Observatory

Major Data Breaches and Cyberattacks

A timeline of the most significant, publicly documented security incidents in France and internationally: who was hit, how, and how many people were affected. Updated as public disclosures happen.

This page tracks, year by year, the most significant data breaches and cyberattacks affecting French and international companies and administrations. This is not an exhaustive list: we selected incidents based on scale, impact, or media coverage, not every publicly recorded violation.

Figures come from official disclosures, investigative journalism, and regulatory notifications (CNIL and other data protection authorities). They are provided for reference: some exact volumes remain debated or are revised after the initial disclosure.

32 incidents tracked

2026

DGFiP (impots.gouv.fr)

2026-08-20 · France · Public sector

2+ million people potentially affected

France's tax authority confirms illegitimate access to its systems, reviving the debate over public-sector security.

Cause : Impersonated agent credentials and lack of widespread MFA across the tax administration's information system.

Read the full analysis →

2025

SFR

2025-11-01 · France · Telecom

Not disclosed

A further compromise at the same operator, revealing persistent weaknesses in internal access security.

Cause : A second, separate security incident roughly 18 months after the first breach.

Read the full analysis →

2024

Free / Free Mobile

2024-10-16 · France · Telecom

24 million accounts (+ IBANs for dual-play subscribers)

One of the largest French telecom incidents, followed by a record CNIL fine for failing to secure customer data.

Cause : Intrusion into internal systems, exfiltration of contracts and bank details; resulted in a €42 million CNIL fine.

Read the full analysis →

SFR

2024-09-01 · France · Telecom

3.6 million customers

The first of two distinct security incidents suffered by the operator in less than two years.

Cause : Compromise of an internal management tool exposing contracts and contact details.

Read the full analysis →

National Public Data

2024-08-06 · United States · Other

Up to 2.9 billion records claimed

A little-known data broker had decades of personal history records resold on criminal forums.

Cause : A data broker's database exposed, containing address histories and social security numbers.

AT&T

2024-07-12 · United States · Telecom

73 million customers (+110 million call logs)

Two distinct 2024 incidents: republication of old data, then a massive theft of call and text metadata for nearly all customers.

Cause : Historical leak republished, plus a separate theft of call and text records via a compromised Snowflake cloud account.

Ticketmaster / Live Nation

2024-05-30 · International · Retail / Ticketing

560 million customers

One of the largest ticketing data breaches in history, exposing names, emails and partial payment data of customers worldwide.

Cause : Compromise of customer Snowflake accounts lacking MFA, part of a wave of attacks hitting multiple companies.

France Travail

2024-03-13 · France · Public sector

43 million people

Names, social security numbers and registration status of nearly all French workers and jobseekers exposed.

Cause : Unauthorized access via compromised advisor/agent credentials at France's employment agency.

Read the full analysis →

Change Healthcare

2024-02-21 · United States · Healthcare

100+ million people

The attack paralyzed billing and reimbursement across a large part of the US healthcare system for weeks, with an estimated $22 million ransom paid.

Cause : ALPHV/BlackCat ransomware via Citrix credentials without multi-factor authentication.

Viamedis / Almerys

2024-01-01 · France · Healthcare

33 million French residents

Health data (insurer, reimbursements) of half the French population exposed via two separate providers hit in parallel.

Cause : Double compromise of two French health third-party payment operators via stolen professional credentials.

Read the full analysis →

2023

23andMe

2023-10-06 · United States · Healthcare

6.9 million users

Sensitive genetic and genealogical data exposed, with attackers claiming to target Ashkenazi Jewish and Chinese profiles.

Cause : Credential stuffing on accounts reusing passwords, then abuse of the DNA Relatives feature to widen the exposure.

MGM Resorts

2023-09-14 · United States · Hospitality / Leisure

Internal systems paralyzed (casinos, hotels)

A single phone call to the help desk paralyzed the group's casinos and hotels for days, at an estimated cost of $100 million.

Cause : Vishing social engineering against the IT help desk (Scattered Spider group), followed by ransomware.

Caesars Entertainment

2023-09-07 · United States · Hospitality / Leisure

Not disclosed

Days before the MGM Resorts attack, the same threat actors targeted Caesars, which chose to pay the ransom.

Cause : Vishing social engineering against IT support (Scattered Spider group); roughly $15 million ransom paid.

MOVEit Transfer (Cl0p)

2023-05-31 · International · Tech / Software

2,500+ companies, 90+ million people

The largest data-extortion campaign ever run through a single software vulnerability, hitting hundreds of organizations worldwide.

Cause : Zero-day SQL injection in MOVEit Transfer, exploited at scale by the Cl0p group.

Read the full analysis →

2022

LastPass

2022-12-22 · International · Tech / Software

Encrypted vaults of all users

The password manager had customer backups stolen; real-world impact depends on the strength of each user's master password.

Cause : Compromise of a developer's workstation, followed by theft of encrypted vault backups from the cloud.

