France Travail job-seeker data incident

One or more attackers used social engineering to take over Cap emploi adviser accounts and access France Travail job-seeker data. Access to identity, employment-service account, national-insurance, and contact information for current and former registrants and candidate-account holders.

Last modified

Summary

  • Environment: Network whose adviser accounts were hijacked and used to reach France Travail data.
  • Operational impact: No outage or recovery duration quantified
  • Financial impact: No public cost estimate
  • Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.

What happened

One or more attackers used social engineering to take over Cap emploi adviser accounts and access France Travail job-seeker data. [1]

Impact

Access to identity, employment-service account, national-insurance, and contact information for current and former registrants and candidate-account holders. [1]

Documented data types include:

  • Contact information — Email addresses, postal addresses, and telephone numbers. [1][2]
  • Usernames and account identifiers — France Travail identifiers; not asserted to include passwords. [1][2]
  • Social Security numbers — French national-insurance numbers; mapped to the database’s government social-insurance identifier category. [1][2]
  • Names — Names and surnames. [1][2]

A cited record reports 43,000,000 individuals (Initial March 2024 CNIL estimate of people potentially affected; the source said the figure required confirmation and it is not a verified final count; as of 2024-03-13). [1][2]

The CNIL’s March 2024 information said passwords and bank details were not affected; the later enforcement summary also said complete job-seeker files, which may include health data, were not accessed. [1][2]

Timeline

  1. Public disclosure

    Date France Travail and Cap emploi informed the CNIL of the intrusion; not necessarily the first public announcement date.

    [2]
  2. Documented event

    Date the CNIL imposed the sanction.

    [1]
  3. Briefing updated

    This briefing was last reviewed and updated on August 9, 2026.

Threat Group & Attack Vector

The CNIL found Cap emploi adviser permissions were too broad and allowed access to people the advisers were not supporting, increasing the volume exposed to attackers. [1]

Social engineering was used to exploit trust or lack of awareness and take over Cap emploi adviser accounts; the source does not identify a more specific standardized technique. [1]

The attackers hijacked Cap emploi adviser accounts and used them to access the France Travail information system in the first quarter of 2024. [1]

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

The CNIL imposed a €5 million administrative fine on France Travail. The CNIL found logging measures were inadequate for detecting abnormal behavior on the information system. The CNIL found the authentication procedures used by Cap emploi advisers to access France Travail were not sufficiently robust. The CNIL ordered France Travail to justify corrective measures on a specified schedule, with a €5,000 daily penalty for delay. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1]