Overview
- The ministry says the breach began in the night of July 25 when a professional account was usurped to access the system for personnel training.
- Investigators detected the intrusion the next day, suspended external access to the affected system, activated a crisis cell and mobilized technical teams to contain the incident.
- The data possibly exfiltrated include identity and professional details, and for some people contact information, postal address, phone number and social‑security number; the ministry says the system does not hold bank details, passwords or student records.
- A formal complaint has been filed and France’s cybersecurity agency ANSSI and data regulator CNIL have been notified while the ministry prepares to notify those potentially affected but has not given a final headcount.
- This breach follows earlier intrusions this year that exposed staff and student data, raising the risk of follow‑on phishing and identity fraud and underlining recurring account‑takeover vulnerabilities in ministry systems.