France’s data protection authority CNIL fined public employment agency France Travail €5 million for failing to implement security measures appropriate to the risk (citing GDPR Article 32) after attackers accessed job-seeker data via social engineering. Investigators said the attackers compromised accounts used by staff at Cap emploi (a partner organization), and that existing safeguards did not sufficiently reduce the risk of unauthorized access through compromised accounts.
The intrusion enabled access to personal data associated with roughly 43 million people, including current registrants, former registrants going back about 20 years, and individuals with candidate profiles on francetravail.fr. Exposed data included social security/national insurance numbers, names and dates of birth, and contact details (email, postal address, phone); reporting noted the breach did not include bank details or account passwords and did not provide complete job-seeker files. CNIL ordered France Travail to provide evidence and a schedule of corrective actions, backed by a conditional €5,000/day penalty for non-compliance.

See the reporting duties and controls this puts on the clock.
6 events from the most recent confirmed update back to the earliest known activity.
After CNIL's ruling, France Travail said it accepted the decision while arguing that the penalty was severe despite cybersecurity efforts made since the incident. The statement served as the agency's official response to the enforcement action.
Alongside the fine on January 29, 2026, CNIL ordered France Travail to document and implement corrective security measures within a set timeframe. The regulator said non-compliance could trigger a conditional daily penalty of €5,000.
On January 29, 2026, France's data protection authority CNIL fined France Travail €5 million for failing to adequately secure job seekers' personal data, citing GDPR Article 32 violations. CNIL said safeguards such as authentication, logging and monitoring, and access controls were insufficient to prevent or detect the compromise.
The early 2024 breach was found to have exposed personal information associated with about 43 million people, including names, dates of birth, national insurance or social security numbers, and contact details. Reports said bank details, passwords, full job-seeker files, and health data were not taken.
In early 2024, attackers used social engineering to hijack accounts belonging to CAP EMPLOI advisers or related partner organizations, gaining unauthorized access to France Travail systems. The intrusion exposed personal data tied to current and former registrants over roughly 20 years.
In August 2023, France Travail experienced a separate data breach that reportedly affected about 10 million individuals. This earlier incident was later cited in coverage of the larger 2024 breach.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcetherecord.media
Open sourcehelpnetsecurity.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.