
Joined
Jan 2022
Message
28
#19

Let me share what happened to me; it might be useful. An untested backup is not a backup.

Solutions that work at a small scale collapse when you grow; I learned this late. Good luck with that.

KKerem O***Member
Job title
Game studio
Organization type
20-person company
Joined
Feb 2024
Message
98
#20

I partly agree partly disagree. If you get three different answers on a topic, the question was asked wrong.

Don't hesitate to ask; those who don't ask always pay more. I'm also curious if anyone does it differently.

This topic has been closed.The moderator marked the topic as resolved. If you have a similar issue, you can open a new topic.
New topic