Orange A.I CyberSecurity Scoring
Orange
Company Information
Website:https://www.orange.com
Employees number:135,828
Number of followers:1,194,818
NAICS:517
Industry Type:Telecommunications
Homepage:orange.com
Orange Risk Score (AI oriented)
Between 0 and 549
OrangeTelecommunications
Updated:
01/05/2026
01/05/2026
397/1000
Critical
C
Orange Global Score (TPRM)
xxxx
OrangeTelecommunications
Score locked

OrangeCritical
Current Score
397C (CRITICAL)
01000
10 incidents
-91.75 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
412
MAY 2026
402
APRIL 2026
399
MARCH 2026
373
FEBRUARY 2026
360
JANUARY 2026
350
DECEMBER 2025
334
NOVEMBER 2025
330
OCTOBER 2025
319
SEPTEMBER 2025
313
Cyber Attack
01 Sep 2025 • Orange
Orange Belgium
Cyberattaque ciblant Orange Belgium avec risque de vol de numéros de téléphone
305
HIGH-8
ORA814090225
Orange Belgium, a major telecom operator, suffered a cyberattack targeting its IT systems, raising concerns over potential theft of customer phone numbers. The attack exposed vulnerabilities where fraudsters could exploit stolen customer data to impersonate legitimate users and hijack phone numbers via SIM-swap fraud. Once in control of a victim’s number, attackers could intercept verification codes (e.g., for password resets, email, social media, or payment systems), enabling broader fraudulent activities like account takeovers or financial theft. The Belgian telecom regulator (IBPT) responded by mandating an additional verification step—sending an SMS alert to customers for any number-transfer requests, allowing them to block unauthorized changes by replying 'STOP'. While no large-scale data breach (e.g., financial or sensitive personal records) was confirmed, the attack disrupted trust in Orange’s security, forced operational changes, and posed reputational and financial risks due to potential downstream fraud. Customers were urged to enable multi-factor authentication and scrutinize suspicious communications, highlighting the attack’s secondary impact on user behavior and operational processes.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
AUGUST 2025
359
Breach
23 Aug 2025 • Orange
Orange Romania, Orange Belgium and Orange: Ransomware hack hit Orange telecom, data published on dark web
Orange Hit by Ransomware Attack as Warlock Gang Leaks Stolen Business Data
315
HIGH-44
ORA1770804300
Orange Hit by Ransomware Attack as Warlock Gang Leaks Stolen Business Data
French telecommunications giant Orange has confirmed a ransomware attack by the cybercriminal group Warlock, which resulted in the theft and publication of business customer data. The breach, disclosed to national authorities in late July, saw approximately four gigabytes of data posted to the dark web in mid-August.
According to sources familiar with the incident, the attack targeted Orange’s internal systems using ransomware leased by Warlock a group known for providing its malware to other hackers in exchange for a cut of ransom payments. While Orange acknowledged the data leak, a spokesperson stated that the compromised information was "outdated or low-sensitivity" and that affected businesses were notified prior to the public release. The company is collaborating with authorities and impacted clients to mitigate the fallout.
This incident marks the third major breach for Orange in 2024. In July, attackers accessed customer data from its Belgian division, while a separate attack exposed employee records from its Romanian operations on the dark web.
Telecom providers remain prime targets for cybercriminals due to the vast amounts of financial, government, and corporate data they handle. The repeated attacks on Orange underscore the growing threat to critical infrastructure in the sector.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
AUGUST 2025
510
Ransomware
22 Aug 2025 • Orange
Orange SA: Ransomware Hack Hit Orange Telecom, Data Published on Dark Web
Orange Telecom Hit by Warlock Ransomware Attack, Customer Data Leaked on Dark Web
310
CRITICAL-200
ORA1770316673
Orange Telecom Hit by Warlock Ransomware Attack, Customer Data Leaked on Dark Web
In late July 2025, French telecommunications giant Orange SA disclosed a ransomware attack on its internal systems to national authorities. The breach, attributed to the cybercriminal group Warlock, resulted in the theft of business customer data, approximately 4GB of which was published on the dark web in mid-August.
