Particle.news
Download on the App Store

French Education Ministry Says July 25 Account Takeover May Have Exposed Staff Data

Authorities are investigating after an intruder used a usurped professional account to access a personnel training system that may have copied identity records for staff who worked in académie since 2001.

Overview

  • The ministry says the breach began in the night of July 25 when a professional account was usurped to access the system for personnel training.
  • Investigators detected the intrusion the next day, suspended external access to the affected system, activated a crisis cell and mobilized technical teams to contain the incident.
  • The data possibly exfiltrated include identity and professional details, and for some people contact information, postal address, phone number and social‑security number; the ministry says the system does not hold bank details, passwords or student records.
  • A formal complaint has been filed and France’s cybersecurity agency ANSSI and data regulator CNIL have been notified while the ministry prepares to notify those potentially affected but has not given a final headcount.
  • This breach follows earlier intrusions this year that exposed staff and student data, raising the risk of follow‑on phishing and identity fraud and underlining recurring account‑takeover vulnerabilities in ministry systems.