The largest personal data incident ever disclosed in France, and in Europe by headcount, is the France Travail breach, which exposed data on up to 43 million people in early 2024. This ranked list covers the 20 biggest and most consequential French data breaches, current as of July 2026, from that record-setting incident to the 2026 wave of public sector and telecom compromises.
France has become the most heavily breached large jurisdiction in Europe by volume of exposed records, and the Commission Nationale de l'Informatique et des Libertés (CNIL) logged 6,167 personal data breach notifications in 2025. Each entry below gives the records affected, key dates, sector, attack vector, data exposed, and aftermath, with source links. Where a figure is disputed, estimated, or claimed only by the attacker, that flag is preserved so you can weigh it accurately.
The common thread running through France's biggest breaches isn't an exotic zero-day. It's the abuse of legitimate access. Attackers keep reaching population-scale datasets by taking over the accounts, portals, and suppliers that already hold the keys, which is a far cheaper path than breaking cryptography or chaining novel exploits.
The pattern repeats across sectors. France Travail was breached through social-engineered partner accounts, Viamedis and Almerys through phished healthcare portals, Free and Bouygues Telecom through compromised subscriber management tools, and France Titres through an insecure direct object reference (IDOR) flaw in a public portal. Across 2024 to 2026, at least seven separate incidents each affected more than five million people.
Concentration risk turns single failures into national ones. Mid-sized intermediaries and software suppliers like Viamedis, Almerys, and Harvest hold data on behalf of hundreds of controllers, so one intrusion cascades into dozens of downstream notifications. Continuous monitoring of your third-party ecosystem and external attack surface is what surfaces that exposure before an attacker reaches it.
The CNIL received 6,167 personal data breach notifications in 2025, up from 5,629 in 2024. Around one in two notified breaches in 2025 involved hacking, now the most common cause ahead of human error.
Enforcement reached a record scale. The CNIL issued approximately €487 million in fines in 2025, the highest annual total in its history and close to nine times the 2024 figure. Two decisions accounted for €475 million of that total, namely €325 million against Google and €150 million against Shein; excluding those two, the remaining 2025 sanctions totalled around €12 million. Cybersecurity accounted for roughly one third of CNIL inspections and close to 30% of sanctions in 2025.
The CNIL's reference decisions are dominated by advertising and cookie consent cases: Google at €325 million (2025), Shein at €150 million (2025), and, in an unrelated matter, Orange at €50 million (2024) for inserting advertising among emails without consent. The 2022 Dedalus Biologie fine of €1.5 million remains a landmark because it targeted a data processor rather than a controller.
Two 2026 decisions tie enforcement directly to breaches in this list. The CNIL fined France Travail €5 million on January 22, 2026 under Article 32 of the General Data Protection Regulation (GDPR), where €10 million is the maximum for a public body. Days earlier, on January 13, 2026, it fined Free Mobile €27 million and Free €15 million, €42 million in total, over the October 2024 breach. Cumulatively the CNIL has issued more than €1 billion in fines since GDPR came into force.
The list runs roughly from the largest French incidents by scale and consequence down to smaller or less certain cases. Attacker-claimed and estimated figures are flagged in place.
Records affected: Up to 43 million people. This is France Travail's own maximum exposure figure, not a confirmed exfiltration count.
Date of breach: February 6 to March 5, 2024
Date disclosed: March 13, 2024
Country: France
Sector: Government / public employment
Attack vector: Impersonation of Cap Emploi advisers to obtain and abuse legitimate credentials for the jobseeker database
Data exposed: Name, date and place of birth, social security number, France Travail identifier, email address, postal address, and telephone number. Bank details and passwords were not affected.
Attackers posing as staff at partner organisation Cap Emploi queried France Travail's jobseeker database over roughly a month, potentially exposing identity records including social security numbers for everyone registered as a jobseeker in the preceding 20 years. The striking detail is the absence of any technical exploitation. The entire breach was achieved by abusing a legitimate partner access channel, which is the central lesson for anyone who grants third parties standing access to a sensitive system.
Aftermath: Reported to the CNIL and to the Paris prosecutor's cybercrime unit (J3), with three suspects arrested in March 2024. Several French firms and consumer groups announced collective claims. The CNIL fined France Travail €5 million on January 22, 2026, finding it had not implemented technical and organisational measures that could have made the attack more difficult.
Source: CNIL fine decision, Help Net Security
Records affected: More than 33 million people combined, confirmed by the CNIL. This is France's largest health related data breach.
