Pajemploi, a French social security service under URSSAF that supports parents and home-based childcare providers, has suffered a significant data breach impacting approximately 1.2 million professional caregivers. The breach, detected on November 14, resulted in the theft of personal data including full names, places of birth, postal addresses, social security numbers, names of banking institutions, Pajemploi numbers, and accreditation numbers. However, sensitive information such as bank account numbers (IBANs), email addresses, phone numbers, and account passwords were not accessed. Pajemploi has assured that its operational services remain unaffected and has taken immediate steps to secure its systems, while also notifying the French Data Protection Authority (CNIL) and the National Agency for the Security of Information Systems (ANSSI).
All affected individuals will be notified directly by Pajemploi, and the agency has advised heightened vigilance against potential fraudulent communications. The breach specifically targets employees of private employers using the Pajemploi service, raising concerns about the risk of identity theft and social engineering attacks. URSSAF has recommended that users remain alert for suspicious emails or SMS messages that could exploit the exposed data.

See attribution, scope, and your downstream exposure.
1 event from the most recent confirmed update back to the earliest known activity.
French agency Pajemploi reported a data breach that exposed information belonging to about 1.2 million people. Multiple outlets covered the same disclosure, with no additional distinct developments provided in the references.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
databreaches.net
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.