Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Orange

Orange Vendor Cyber Rating & Cyber Score

orange.com

Orange is one of the world’s leading telecommunications operators with revenues of 40.3 billion euros in 2024 and 127,000 employees worldwide at 31 December 2024, including 71,000 employees in France. The Group has a total customer base of 291 million customers worldwide at 31 December 2024, including 253 million mobile customers and 22 million fixed broadband customers. The Group is present in 26 countries. Orange is also a leading provider of global IT and telecommunication services to multinational companies under the brand Orange Business. In February 2023, the Group presented its strategic plan « Lead the future », built on a new business model and guided by responsibility and efficiency. « Lead the future » capitalizes on network


Orange A.I CyberSecurity Scoring

Orange
Company Information
Website:https://www.orange.com
Employees number:135,828
Number of followers:1,194,818
NAICS:517
Industry Type:Telecommunications
Homepage:orange.com
Orange Risk Score (AI oriented)
Between 0 and 549
logo
OrangeTelecommunications
Updated:
01/05/2026
397/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Orange Global Score (TPRM)
xxxx
logo
OrangeTelecommunications
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Orange
OrangeCritical
Current Score
397C (CRITICAL)
01000
10 incidents
-91.75 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
412Before Incident
MAY 2026
402Before Incident
APRIL 2026
399Before Incident
MARCH 2026
373Before Incident
FEBRUARY 2026
360Before Incident
JANUARY 2026
350Before Incident
DECEMBER 2025
334Before Incident
NOVEMBER 2025
330Before Incident
OCTOBER 2025
319Before Incident
SEPTEMBER 2025
313Before Incident
Cyber Attack
01 Sep 2025Orange
Orange Belgium

Cyberattaque ciblant Orange Belgium avec risque de vol de numéros de téléphone

305After Incident
HIGH-8
ORA814090225
Orange Belgium, a major telecom operator, suffered a cyberattack targeting its IT systems, raising concerns over potential theft of customer phone numbers. The attack exposed vulnerabilities where fraudsters could exploit stolen customer data to impersonate legitimate users and hijack phone numbers via SIM-swap fraud. Once in control of a victim’s number, attackers could intercept verification codes (e.g., for password resets, email, social media, or payment systems), enabling broader fraudulent activities like account takeovers or financial theft. The Belgian telecom regulator (IBPT) responded by mandating an additional verification step—sending an SMS alert to customers for any number-transfer requests, allowing them to block unauthorized changes by replying 'STOP'. While no large-scale data breach (e.g., financial or sensitive personal records) was confirmed, the attack disrupted trust in Orange’s security, forced operational changes, and posed reputational and financial risks due to potential downstream fraud. Customers were urged to enable multi-factor authentication and scrutinize suspicious communications, highlighting the attack’s secondary impact on user behavior and operational processes.
INCIDENT DETAILS -
TYPE
CyberattaqueUsurpation d'identitéFraude par transfert de numéro (SIM swapping)
MOTIVATION
Fraude financièreVol d'identitéAccès non autorisé à des comptes en ligne
IMPACT
Données personnelles des clients (non précisées)Numéros de téléphoneSystèmes informatiques d'Orange Belgium (partiellement)Procédures de transfert de numéroRenforcement des contrôles de sécurité pour les transferts de numéroCommunication accrue avec les clientsRisque de perte de confiance des clientsNécéssité de mesures correctives publiquesÉlevé (vol de numéros de téléphone pour usurpation d'identité)Risque accru via l'accès aux codes de vérification envoyés par SMS
DATA BREACH
Données personnelles (non détaillées)Numéros de téléphoneSensitivity Of Data: Élevée (risque d'usurpation d'identité et de fraude)Data Exfiltration: Probable (utilisation des données par des escrocs)Numéros de téléphoneAutres données personnelles (non spécifiées)
AUGUST 2025
359Before Incident
Breach
23 Aug 2025Orange
Orange Romania, Orange Belgium and Orange: Ransomware hack hit Orange telecom, data published on dark web