Date of breach: Late January 2024 (Viamedis), early February 2024 (Almerys)
Date disclosed: February 1, 2024 (Viamedis), February 7, 2024 (Almerys); CNIL statement February 7, 2024
Country: France
Sector: Complementary health insurance / third-party payment operators
Attack vector: Phishing and compromise of healthcare professionals' portal credentials at both operators independently within days of each other
Data exposed: Marital status, date of birth, social security number, name of the health insurer, and the guarantees held under the policy. No bank details, no medical data, no reimbursement data, and no contact details.
Two third-party payment operators that handle tiers payant processing for dozens of French insurers and mutuelles were each breached through compromised health professional accounts, exposing insurance and identity records for over half the French population. The CNIL confirmed the combined 33 million figure on February 7, 2024. This is the definitive European example of concentration risk in mid-sized sector intermediaries that hold data on behalf of hundreds of controllers.
Aftermath: The CNIL opened investigations into both operators on February 7, 2024, focused on Article 32 security obligations and the appropriateness of authentication for professional access, and required direct notification of affected individuals. Multiple collective actions launched. No public CNIL fine as of July 2026.
Source: BleepingComputer, Le Monde
Records affected: Around 19.2 million subscriber accounts, of which approximately 5.11 million included an International Bank Account Number (IBAN). Free confirmed the breach and the presence of IBANs; the precise counts derive from analysis of the auctioned dataset and should be treated as well corroborated estimates rather than company confirmed figures.
Date of breach: Around October 21 to 25, 2024
Date disclosed: October 25 to 26, 2024
Country: France
Sector: Telecommunications
Attack vector: Unauthorised access to a subscriber management tool, then exfiltration and auction of the dataset on a cybercrime forum
Data exposed: Name, email address, postal address, telephone number, date and place of birth, subscription details, and IBAN for a large subset. Free stated card numbers and passwords were not affected.
France's second largest internet service provider confirmed that an attacker had reached a subscriber management tool and taken data covering most of its customer base, including bank account identifiers for around a quarter of subscribers. IBAN exposure at that scale converts a phishing risk into a direct debit fraud risk, and French banks issued specific guidance. It cemented 2024 as the year French telecoms customer data was compromised at population scale.
Aftermath: A criminal complaint was filed and the CNIL notified, and a suspect was arrested in France in November 2024. UFC Que Choisir and multiple law firms launched collective claims. On January 13, 2026, the CNIL fined Free Mobile €27 million and Free €15 million, €42 million in total, citing weak VPN authentication and inadequate security measures on the day of the breach.
Source: CNIL sanction decision, BleepingComputer
Records affected: 11.7 million accounts. The Interior Ministry disclosed the breach on April 20, 2026, and the agency confirmed the 11.7 million figure on April 24, 2026. Early reporting cited "up to 10 million," and the suspect claimed a database of 18 to 19 million records for sale; that larger figure is unverified.
Date of breach: Intrusion detected April 15, 2026
Date disclosed: April 20, 2026 (agency announcement), with confirmation of scale on April 24, 2026
Country: France
Sector: Government / identity documents
Attack vector: An IDOR flaw in the moncompte.ants.gouv.fr user portal API, allowing another user's file to be retrieved by altering an identifier in a request
Data exposed: Names, email addresses, dates of birth, and telephone numbers associated with accounts used for passports, national identity cards, driving licences, and vehicle registration documents
A trivial authorisation flaw in the portal of the agency that issues France's identity and vehicle documents exposed 11.7 million accounts, roughly one in six French residents. A 15-year-old suspect using the handle breach3d was arrested on April 25, 2026, ten days after detection. The France Titres site was taken offline for an extended period, disrupting vehicle registration and licence services nationally into May 2026.
Aftermath: Notified to the CNIL and referred to prosecutors, with one arrest. The service outage extended into May 2026, with workarounds for carte grise applications, and parliamentary scrutiny of public sector application security followed. No CNIL sanction published as of July 2026.
Source: BleepingComputer, Franceinfo
Records affected: 6.4 million customers, confirmed by Bouygues Telecom. Some early reports cited 5.7 million; 6.4 million is the company's own figure and supersedes it.
Date of breach: August 4, 2025
Date disclosed: August 6, 2025
Country: France
Sector: Telecommunications
Attack vector: Unauthorised third party access to systems holding customer account data; Bouygues said it blocked the access and strengthened monitoring
Data exposed: Contact details, contractual data, civil status details, company data for business customers, and IBANs. Bouygues stated card numbers and account passwords were not included.
