Breach Intelligence

6,875

Total breached databases

In June 2026, the internal staff directory of INSEE (Institut national de la statistique et des études économiques), France's national statistics institute, hosted at trombi.insee.fr, allegedly suffered a data breach. Reports suggest the directory — reserved exclusively for INSEE personnel — was exposed, affecting approximately 13,000 employees. The compromised data allegedly included email addresses, full names, phone numbers, genders and job/assignment information. No passwords were included.
  • Date: Jun 2026
  • Domain: trombi.insee.fr
  • Threat Actor: Saturne
  • Country: France
  • Category: Government
  • Data: Email Addresses Names Phone Numbers Geographic Locations Genders Job Information
  • Records: 12,795
  • Lines: 12,795
  • Size: 16.78 MB
  • Passwords: No
PayTrip (paytrip.fr), a French prepaid-card and travel-money financial service, allegedly suffered a data breach that was reposted on a hacking forum in January 2026. Reports suggest the breach date is unknown. It has been reported that approximately 75,000 records were exposed, including email addresses, full names, dates of birth, phone numbers, physical and geographic locations, and bank account information such as IBANs and account balances. No passwords were included in the exposed data.
  • Date: 2026
  • Domain: paytrip.fr
  • Threat Actor: slvsh3r
  • Country: France
  • Category: Finance & Payments
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Bank Account Information Financial Information Balances Government IDs Birthdates Date of Death
  • Records: 74,876
  • Lines: 74,877
  • Size: 21.2 MB
  • Passwords: No
In June 2026, the French Hospital Federation (Fédération Hospitalière de France, fhf.fr) allegedly suffered a data breach. Reports suggest the site, which represents France's public healthcare and medico-social institutions and hosts a major job board for the public health sector, had approximately 30,000 records exposed. It has been reported that the compromised data included email addresses, names, phone numbers, genders and job-related information. No passwords were included.
  • Date: Jun 2026
  • Domain: fhf.fr
  • Threat Actor: Saturne
  • Country: France
  • Category: Healthcare
  • Data: Email Addresses Names Phone Numbers Geographic Locations Genders Job Information
  • Records: 30,727
  • Lines: 30,727
  • Size: 4.56 MB
  • Passwords: No
Rinaorc (rinaorc.com), a French Minecraft game server network, allegedly suffered a data breach. Reports suggest an AuthMe player database of approximately 1.4 million accounts was exposed, including usernames, email addresses, salted SHA-256 password hashes, and IP addresses.
  • Data: Email Addresses Passwords Usernames IP Addresses
  • Records: 1,463,240
  • Lines: 1,463,239
  • Size: 203.1 MB
  • Passwords: Hashed Salted, SHA-256 Salted
  • Cracked: 0%
At an unknown date, contact data belonging to Aqualter (aqualter.com) was allegedly leaked. Aqualter is an independent French company specializing in water management. It has been reported that a contact dataset covering approximately 273,000 individuals was exposed, split into roughly 86,000 email records and 187,000 phone records. Reports suggest the compromised information consisted of email addresses and phone numbers. No passwords were included in the exposed dataset.
  • Domain: aqualter.com
  • Threat Actor: ChimeraZ
  • Country: France
  • Category: Industry
  • Data: Email Addresses Phone Numbers Geographic Locations
  • Records: 320,932
  • Lines: 320,934
  • Size: 7.01 MB
  • Passwords: No
Sometime before 2025, a dataset of approximately 60,000 French government agents was allegedly compiled and published on a hacking forum. It has been reported that the records span numerous French state ministries and agencies — including Ecology, Justice, Interior, Defense, Finance, Foreign Affairs, Agriculture, Culture, Education, Customs, Civil Aviation, the Gendarmerie, Maritime Affairs and INSEE — rather than a single agency. The data was posted by an actor using the handle HexDex and allegedly exposed information on roughly 50,000 individuals, including full names, official gouv.fr email addresses, phone numbers, job titles and department/service information, and work addresses.
  • Date: 2025
  • Domain: gouv.fr
  • Threat Actor: HexDex
  • Country: France
  • Category: Government
  • Data: Email Addresses Names Phone Numbers Geographic Locations Job Information Company Information
  • Records: 63,817
  • Lines: 63,817
  • Size: 16.28 MB
  • Passwords: No
In May 2016, Deways (deways.com), a French car-sharing and rental platform, allegedly suffered a data breach. The exposed database, which reportedly held around 24,000 members, was published on a hacking forum. Reports suggest the compromised data included email addresses, usernames, names, phone numbers, birthdates, postal addresses, and bcrypt-hashed passwords.
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Birthdates
  • Records: 24,014
  • Lines: 24,015
  • Size: 3.34 MB
  • Passwords: BCrypt
  • Cracked: 0%

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.