Orange Hit by Ransomware Attack as Warlock Gang Leaks Stolen Business Data

315After Incident
HIGH-44
ORA1770804300
Orange Hit by Ransomware Attack as Warlock Gang Leaks Stolen Business Data French telecommunications giant Orange has confirmed a ransomware attack by the cybercriminal group Warlock, which resulted in the theft and publication of business customer data. The breach, disclosed to national authorities in late July, saw approximately four gigabytes of data posted to the dark web in mid-August. According to sources familiar with the incident, the attack targeted Orange’s internal systems using ransomware leased by Warlock a group known for providing its malware to other hackers in exchange for a cut of ransom payments. While Orange acknowledged the data leak, a spokesperson stated that the compromised information was "outdated or low-sensitivity" and that affected businesses were notified prior to the public release. The company is collaborating with authorities and impacted clients to mitigate the fallout. This incident marks the third major breach for Orange in 2024. In July, attackers accessed customer data from its Belgian division, while a separate attack exposed employee records from its Romanian operations on the dark web. Telecom providers remain prime targets for cybercriminals due to the vast amounts of financial, government, and corporate data they handle. The repeated attacks on Orange underscore the growing threat to critical infrastructure in the sector.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain
IMPACT
Data Compromised: 4 GBSystems Affected: Internal systemsBrand Reputation Impact: High
DATA BREACH
Type Of Data Compromised: Business customer dataSensitivity Of Data: Outdated or low-sensitivityData Exfiltration: Yes
AUGUST 2025
510Before Incident
Ransomware
22 Aug 2025Orange
Orange SA: Ransomware Hack Hit Orange Telecom, Data Published on Dark Web

Orange Telecom Hit by Warlock Ransomware Attack, Customer Data Leaked on Dark Web

310After Incident
CRITICAL-200
ORA1770316673
Orange Telecom Hit by Warlock Ransomware Attack, Customer Data Leaked on Dark Web In late July 2025, French telecommunications giant Orange SA disclosed a ransomware attack on its internal systems to national authorities. The breach, attributed to the cybercriminal group Warlock, resulted in the theft of business customer data, approximately 4GB of which was published on the dark web in mid-August. The attack targeted Orange’s infrastructure, though specific details about the compromised systems remain undisclosed. The incident highlights the ongoing threat posed by ransomware gangs to critical infrastructure providers. Orange, headquartered in Paris, has not publicly commented on the ransom demands or the full extent of the data exposed. The breach underscores the persistent risks faced by major corporations, particularly in sectors handling sensitive customer information. Authorities are likely investigating the incident as part of broader efforts to combat cybercrime.
INCIDENT DETAILS -
TYPE
Ransomware
IMPACT
Data Compromised: Business customer dataBrand Reputation Impact: Likely impacted
DATA BREACH
Type Of Data Compromised: Business customer dataData Exfiltration: 4GB of data published on the dark web
JULY 2025
611Before Incident
Ransomware
01 Jul 2025Orange
Orange: Telecom sector sees steady rise in ransomware attacks

Telecom Sector Cyber Incidents and Ransomware Surge (2022-2025)