The third of France's four major mobile operators to be breached in under a year, Bouygues Telecom confirmed that 6.4 million customers had data taken, including IBANs. Taken together with Free in 2024, SFR in 2024 and 2025, and Orange in 2025, essentially the entire French mobile subscriber base has now had account data exposed at least once. The repetition, rather than any single incident, is what makes the French telecoms sequence significant.
Aftermath: Notified to the CNIL and to the national cybersecurity agency (ANSSI), with a criminal complaint filed. All affected customers were notified by email or SMS. The CNIL has flagged telecoms sector security as a priority. No public fine as of July 2026.
Source: BleepingComputer, Infosecurity Magazine, TechCrunch
Records affected: Up to 27 million records claimed by the attacker using the handle Horror404x. Boulanger acknowledged a breach but disputed the scale, indicating a far smaller number of customers were genuinely affected. The 27 million figure is an attacker claim and unverified; treat it with caution.
Date of breach: Early September 2024
Date disclosed: September 8 to 10, 2024
Country: France
Sector: Retail / consumer electronics
Attack vector: Compromise of a shared third party service linked to delivery and order systems used by several French retailers
Data exposed: Names, postal addresses, email addresses, telephone numbers, and order or delivery details. No payment card data was reported as taken.
Boulanger was the largest named victim in a September 2024 campaign by a single actor against a shared retail delivery vendor, which also hit Cultura, Truffaut, and others in the same week. The wide gap between the attacker's claimed 27 million records and the retailer's own assessment shows how inflated leak-site claims distort French breach statistics. The delivery address exposure carried real-world targeting risk beyond phishing.
Aftermath: Notified to the CNIL, with a criminal complaint filed. French media traced the campaign to a common upstream supplier, and the CNIL used the September 2024 retail wave in its subsequent guidance on subcontractor security. No fine published as of July 2026.
Source: Have I Been Pwned, Degrouptest summary of the French retail wave
Records affected: A September 2024 breach reported to affect around 1.4 million customers, followed by a November 2024 resale in which a subset of the data, including banking details, was offered for sale. Both counts should be treated as reported rather than company confirmed.
Date of breach: September 2024, with the data resold in November 2024
Date disclosed: September 2024 and November 2024
Country: France
Sector: Telecommunications
Attack vector: Unauthorised access to a customer management platform in September 2024. French media attributed the later resale to a single actor who also breached Direct Assurance, Le Point, and the Mediboard medical software platform, exploiting weakly secured application access.
Data exposed: Names, contact details, contract data, and, in the resold dataset, IBAN banking details
SFR customer data surfaced twice within months, and the second wave exposed banking identifiers. French reporting linked the resale to a single prolific actor who also breached the insurer Direct Assurance, the magazine Le Point, and the Mediboard medical software platform, demanding comparatively small ransoms. The pattern shows a low sophistication actor achieving repeated high impact results against large French brands.
Aftermath: Both events were notified to the CNIL with criminal complaints filed. The wave attracted CNIL attention specifically because the same vector recurred across multiple controllers. No public fine as of July 2026.
Source: Clubic on the linked intrusions
Records affected: Not quantified as a personal data count. Orange disclosed a cyberattack on internal systems, and the Warlock group published around 4 GB of data on the dark web in mid August 2025. Any customer headcount is unverified.
Date of breach: Detected late July 2025 (disclosed to customers July 29, 2025)
Date disclosed: End of July 2025, with data publication in mid August 2025
Country: France
Sector: Telecommunications
Attack vector: Ransomware associated with the Warlock group against Orange internal systems, prompting Orange to isolate affected services
Data exposed: Internal corporate data published by the attackers. Orange stated the intrusion affected an internal management platform, and the nature of any customer data in the leaked 4 GB was not fully characterised publicly.
Orange told customers to expect service disruption while it isolated systems following a ransomware intrusion, then saw roughly 4 GB of data published on the dark web weeks later. Coming days before the Bouygues Telecom breach, it made mid 2025 the point at which French telecoms security became a political issue. One important clarification: Orange's separate €50 million CNIL fine in 2024 was for unrelated advertising and cookie violations, not this incident, and the two are frequently and incorrectly conflated.
