Cyber & AI intelligence
Wasteland.
Briefs indexed2995
Issues30
Published Mondays07:30 CT
▣ Breach HAUTS-DE-FRANCE 2026-10-03

Hauts-de-France Region: Data Breach via Service Providers Atexo and Docaposte

"On Saturday, October 3, 2026, France's Hauts-de-France regional government said in a statement that two of its service providers had been hit by a cyberattack. The providers are Atexo, which makes software for public…"

On Saturday, October 3, 2026, France's Hauts-de-France regional government said in a statement that two of its service providers had been hit by a cyberattack. The providers are Atexo, which makes software for public bodies, and Docaposte, a La Poste subsidiary. The attack gave someone unauthorised access to personal data the providers process on the Region's behalf. The Region confirmed that names and email addresses were exposed, and possibly bank account details (RIBs) and "other identification data." It also said it cannot yet give "the exact number of people concerned." The headline figure of more than 700,000 victims comes from an attacker using the alias "ChimeraZ." The breach-tracking site FrenchBreaches reported the claim, and nobody has verified it independently. The Region has filed a complaint, shut down the affected platforms and started notifying users.

What Happened

The Region's statement was reported by AFP, franceinfo, France 3 and 20 Minutes. It says Atexo and Docaposte "were victims of a cyberattack that allowed unauthorised access to personal data processed on its behalf." The Region describes this as a breach at its providers, not an intrusion into its own core IT systems. FrenchBreaches makes the same point: the notification names Atexo as the victim, which suggests the unauthorised access happened in Atexo's environment.

The timeline in the sources goes like this:

France in English reports that ANSSI, France's national cybersecurity agency, has been alerted and is involved in the investigation. None of the other sources mention ANSSI, so treat this as unconfirmed.

Accounts of how big the incident is differ sharply. The Region told France 3: "We are not in a position today to confirm the volume and other categories of documents extracted." Franceinfo's headline describes the victims as "several thousand people," while its article body and most other outlets use the attacker's figure of about 700,000.

What Was Taken

What the Region has confirmed and what the attacker claims are far apart, and the two should be kept separate.

Confirmed by the Region: - The Atexo notification (October 2, via FrenchBreaches) confirms only three data types: surname, first name and email address. - The October 3 statement widens this to names, email addresses, "potentially RIBs and other identification data." It says investigations continue to find out whether other categories were accessed or taken.

Claimed by ChimeraZ (via FrenchBreaches and Cyberattaque.org; unverified): - Dataset 1: 782,583 rows covering about 708,000 people (Cyberattaque.org gives 708,068), totalling 528 MB across several JSON files of accounts, support records and transactions. One file is reportedly called 493K_comptes.json. FrenchBreaches' headline refers to "nearly 800,000 accounts," which is the row count, not the number of people. - Dataset 2: 48 GB containing 90,011 PDF files. - Claimed data types: names, email addresses, mobile phone numbers, login identifiers, IBANs/RIBs, transaction records, apprenticeship contracts, proof-of-residence certificates, school enrolment certificates and identity documents.

Reported victim counts therefore range from an unspecified number (the Region's position) to about 708,000 people or 782,583 records (the attacker's claim, via FrenchBreaches). FrenchBreaches says the data comes from Génération#HDF, a regional card that helps high school students and apprentices buy textbooks and school supplies. That means a large share of the people affected are probably minors and young adults.

Why It Matters

This is a third-party breach. The Region was not breached directly. Its data sat with outside providers, and that is where the attacker got in. Atexo makes software for public bodies, and Docaposte is a major document-exchange provider. Both probably serve many other French public-sector customers. Any organisation using either platform should assume its own exposure is being looked at.

Young people are the main targets. If the Génération#HDF attribution holds, many victims are teenagers. Their names, contact details, school records and parents' or their own bank details are now in criminal hands. Young people are less likely to recognise phishing or check their credit and bank activity. A leak that combines RIBs, identity documents and proof-of-residence certificates is a complete kit for identity fraud, fraudulent direct debits and convincing impersonation scams.

There is a disclosure gap. The first notification listed three low-sensitivity fields. Within a day, the attacker's claims described bank details, ID documents and 90,000 PDFs. Defenders should expect first disclosures from public bodies to understate the scope. It is safer to plan around what the attacker claims until it has been disproved.

This fits a wider pattern. 20 Minutes and France in English both note that France remains one of the most targeted countries for data breaches, and that French data sells well on criminal markets.

The Attack Technique

None of the sources disclose how the attackers got in. The Region, Atexo and Docaposte have not described the initial access vector, how long the attacker was inside, or whether the two provider compromises were linked or separate. No source has linked the ChimeraZ alias to a known group or earlier campaign.

What the sources do suggest:

Until the providers publish technical findings, any statement about the technique is speculation.

What Organizations Should Do

  1. List your exposure to these providers. If you use Atexo or Docaposte services, ask both for a written incident statement. Find out which of your datasets they host, and whether your tenant is in scope.
  2. Reduce what service platforms keep. Grant and benefits portals often hold RIBs, ID scans and certificates long after the application is done. Set retention limits and purge supporting documents once they have been verified.
  3. Separate documents from account data. Store uploaded documents in their own storage, with separate credentials, access logging and encryption keys, so one compromise does not expose both the database and the document store.
  4. Write breach-notification terms into provider contracts. Require providers to notify you within a set number of hours, give you a list of affected data categories, and share forensic findings. Your first notice should not come from a breach-tracking site.
  5. Prepare victims for fraud. If RIBs and identity documents may be exposed, tell affected users to watch for fraudulent direct debits (SEPA mandates), phishing that impersonates the Region or the Génération#HDF scheme, and identity-based account takeovers. Write the guidance so teenagers and their parents can follow it.
  6. Monitor criminal forums for your brand and suppliers. In this case, the attacker's forum posts revealed more about the scope than the official notification did. Tracking forum and leak-site mentions of your providers gives you earlier warning.

Sources: Cyberattack in Hauts-de-France Compromises Data... France in English | Cyberattaque dans les Hauts-de-France : Des données personnelles et... | Hauts-de-France : les données de plus de 700 000 personnes revendiq... | Cyberattaque chez ATEXO : des données d’usagers de la Région... | Hauts-de-France : un pirate revendique le vol des données de 700 00... | Sécurité des données : la Région touchée par une cyberattaque : plu... | La région Hauts-de-France victime d'une cyberattaque : "des noms, p... | Dans les Hauts-de-France, deux prestataires de la région piratés, l...