Original Article Text

Click to Toggle View

French agency Pajemploi reports data breach affecting 1.2M people. Pajemploi, the French social security service for parents and home-based childcare providers, has suffered a data breach that may have exposed personal information of 1.2 million individuals. The incident impacts registered professional caregivers working for private employers, typically parents using the Pajemploi service part of URSSAF - the French organization that collects social security contributions from employers and individuals. "The Pajemploi service has been the victim of a theft of personal data belonging to employees of private employers using the Pajemploi service," reads the announcement from the agency. "This cyberattack, detected on November 14, could have affected up to 1.2 million employees of private employers using the Pajemploi service," the public service says. According to the French agency, the data potentially exfiltrated includes the following types: Pajemploi's disclosure highlights that the hackers did not have access to bank account numbers (IBANs), email addresses, phone numbers, or account passwords. Each person affected by the cybersecurity incident will be notified by Pajemploi individually. Pajemploi also stated that the incident has not impacted its operations, and services such as the processing of submitted declarations or payment of salaries continue uninterrupted. The agency notes that after detecting the breach, it took immediate action to stop the attack and protect its information systems. The organization also notified the French Data Protection Authority (CNIL) and the National Agency for the Security of Information Systems (ANSSI). URSSAF recommends that everyone be extra cautious due to the elevated risk of fraudulent emails, SMS, or phone calls targeting them using the stolen information. BleepingComputer has contacted URSSAF with a request for more information about the incident and whether there is a ransom demand from the threat actor, but we received no reply. We will update the article when we hear back. At publishing time, no ransomware group has claimed the attack on Pajemploi. In March 2024, France Travail, formerly Pôle Emploi, the agency responsible for registering unemployed individuals and providing employment assistance, suffered a data breach that exposed the personal data of 43 million individuals in the country. Over the weekend, Eurofiber France disclosed that hackers breached its network on November 13 and stole customer data from its ticket management platform. Secrets Security Cheat Sheet: From Sprawl to Control Whether you're cleaning up old keys or setting guardrails for AI-generated code, this guide helps your team build securely from the start. Get the cheat sheet and take the guesswork out of secrets management.

Daily Brief Summary

DATA BREACH // Pajemploi Data Breach Exposes Information of 1.2 Million Individuals

Pajemploi, a French social security service, experienced a data breach affecting 1.2 million registered professional caregivers, primarily impacting parents and home-based childcare providers.

The breach, detected on November 14, involved the exfiltration of personal data, though sensitive information such as bank details, emails, and passwords remained secure.

Pajemploi assured that its operations, including salary processing and declaration submissions, continue unaffected, maintaining service continuity despite the breach.

The agency promptly halted the attack and reinforced its information systems, while notifying both the French Data Protection Authority and the National Agency for the Security of Information Systems.

Individuals affected by the breach will receive personal notifications, and URSSAF advises heightened vigilance against potential phishing attempts using the stolen data.

No ransomware group has claimed responsibility for the attack, and there is no confirmation of a ransom demand from the perpetrators.

This incident follows a similar breach in March 2024 involving France Travail, emphasizing the ongoing cybersecurity challenges faced by French public services.