Aftermath: Reported to ANSSI and to the CNIL, with a criminal complaint filed. Separately, and unrelated to this incident, the CNIL fined Orange €50 million in 2024 for inserting advertising among emails without consent and continuing to read cookies after consent withdrawal.
Source: CNIL on the €50 million Orange fine, The Record, Insurance Journal on the ransomware
Records affected: Between 1.5 million and 2.6 million accounts, per reporting on the attacker's claims. Not confirmed by Cultura; treat as an estimate range.
Date of breach: Early September 2024
Date disclosed: September 2024
Country: France
Sector: Retail / books, culture, and leisure
Attack vector: The same September 2024 campaign as Boulanger, via a shared third party delivery or order service
Data exposed: Names, email addresses, postal addresses, telephone numbers, and order history
Cultura was hit in the same week as Boulanger and Truffaut by the actor Horror404x, who appeared to have compromised a supplier common to multiple French retail chains. The clustering of three well known retail brands within days made the September 2024 wave the moment French consumers began to see breach notifications as routine. Cultura notified customers and advised vigilance against phishing.
Aftermath: Notified to the CNIL, with a criminal complaint filed. Included in French media and CNIL analysis of the shared subcontractor as the common cause. No fine published as of July 2026.
Source: SafetyDetectives, Degrouptest
Records affected: Around 270,000 accounts, per reporting on the attacker's claims. Not company confirmed.
Date of breach: Early September 2024
Date disclosed: September 2024
Country: France
Sector: Retail / garden centres
Attack vector: The same September 2024 shared supplier campaign
Data exposed: Names, contact details, postal addresses, and order data
The garden retail chain Truffaut was the smallest of the three named victims in the September 2024 Horror404x campaign, at around 270,000 accounts. Its inclusion matters because it demonstrated the campaign's method was indiscriminate across the supplier's whole client list rather than targeted at large brands. Customers were notified and warned about phishing.
Aftermath: Notified to the CNIL. No fine published as of July 2026.
Source: SafetyDetectives, Degrouptest
Records affected: Several hundred thousand loyalty programme customers. Auchan notified affected customers without publishing a total; specific figures circulating are unverified.
Date of breach: November 2024
Date disclosed: November 21 to 22, 2024
Country: France
Sector: Retail / grocery
Attack vector: Unauthorised access to loyalty programme customer data
Data exposed: Name, postal address, email address, telephone number, date of birth, family composition, and loyalty card number. Auchan stated no bank data or passwords were affected.
Auchan notified loyalty scheme members that their household and contact data had been accessed, adding a grocery giant to the 2024 sequence of French retail breaches. The exposure of family composition data alongside addresses was unusual and raised concerns about targeting of households with children. It came weeks after Free and days before further French retail disclosures.
Aftermath: Notified to the CNIL, with a criminal complaint filed. Auchan advised customers to watch for phishing. No fine published as of July 2026.
Source: CSIDB incident record, Degrouptest
Records affected: Reported in the tens of thousands of loyalty customers. Picard notified affected customers; no authoritative total was published, so any figure is unverified.
Date of breach: November 2024
Date disclosed: November 2024
Country: France
Sector: Retail / frozen food
Attack vector: Unauthorised access to loyalty programme data
Data exposed: Names, contact details, and loyalty account information
Frozen food retailer Picard disclosed a loyalty data breach in the same November 2024 window as Auchan, contributing to the perception of a coordinated wave against French retail loyalty databases. The individual scale was modest, but the timing amplified public concern. Picard notified customers directly and warned about phishing.
Aftermath: Notified to the CNIL. No fine published as of July 2026.
Source: Degrouptest
Records affected: Not officially quantified. French reporting placed it in the tens of thousands of customers and prospects. Treat any figure as unverified.
Date of breach: Late 2024
Date disclosed: November 2024
Country: France
Sector: Insurance (motor)
Attack vector: Attributed by French media to the same actor behind the SFR, Le Point, and Mediboard intrusions, exploiting weakly secured application access
Data exposed: Identity data, contact details, and insurance quotation or contract data including, in some cases, driving licence and vehicle information
The AXA owned direct motor insurer was one of several French organisations breached in late 2024 by a single actor who demanded unusually small ransoms across a string of victims. Insurance quotation data is particularly sensitive because it combines identity, address, vehicle, and sometimes claims history in one record. The case is a marker of how a single low sophistication actor produced a national scale problem across unrelated sectors.