The attack targeted Orange’s infrastructure, though specific details about the compromised systems remain undisclosed. The incident highlights the ongoing threat posed by ransomware gangs to critical infrastructure providers. Orange, headquartered in Paris, has not publicly commented on the ransom demands or the full extent of the data exposed.
The breach underscores the persistent risks faced by major corporations, particularly in sectors handling sensitive customer information. Authorities are likely investigating the incident as part of broader efforts to combat cybercrime.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JULY 2025
611
Ransomware
01 Jul 2025 • Orange
Orange: Telecom sector sees steady rise in ransomware attacks
Telecom Sector Cyber Incidents and Ransomware Surge (2022-2025)
496
CRITICAL-115
ORA1767980221
Telecom Sector Faces Surge in Ransomware Attacks, Data Theft in 2025
The telecom industry has become a prime target for cybercriminals, with ransomware attacks quadrupling from 24 incidents in 2022 to 90 in 2025, according to a recent threat intelligence report by Cyble. The sector’s critical role in national infrastructure and its vast stores of subscriber data make it a lucrative target for hackers, who exploit vulnerabilities in internet-facing systems and third-party dependencies.
In late 2025, cybercriminals advertised stolen administrator credentials for a major U.S. telecom firm on the dark web for $4,000. The DragonForce ransomware gang also claimed to have exfiltrated over five terabytes of data from another U.S. telecom provider, though no evidence was provided. Cyble identified 444 data theft incidents in the sector, including 133 listings of stolen databases containing sensitive customer and operational information.
The majority of attacks in 2025 were attributed to a handful of ransomware groups, with Qilin leading, followed by Akira and Play. High-profile victims included British telecom giant Orange. Roughly 70% of attacks targeted companies in the Americas, with Europe, Asia-Pacific, and the Middle East and Africa also affected.
Cyble’s report highlighted that many attacks were enabled by the rapid exploitation of zero-day vulnerabilities in network equipment. Nation-state hackers and hacktivist groups further compounded the threat, using DDoS attacks and website defacements to disrupt operations. The telecom sector’s security posture remains a concern for businesses across industries, given its role in enabling secure communications.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MARCH 2025
681
Ransomware
01 Mar 2025 • Orange
Orange
Orange Telecommunications Breach by Babuk Ransomware
603
CRITICAL-78
ORA625031825
Major telecommunications provider Orange suffered a severe security breach by the Babuk ransomware gang, resulting in the theft of 4.5 TB of sensitive data. The compromised data includes customer records, email addresses, user data, source code, invoices, internal documents, contracts, employee details, credit cards, messages, call logs, and other personal information. This cyberattack has put both customers and the company at significant risk, impacting the confidentiality, integrity, and availability of valuable data.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JULY 2024
723
Breach
01 Jul 2024 • Orange
Orange Belgium
Orange Belgium Cyberattack Compromising Customer Data
667
CRITICAL-56
ORA529082025
Orange Belgium disclosed a cyberattack discovered in late July 2024, compromising data from 850,000 customer accounts. The breach exposed non-critical but sensitive personal information, including names, first names, telephone numbers, SIM card numbers, and PUK (Personal Unblocking Key) codes—8-digit security codes used to unblock SIM cards. The company confirmed that no passwords, email addresses, banking, or financial details were accessed. Upon detection, Orange Belgium blocked access to the affected system, reinforced security measures, and notified relevant authorities, filing an official complaint. Customers were alerted via email and SMS, with warnings to stay vigilant against potential phishing attempts via a dedicated webpage. The attack’s connection to a prior incident at parent company Orange Group (detected on July 25, with no confirmed customer data extraction) remains unconfirmed. The nature of the attack (e.g., method, perpetrator) was not disclosed.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JUNE 2024
767
Breach
16 Jun 2024 • Orange
French telecom operators: Data protection: key compliance updates (12 – 16 Jan)
French Telecom Operators Fined for Data Breaches
723
MEDIUM-44
ORA1768849235
French Telecom Operators Fined for Data Breaches as Global Privacy Regulations Tighten
French telecom operators have been hit with fines for data breaches, underscoring heightened enforcement of data protection laws in Europe. The penalties, issued by France’s National Commission on Information and Liberties (CNIL), reflect stricter scrutiny under the GDPR, which mandates robust security measures and timely breach notifications.
