Summary
- Environment: Pass'Sport
- Operational impact: No outage or recovery duration quantified
- Financial impact: No public cost estimate
- Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.
What happened
An exfiltration from a French Ministry of Sports information system associated with the Pass’Sport program and a later-public personal-data corpus. [1][3]
Impact
A public corpus measured separately as unique email addresses, historical rows, and affected households so those units are not conflated. [1][3]
Documented data types include:
- Contact information — Email addresses, phone numbers, and physical or postal addresses associated with corpus records. [1][3]
- Gender information — Gender information listed in HIBP’s verified Pass’Sport record. [1][3]
- Names — Names listed by HIBP and identities directly reported in the examined corpus. [1][3]
A cited record reports 6,366,133 records (Unique email addresses represented in the verified HIBP corpus; not a count of unique people, households, total rows, or Pass’Sport beneficiaries; as of 2026-01-18). [1][3]
A cited record reports 22,445,764 records (Rows in the file directly examined by Les Numériques; the publication said the four-year history could contain the same person up to four times, so this is not a people or household count). [3]
The ministry said specialized technical teams assessed the nature and scope of the affected data and implemented security measures to stop further leakage. [2]
A file associated with the incident was published on a criminal forum during the night of December 17 to 18, 2025. [1][3]
The ministry said it was working to inform 3.5 million affected households, while independent analysis described approximately 3.5 million unique households after deduplication. [1][2][3]
CNAF said the circulated data appeared to come from another public service’s information system with which it exchanged data for benefits or services. [4]
Timeline
Public disclosure
Date of the ministry’s public exfiltration notice; public reporting and CNAF’s statement appeared the preceding day.
[2]Briefing updated
This briefing was last reviewed and updated on August 9, 2026.
Threat Group & Attack Vector
The incident involved Pass’Sport. HIBP identifies the corpus as Pass’Sport data, and independent analysis linked the mixed CAF, MSA, and CNOUS fields plus id_psp identifiers to that program; the ministry notice did not name a specific application. [1][3]
Actors
- No threat actor group has been identified in the reviewed public evidence.
TTPs
- No specific MITRE ATT&CK technique is currently mapped for this case.
Response
CNAF said the disclosed data did not include banking data or passwords capable of accessing caf.fr accounts. CNAF said its investigation detected no intrusion or vulnerability in its own information systems or caf.fr. The ministry said it would notify CNIL within 72 hours in accordance with its regulatory obligations. The ministry said it would file a complaint with the competent authorities. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [2][4]