Aftermath: Notified to the CNIL with a criminal complaint filed, and affected customers notified. The linked series of intrusions became a CNIL supervisory focus. No fine published as of July 2026.
Source: Clubic
Records affected: Not quantified publicly. Harvest serves around 4,600 clients including banks, insurers, investment funds, and family offices. Downstream victims that confirmed exposure include MAIF and the BPCE group (Banque Populaire and Caisse d'Epargne). Individual counts were not published.
Date of breach: Night of February 26 to 27, 2025
Date disclosed: March 2025, via notifications from downstream clients including MAIF and BPCE
Country: France
Sector: Software for wealth management and financial advice
Attack vector: Exploitation of a vulnerability in the information system of one of Harvest's hosting providers, then lateral access to client data
Data exposed: Wealth management and financial advisory client data, including identity data, contact details, and financial situation information held by insurers and banks using Harvest software
Harvest supplies the wealth management and financial planning software used across much of the French banking and insurance sector, so a single intrusion at one of its hosting providers propagated into notifications from MAIF, BPCE, and other major institutions. The financial profiling nature of the data, covering assets, income, and family situation, makes it unusually valuable for targeted fraud. This is France's clearest fourth party supply chain breach, since the initial compromise was at Harvest's own supplier.
Aftermath: Harvest and each affected financial institution notified the CNIL separately, and French insurance and banking supervisors reviewed exposure. The incident is cited in French sector guidance on assessing subcontractors of subcontractors. No fine published as of July 2026.
Source: La Tribune de l'Assurance
Records affected: 491,840 people, confirmed by the CNIL. This is the figure commonly rounded to "around 500,000 patient records."
Date of breach: Data covering tests carried out between 2015 and 2020; the file appeared online in February 2021
Date disclosed: February 2021, with the CNIL sanction decision on April 15, 2022
Country: France
Sector: Healthcare software (medical laboratory information systems)
Attack vector: An insecure server at the software provider, which had extracted and retained a bulk data file during a software migration for laboratory clients. The CNIL found Dedalus had been warned about the server's vulnerabilities beforehand.
Data exposed: First and last name, social security number, prescribing doctor, examination date, and highly sensitive medical data including HIV status, cancer diagnoses, genetic diseases, pregnancies, medications, and genetic data, covering 28 laboratories across several departments
A bulk file of medical test results for 491,840 French patients, including HIV status and genetic data, was published online after the software provider that had extracted it during a migration left it on an inadequately secured server. It remains the most sensitive health data leak in French history by data type, even though its headcount is far below Viamedis and Almerys. The CNIL's decision established that a processor can be fined directly for its own Article 28, 29, and 32 failures.
Aftermath: The CNIL fined Dedalus Biologie €1.5 million on April 15, 2022 (deliberation SAN-2022-009) for breaches of GDPR Articles 28, 29, and 32, one of the first significant European fines imposed on a processor rather than a controller. Criminal proceedings followed against those who published the file.
Source: CNIL sanctions register, Orrick analysis
Records affected: Around 229 million user records in the leaked dataset, reduced from roughly 257 million rows to approximately 229 million unique records after deduplication by Have I Been Pwned. Deezer confirmed the data originated from a third party partner and was dated 2019.
Date of breach: 2019 (data date), leaked publicly November 2022
Date disclosed: November 2022, with Deezer confirmation and Have I Been Pwned loading in early January 2023
Country: France
Sector: Music streaming
Attack vector: Exposure at a third party service provider that had been given a copy of Deezer user data for testing or analytics purposes
Data exposed: Email addresses, usernames, dates of birth, gender, IP addresses, geographic location, and account creation dates. Deezer stated no passwords or payment data were included.
The Deezer leak is the largest French originated dataset by record count, exposing account and profile data for roughly 229 million users worldwide from a copy held by a partner in 2019. Deezer's disclosure that the data had been at a third party underlines that the largest French breach by raw records was not a breach of the company's own production systems. The absence of passwords limited direct account takeover risk, but the dataset remains a credential stuffing and profiling resource.
Aftermath: Notified to the CNIL. Deezer said it had terminated the partner relationship and reviewed its data sharing, and the dataset was loaded into Have I Been Pwned in January 2023. No public CNIL fine as of July 2026.
Source: Have I Been Pwned, Music Business Worldwide
Records affected: 6,128 appointments in the July 2020 incident. A separate 2020 research finding concerned exposure of appointment metadata. Larger figures sometimes attributed to Doctolib are not supported by the company's disclosures and should be treated as unverified.
