France’s data-protection authority, CNIL, fined Hôpital privé de la Loire (HPL) €500,000 over a 2025 breach in which an attacker used a compromised doctor’s account to access its electronic patient-record system. The incident exposed sensitive data for 524,867 patients and 202,246 trusted third parties—more than 727,000 people in total. A person using the alias “Marak” claimed responsibility; three suspects were arrested in late June in connection with attacks on automated data-processing systems.
CNIL found that HPL allowed remote access without a VPN or multifactor authentication, assigned overly broad permissions that enabled one compromised account to reach all patient records, and lacked monitoring capable of promptly detecting prolonged exploration and exfiltration. The authority also found that HPL failed to directly notify affected third parties, violating GDPR Articles 32 and 34. HPL has been ordered to correct the identified deficiencies within deadlines ranging from three to 15 months.

See the reporting duties and controls this puts on the clock.
5 events from the most recent confirmed update back to the earliest known activity.
On September 3, 2026, France's CNIL imposed a public €500,000 fine on Hôpital privé de la Loire for GDPR security and breach-notification failures. CNIL found that external access lacked VPN and multifactor authentication, access rights were excessive, and monitoring and alerting were inadequate; it gave the hospital three to fifteen months to remediate deficiencies.
During July 2025, an attacker used a compromised doctor account to access the hospital's electronic patient-record system. The intrusion exposed records for 524,867 patients and data on 202,246 trusted third parties, affecting more than 727,000 people; the attacker was able to explore and exfiltrate data over several days.
A teenager using the alias “Marak” claimed responsibility for the intrusion, saying a single compromised doctor account provided access to HPL's internal systems. The actor reportedly attempted to sell the stolen data for €2,000 to €5,000, but the data was later reported not to have been sold or published.
Hôpital privé de la Loire notified affected patients about the breach but did not directly notify the 202,246 affected trusted third parties whose information was exposed.
Three suspects were arrested at the end of June in connection with attacks against automated data-processing systems. They were charged and placed under judicial supervision.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
4 references tracked. Mallory keeps watching after this page renders.
teiss.co.uk
Open sourcemalware.news
Open sourcebleepingcomputer.com
Open sourcezdnet.fr
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.