496After Incident
CRITICAL-115
ORA1767980221
Telecom Sector Faces Surge in Ransomware Attacks, Data Theft in 2025 The telecom industry has become a prime target for cybercriminals, with ransomware attacks quadrupling from 24 incidents in 2022 to 90 in 2025, according to a recent threat intelligence report by Cyble. The sector’s critical role in national infrastructure and its vast stores of subscriber data make it a lucrative target for hackers, who exploit vulnerabilities in internet-facing systems and third-party dependencies. In late 2025, cybercriminals advertised stolen administrator credentials for a major U.S. telecom firm on the dark web for $4,000. The DragonForce ransomware gang also claimed to have exfiltrated over five terabytes of data from another U.S. telecom provider, though no evidence was provided. Cyble identified 444 data theft incidents in the sector, including 133 listings of stolen databases containing sensitive customer and operational information. The majority of attacks in 2025 were attributed to a handful of ransomware groups, with Qilin leading, followed by Akira and Play. High-profile victims included British telecom giant Orange. Roughly 70% of attacks targeted companies in the Americas, with Europe, Asia-Pacific, and the Middle East and Africa also affected. Cyble’s report highlighted that many attacks were enabled by the rapid exploitation of zero-day vulnerabilities in network equipment. Nation-state hackers and hacktivist groups further compounded the threat, using DDoS attacks and website defacements to disrupt operations. The telecom sector’s security posture remains a concern for businesses across industries, given its role in enabling secure communications.
INCIDENT DETAILS -
TYPE
ransomwaredata_breachinitial_access_broker
MOTIVATION
financial gainstrategic advantage over adversary nationsgeopolitical disruptionresale of customer data
IMPACT
Data Compromised: over five terabytes (claimed by DragonForce), sensitive customer data, operational information, subscriber data, U.S. wiretap targets informationtelecom infrastructurecustomer databasesnetwork equipmentOperational Impact: network disruptions, enterprise business operations disrupted for up to two weeksBrand Reputation Impact: highIdentity Theft Risk: high
DATA BREACH
customer datasubscriber dataoperational informationU.S. wiretap targets informationSensitivity Of Data: highData Exfiltration: yes (claimed by DragonForce)Personally Identifiable Information: yes
MARCH 2025
681Before Incident
Ransomware
01 Mar 2025Orange
Orange

Orange Telecommunications Breach by Babuk Ransomware

603After Incident
CRITICAL-78
ORA625031825
Major telecommunications provider Orange suffered a severe security breach by the Babuk ransomware gang, resulting in the theft of 4.5 TB of sensitive data. The compromised data includes customer records, email addresses, user data, source code, invoices, internal documents, contracts, employee details, credit cards, messages, call logs, and other personal information. This cyberattack has put both customers and the company at significant risk, impacting the confidentiality, integrity, and availability of valuable data.
INCIDENT DETAILS -
TYPE
Data Breach, Ransomware
IMPACT
customer recordsemail addressesuser datasource codeinvoicesinternal documentscontractsemployee detailscredit cardsmessagescall logsother personal information
DATA BREACH
customer recordsemail addressesuser datasource codeinvoicesinternal documentscontractsemployee detailscredit cardsmessagescall logsother personal informationSensitivity Of Data: HighData Exfiltration: YesPersonally Identifiable Information: Yes
JULY 2024
723Before Incident
Breach
01 Jul 2024Orange
Orange Belgium

Orange Belgium Cyberattack Compromising Customer Data

667After Incident
CRITICAL-56
ORA529082025
Orange Belgium disclosed a cyberattack discovered in late July 2024, compromising data from 850,000 customer accounts. The breach exposed non-critical but sensitive personal information, including names, first names, telephone numbers, SIM card numbers, and PUK (Personal Unblocking Key) codes—8-digit security codes used to unblock SIM cards. The company confirmed that no passwords, email addresses, banking, or financial details were accessed. Upon detection, Orange Belgium blocked access to the affected system, reinforced security measures, and notified relevant authorities, filing an official complaint. Customers were alerted via email and SMS, with warnings to stay vigilant against potential phishing attempts via a dedicated webpage. The attack’s connection to a prior incident at parent company Orange Group (detected on July 25, with no confirmed customer data extraction) remains unconfirmed. The nature of the attack (e.g., method, perpetrator) was not disclosed.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Customer names (first and last)Telephone numbersSIM card numbersPUK (Personal Unblocking Key) codesTariff plansAn IT system containing customer dataBrand Reputation Impact: Potential risk due to exposure of customer data and phishing warningsIdentity Theft Risk: Low (no critical data like passwords, emails, or financial details compromised, but PUK codes could enable SIM swapping)Payment Information Risk: None (no banking or financial details exposed)
DATA BREACH
Personal data (names, telephone numbers)SIM-related data (SIM card numbers, PUK codes)Service data (tariff plans)Number Of Records Exposed: 850,000Sensitivity Of Data: Moderate (no critical data like passwords or financial details, but PUK codes are sensitive)NamesTelephone numbers
JUNE 2024
767Before Incident
Breach
16 Jun 2024Orange
French telecom operators: Data protection: key compliance updates (12 – 16 Jan)