Date of breach: July 2020
Date disclosed: July 21, 2020
Country: France
Sector: Healthcare / online medical appointment booking
Attack vector: Unauthorised access to a management interface, described by Doctolib as exploitation of a technical means to access appointment data
Data exposed: Patient name, telephone number, email address, and the appointment (practitioner and time) for 6,128 appointments. Doctolib stated no medical records, no comments, and no bank details were exposed.
Doctolib disclosed that an attacker had accessed the details of 6,128 appointments, a small number in absolute terms but significant because the practitioner identity alone can reveal sensitive health information such as a consultation with an oncologist or psychiatrist. The case is included because Doctolib holds appointment data for tens of millions of French patients and became a focal point for French debate on health data hosting, including a separate 2020 controversy over its use of Microsoft Azure. It demonstrates that metadata alone can constitute special category data.
Aftermath: Notified to the CNIL and affected individuals, with one arrest reported. Doctolib's health data hosting arrangements were separately challenged before the Conseil d'Etat in 2020, which declined to suspend them subject to safeguards. No fine.
Source: Le Monde
Records affected: Approximately 1.5 million email addresses and around 696,000 customer records, as confirmed by Have I Been Pwned and security researchers.
Date of breach: April 2024
Date disclosed: April 18, 2024 (company learned of the breach April 15, 2024)
Country: France
Sector: Retail / apparel
Attack vector: Unauthorised access to customer account data on the e-commerce platform
Data exposed: Names, email addresses, postal addresses, telephone numbers, and order numbers. No passwords or payment card data were affected.
The French underwear brand Le Slip Français disclosed in April 2024 that an attacker had accessed customer data, exposing around 1.5 million email addresses and approximately 696,000 customer records. The breach was loaded into Have I Been Pwned, confirming its scope. It demonstrates that mid-market direct-to-consumer brands face the same notification obligations and reputational exposure as larger retailers.
Aftermath: Notified to the CNIL and to customers. No CNIL sanction published as of July 2026.
Source: Have I Been Pwned, Bitdefender
Records affected: Up to 37.8 million customer records claimed by the threat actor advertising the data. This is an attacker claim and was not confirmed by ManoMano; treat it as unverified.
Date of breach: Claimed February 2026
Date disclosed: February 2026 (via a criminal forum listing)
Country: France
Sector: E-commerce / DIY and home improvement
Attack vector: Not established publicly
Data exposed: Claimed to include identity data, contact details, and administrative information
A threat actor advertised a dataset it claimed contained up to 37.8 million ManoMano customer records, which would make it one of the largest French e-commerce exposures on record if confirmed. Because the only source is the seller's own listing, the figure should not be presented as established. It is included here because it is widely cited in 2026 French breach roundups and readers will expect it to be addressed.
Aftermath: No confirmed regulatory action or company confirmation identified. This entry should be treated as an unverified claim pending primary confirmation from ManoMano and the CNIL.
Source: No authoritative source located; secondary aggregation only.
Several large 2026 French public sector breaches are circulating widely in French language aggregator sources but could not be corroborated against a primary or tier one source. Each is listed here with its claimed figures flagged as unverified.
To confirm any of these, check CNIL press releases, ANSSI advisories, the relevant ministry newsroom, and Le Monde or Next for French language confirmation.
Source: CNIL press releases, ANSSI
The French sequence points to a short list of controls that would have blunted most of these incidents: phishing-resistant authentication on partner and employee portals, strict governance of third-party and supplier access, continuous dark web and attack surface monitoring, and readiness to meet the CNIL's 72-hour notification deadline. The organisations that fared worst weren't missing firewalls; they were missing visibility into who could reach their data and how.
That's the gap the UpGuard platform is built to close:
Start a free trial to see your exposure across your own attack surface and your vendor ecosystem.
The France Travail breach is the largest, exposing personal data on up to 43 million people between February and March 2024. It is also the largest personal data incident ever disclosed in France or Europe by headcount.
Yes. The CNIL fined France Travail €5 million on January 22, 2026 under Article 32 of the GDPR for failing to implement adequate security measures.
Free and Free Mobile (2024), Bouygues Telecom (2025), SFR (2024 and 2025), and Orange (2025) all confirmed breaches, meaning nearly the entire French mobile subscriber base has had account data exposed at least once.
The CNIL received 6,167 personal data breach notifications in 2025, up from 5,629 in 2024, with around half involving hacking.