Summary
- Environment: Network whose adviser accounts were hijacked and used to reach France Travail data.
- Operational impact: No outage or recovery duration quantified
- Financial impact: No public cost estimate
- Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.
What happened
One or more attackers used social engineering to take over Cap emploi adviser accounts and access France Travail job-seeker data. [1]
Impact
Access to identity, employment-service account, national-insurance, and contact information for current and former registrants and candidate-account holders. [1]
Documented data types include:
- Contact information — Email addresses, postal addresses, and telephone numbers. [1][2]
- Usernames and account identifiers — France Travail identifiers; not asserted to include passwords. [1][2]
- Social Security numbers — French national-insurance numbers; mapped to the database’s government social-insurance identifier category. [1][2]
- Names — Names and surnames. [1][2]
A cited record reports 43,000,000 individuals (Initial March 2024 CNIL estimate of people potentially affected; the source said the figure required confirmation and it is not a verified final count; as of 2024-03-13). [1][2]
The CNIL’s March 2024 information said passwords and bank details were not affected; the later enforcement summary also said complete job-seeker files, which may include health data, were not accessed. [1][2]
Timeline
Threat Group & Attack Vector
The CNIL found Cap emploi adviser permissions were too broad and allowed access to people the advisers were not supporting, increasing the volume exposed to attackers. [1]
Social engineering was used to exploit trust or lack of awareness and take over Cap emploi adviser accounts; the source does not identify a more specific standardized technique. [1]
The attackers hijacked Cap emploi adviser accounts and used them to access the France Travail information system in the first quarter of 2024. [1]
Actors
- No threat actor group has been identified in the reviewed public evidence.
TTPs
- No specific MITRE ATT&CK technique is currently mapped for this case.
Response
The CNIL imposed a €5 million administrative fine on France Travail. The CNIL found logging measures were inadequate for detecting abnormal behavior on the information system. The CNIL found the authentication procedures used by Cap emploi advisers to access France Travail were not sufficiently robust. The CNIL ordered France Travail to justify corrective measures on a specified schedule, with a €5,000 daily penalty for delay. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1]
