France’s data protection authority CNIL fined France Travail €5 million after finding the agency failed to adequately protect job seekers’ personal data in a major breach. Investigators said attackers used social engineering to compromise CAP EMPLOI adviser accounts and access France Travail’s information system, exposing data tied to people currently or previously registered over the past 20 years, as well as users with candidate accounts on francetravail.fr. The exposed information included national insurance or social security numbers and contact details, while complete job seeker files containing potentially sensitive health data were reportedly not accessed.
CNIL said the agency had inadequate authentication controls, insufficient logging to detect abnormal behavior, and overly broad access permissions, despite having already identified many of the needed safeguards. Alongside the fine, the regulator ordered France Travail to document corrective actions and provide a precise remediation timetable or face a penalty of €5,000 per day for delay. The case follows earlier scrutiny of the agency, formerly known as Pôle emploi, after a separate service-provider breach linked to the mass exploitation of MOVEit exposed data on roughly 10 million people, including names and French social security numbers.

See the reporting duties and controls this puts on the clock.
4 events from the most recent confirmed update back to the earliest known activity.
On 2026-01-22, France's data protection authority CNIL fined France Travail €5 million for inadequate security measures tied to the 2024 breach. CNIL also ordered the agency to document corrective actions and an implementation schedule, with a potential €5,000-per-day penalty for delay.
In the first quarter of 2024, attackers used social engineering to compromise CAP EMPLOI adviser accounts and gain access to France Travail's information system. They accessed data on current and former registrants from the prior 20 years, as well as candidate-account holders, including national insurance numbers and contact details.
On or before 2023-08-25, Pôle emploi announced that a breach involving one of its service providers may have exposed the personal data of roughly 10 million job seekers and former users. Exposed data included names and French social security numbers, while passwords, banking data, email addresses, and phone numbers were reportedly not affected.
By mid-June 2023, U.S. officials disclosed that a global hacking campaign exploiting MOVEit software had exposed personal data belonging to millions of Americans through multiple federal agencies and contractors. The campaign was later broadly attributed to the Clop ransomware operation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
4 references tracked. Mallory keeps watching after this page renders.
infosecurity-magazine.com
Open sourcebleepingcomputer.com
Open sourcecnn.com
Open sourcecnil.fr
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.