French Telecom Operators Fined for Data Breaches

723After Incident
MEDIUM-44
ORA1768849235
French Telecom Operators Fined for Data Breaches as Global Privacy Regulations Tighten French telecom operators have been hit with fines for data breaches, underscoring heightened enforcement of data protection laws in Europe. The penalties, issued by France’s National Commission on Information and Liberties (CNIL), reflect stricter scrutiny under the GDPR, which mandates robust security measures and timely breach notifications. Meanwhile, Taiwan’s AI Basic Act officially took effect, establishing a legal framework for artificial intelligence that balances innovation with privacy protections. The law introduces guidelines for AI development, including transparency and accountability requirements for organizations handling personal data. In China, the Cyberspace Administration has launched a public consultation on proposed rules for personal information collection, signaling further regulatory evolution in data governance. The draft aims to refine existing privacy laws, potentially imposing new compliance obligations on businesses operating in the region. These developments coincide with broader global shifts in data protection: - Kentucky’s Consumer Data Protection Act (2024) has come into force in the U.S., expanding state-level privacy rights for residents. - The UK’s Information Commissioner’s Office (ICO) and California’s Privacy Protection Agency continue to enforce stringent breach response protocols, with updated guidance for organizations. - The Taiwan Financial Supervisory Commission and U.S. Federal Trade Commission (FTC) are also ramping up oversight, reflecting a trend toward cross-border regulatory alignment. The fines in France and the rollout of Taiwan’s AI Act highlight the growing intersection of cybersecurity, privacy, and emerging technologies, with regulators prioritizing both enforcement and proactive compliance. Organizations face increasing pressure to adapt to evolving legal landscapes or risk significant penalties.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Financial Loss: Fines imposed
JANUARY 2024
774Before Incident
Cyber Attack
01 Jan 2024Orange
Orange

Hack Targeting Orange's Spanish Business

760After Incident
HIGH-14
ORA214221124
An unknown number of consumers were unable to access specific websites as a result of a hack that targeted Orange's Spanish business, a telecom operator. Orange successfully identified and neutralised the majority of the unauthorised access to its IP network coordination centre. The French corporation said that there was no risk to client data in a message posted on the social networking platform X.
INCIDENT DETAILS -
TYPE
Hack
IMPACT
IP network coordination centreConsumers unable to access specific websites
MARCH 2022
763Before Incident
Cyber Attack
01 Mar 2022Orange
Orange

Cyber Attack on Orange and Nordnet

749After Incident
CRITICAL-14
ORA2548322
The cyber attackers targeted Orange and its subsidiary internet provider Nordnet in France. The cyberattack affected thousands of internet users across Europe amid the Ukraine-Russia war. Nearly 9,000 subscribers were affected by this internet outage.
INCIDENT DETAILS -
TYPE
Cyber Attack
IMPACT
Systems Affected: Internet Services
JULY 2020
814Before Incident
Ransomware
01 Jul 2020Orange
Orange

Orange S.A. Nefilim Ransomware Attack

738After Incident
CRITICAL-76
ORA2911822
French telecommunications company Orange S.A.was targeted by a Nefilim ransomware group which resulted in data loss. The company's security team was mobilized to identify the origin of the attack and put in place all necessary solutions required to ensure the security of its systems. The data from about 20 customers on its virtual hosting service was accessed by those behind the ransomware attack.
INCIDENT DETAILS -
TYPE
Ransomware
IMPACT
Data Compromised: Data from about 20 customers on its virtual hosting service was accessed.

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Orange ?
?
What was Orange's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Orange's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Orange's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Orange's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Orange's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Orange's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Orange's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Orange's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Orange's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Orange's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Orange's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Orange's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Orange ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Orange's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?