Read the full analysis →

Uber

2022-09-15 · United States · Tech / Software

Entire internal information system

A lone attacker gained full administrator access to Uber's Slack, AWS, GSuite and financial tools within hours.

Cause : Social engineering and MFA fatigue by an 18-year-old attacker, full access to internal tools.

Read the full analysis →

Boulanger / Cultura

2022-09-01 · France · Retail / Ticketing

Several hundred thousand customers

Several French retail chains notified customers of a contact-details leak (name, email, phone) via a shared contractor.

Cause : Leak via a shared customer relationship management contractor, hitting several retail chains in parallel.

Twitter / X

2022-08-25 · International · Tech / Software

200 million accounts

Emails and phone numbers linked to accounts were aggregated and later leaked for free, exposing anonymous accounts to re-identification.

Cause : Vulnerable API allowing phone numbers or emails to be matched to accounts, abused for mass scraping.

CH Sud Francilien (Corbeil-Essonnes)

2022-08-21 · France · Healthcare

Patient medical records

The hospital operated in degraded mode for weeks after an attack that encrypted its information system and exposed patient data.

Cause : LockBit ransomware; a $10 million ransom was demanded and refused by the hospital, with data published in retaliation.

La Poste Mobile

2022-07-04 · France · Telecom

Not disclosed

La Poste Group's mobile operator took several weeks to restore services following a ransomware attack.

Cause : Ransomware paralyzing billing and customer support for several weeks.

2021

LinkedIn

2021-06-01 · International · Tech / Software

700 million profiles

Professional and personal data of nearly all active users aggregated and resold on specialized forums.

Cause : Mass scraping of public profiles via the API, without exploiting a vulnerability in the strict sense.

Facebook / Meta

2021-04-03 · International · Tech / Software

533 million accounts

Phone numbers, full names and locations of over half a billion users republished for free on a hacking forum.

Cause : Mass scraping via a contact-import feature, patched in 2019 but already abused before the fix.

Ameli.fr (Assurance Maladie)

2021-02-23 · France · Healthcare

500,000 policyholders

Compromised healthcare professional credentials allowed extraction of data on hundreds of thousands of France's national health insurance policyholders.

Cause : Stolen healthcare professional credentials used to query the ameli pro teleservice.

Orange

2021-02-01 · France · Telecom

Not disclosed (business customers)

The operator confirmed unauthorized access to business customer data via one of its management platforms.

Cause : Intrusion into an internal management platform dedicated to business customers.

2020

SolarWinds

2020-12-13 · United States · Tech / Software

18,000 organizations

The decade's most significant software supply-chain attack, hitting US federal agencies and Fortune 500 companies.

Cause : Malicious implant injected into Orion software updates by the Nobelium group.

Read the full analysis →

Sopra Steria

2020-10-11 · France · Tech / Software

Not disclosed (internal systems)

One of France's largest IT services firms paralyzed for days by ransomware, in the same wave as the Groupe M6 attack.

Cause : Ryuk ransomware encrypting part of the IT services firm's information system.

Groupe M6

2020-10-10 · France · Other

No confirmed data leak

The TV group kept broadcasting despite an attack that blocked a large part of its information system.

Cause : Ryuk ransomware paralyzing the broadcast group's internal systems and operations for several days.

Pôle emploi (prestataire tiers)

2020-09-01 · France · Public sector

800,000 jobseekers

France's employment agency warned hundreds of thousands of jobseekers after uncovering a phishing campaign built on data stolen from a partner.

Cause : Data leak at a third-party contractor, later reused for a targeted phishing campaign.

2019

Capital One

2019-07-29 · United States · Finance / Insurance

106 million people

Credit applications, social security numbers and bank data exfiltrated from a poorly protected cloud storage bucket.

Cause : Misconfigured web application firewall (SSRF) exploited by a former employee of an AWS cloud contractor.

2018

Marriott / Starwood

2018-11-30 · United States · Hospitality / Leisure

500 million guests

Passport numbers, birth dates and card data of hundreds of millions of hotel guests exposed over an unusually long dwell time.

Cause : Intrusion left undetected for roughly four years inside the Starwood reservation database after the acquisition.

2017

Equifax

2017-09-07 · United States · Finance / Insurance

147 million people

Social security numbers, birth dates and addresses of nearly half of Americans exposed through a known, neglected web vulnerability.

Cause : Known Apache Struts CVE, left unpatched despite a fix having been available for months.

Read the full analysis →

2013

Yahoo

2016-12-14 · United States · Tech / Software

3 billion accounts

The largest data breach ever recorded: every single Yahoo account at the time, disclosed in waves during 2016-2017 for intrusions dating back to 2013.

Cause : Credentials stolen by suspected state-sponsored actors; passwords hashed with obsolete MD5.

Information sourced from public disclosures (official statements, specialized press, regulators). Figures may change after initial publication.

Need an external review of your HR SaaS?

Share your product, stack, and client context. We will come back with the right review scope.

Discuss your audit