Meanwhile, Taiwan’s AI Basic Act officially took effect, establishing a legal framework for artificial intelligence that balances innovation with privacy protections. The law introduces guidelines for AI development, including transparency and accountability requirements for organizations handling personal data.
In China, the Cyberspace Administration has launched a public consultation on proposed rules for personal information collection, signaling further regulatory evolution in data governance. The draft aims to refine existing privacy laws, potentially imposing new compliance obligations on businesses operating in the region.
These developments coincide with broader global shifts in data protection:
- Kentucky’s Consumer Data Protection Act (2024) has come into force in the U.S., expanding state-level privacy rights for residents.
- The UK’s Information Commissioner’s Office (ICO) and California’s Privacy Protection Agency continue to enforce stringent breach response protocols, with updated guidance for organizations.
- The Taiwan Financial Supervisory Commission and U.S. Federal Trade Commission (FTC) are also ramping up oversight, reflecting a trend toward cross-border regulatory alignment.
The fines in France and the rollout of Taiwan’s AI Act highlight the growing intersection of cybersecurity, privacy, and emerging technologies, with regulators prioritizing both enforcement and proactive compliance. Organizations face increasing pressure to adapt to evolving legal landscapes or risk significant penalties.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
JANUARY 2024
774
Cyber Attack
01 Jan 2024 • Orange
Orange
Hack Targeting Orange's Spanish Business
760
HIGH-14
ORA214221124
An unknown number of consumers were unable to access specific websites as a result of a hack that targeted Orange's Spanish business, a telecom operator.
Orange successfully identified and neutralised the majority of the unauthorised access to its IP network coordination centre.
The French corporation said that there was no risk to client data in a message posted on the social networking platform X.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
MARCH 2022
763
Cyber Attack
01 Mar 2022 • Orange
Orange
Cyber Attack on Orange and Nordnet
749
CRITICAL-14
ORA2548322
The cyber attackers targeted Orange and its subsidiary internet provider Nordnet in France.
The cyberattack affected thousands of internet users across Europe amid the Ukraine-Russia war.
Nearly 9,000 subscribers were affected by this internet outage.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
JULY 2020
814
Ransomware
01 Jul 2020 • Orange
Orange
Orange S.A. Nefilim Ransomware Attack
738
CRITICAL-76
ORA2911822
French telecommunications company Orange S.A.was targeted by a Nefilim ransomware group which resulted in data loss.
The company's security team was mobilized to identify the origin of the attack and put in place all necessary solutions required to ensure the security of its systems.
The data from about 20 customers on its virtual hosting service was accessed by those behind the ransomware attack.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Orange ??
What was Orange's A.I Rankiteo Cyber Score in May 2026 ??
What was Orange's A.I Rankiteo Cyber Score in April 2026 ??
What was Orange's A.I Rankiteo Cyber Score in March 2026 ??
What was Orange's A.I Rankiteo Cyber Score in February 2026 ??
What was Orange's A.I Rankiteo Cyber Score in January 2026 ??
What was Orange's A.I Rankiteo Cyber Score in December 2025 ??
What was Orange's A.I Rankiteo Cyber Score in November 2025 ??
What was Orange's A.I Rankiteo Cyber Score in October 2025 ??
What was Orange's A.I Rankiteo Cyber Score in September 2025 ??
What was Orange's A.I Rankiteo Cyber Score in August 2025 ??
What was Orange's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on Orange's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Orange ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Orange's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?