
AI-generated summary
The ASP is a public establishment which provides numerous aids. In April 2026, another ASP account, linked to the remuneration of trainees, had already enabled the exfiltration of identities, NIRs and IBANs. According to the CNIL, in 2025, 6,167 data breaches were notified in France, with a growing share coming from the public sector.
Your data once again in the wild. The Services and Payment Agency confirms a new leak. More than 143,000 people would be affected, according to FrenchBreaches and Seb (@seblatombe). In the files: names, addresses, IBAN/BIC, beneficiary numbers and amounts paid, extracts from payment notices for 2023 and 2024.
Behind the press release, a regional aid portal, a compromised user account, and the second case of its kind at the ASP in five months.
Key Points
The ASP, a public establishment which pays numerous aid, confirms “fraudulent access to a user account” on August 27, 2026, detected on the 28
The exfiltrated documents are 2023-2024 payment notices for the “Energy Boost” from the Île-de-France Region
It contains names, postal addresses, beneficiary numbers, IBAN/BIC and amounts paid.
The figure of more than 143,000 people comes from FrenchBreaches, not the official notification; a cybercriminal forum claims 143,518 files
In April 2026, another ASP account, on the trainee remuneration side, had already enabled the exfiltration of identities, NIRs and IBANs
ASP: 143,000 IBAN in payment advices
FrenchBreaches is a media outlet which, as its name suggests, specializes in covering data leaks in France. This September 24, the media revealed that the Services and Payment Agency, a public body of the State responsible for instructing and paying for a wide range of aid, announced that it had been the victim of a data leak, via a notification sent to the people concerned.
The incident occurred on August 27, 2026. It was detected the next day. According to the official wording, “fraudulent access to a user account” allowed the exfiltration of documents containing personal data. The Agency indicates that corrective measures have been applied. Unfortunately for our precious private data, it was already too late.
Although the notification does not give the number of victims, FrenchBreaches estimates that more than 143,000 people are affected. The volume sticks to a publication on a cybercriminal forum, where the author attributes to the ASP a batch of “143,518 K” and speaks of an IDOR type flaw. A critical flaw, which should never have slipped through the cracks.
Indeed, this is a flaw where the application exposes an object identifier (opinion number, user number, file number) and serves the corresponding file without verifying that the connected account has the right to see this object.
The files are payment notices for 2023 and 2024. They relate to the “Energy Boost” of the Île-de-France Region, for which the ASP ensured payment. There is no indication that the Agency's entire information system was blown, and it appears that the account targeted is that of the portal linked to this system.
Names, addresses, IBAN: the combo that makes Monday morning calls
In the notices: first and last name, postal address, beneficiary number, IBAN/BIC, amount paid. An IBAN alone does not empty an account. However, attached to an identity, an address and the exact amount of regional aid, it gives a scammer the means to present themselves as the ASP, the Region or “the fraud department of your bank”. The scenario writes itself: regularization, overpayment, RIB update, “your Coup de Pouce transfer has been rejected”.
Seb summarized it https://x.com/seblatombe/status/2103097482397753595it thus on
“More than 143,000 people are affected, according to our information. Names, addresses, IBAN/BIC, beneficiary numbers and amounts paid appear in payment notices dating from 2023 and 2024 which were exfiltrated. »
Seb (@seblatombe)
6,167 leaks in one year, and the State in the mix
ASP does not happen in a vacuum. In its 2025 annual report, the CNIL lists 6,167 notified data breaches, around 10% more than the previous year, which was already a record. Half of it is hacking. Over two years, around eighty leaks affected at least a million French people. ANTS, Interior, France Travail, Free, Auchan, Parcoursup: no one can say that “it only happens to others” anymore.
Marie-Laure Denis, president of the CNIL, says it bluntly: the State has “a particular responsibility” with regard to the data of the French, and must “upgrade”. In 2025, public sector processing represented 20% of notifications, compared to 11% in 2023. One leak in five, therefore, on the administration side. The September 2026 ASP is exactly in line with this trend.
The data that comes out of a payment notice does not remain in the form of an unused PDF. It circulates, intersects, is resold. It’s not the IBAN that kidnaps someone. It’s the address, the estimated assets, the habits, assembled from files costing a few euros. There has been a lot of talk about Bitcoin after a series of kidnappings. The means of payment interests the kidnapper. What guides him to the door is flight. We had already written here: the real problem is not crypto, it is the hemorrhage of files.
AI outlook — possibilities, not facts
The CNIL will open a formal investigation into this data leak at the ASP
Likely · Within weeks
The ASP will strengthen its security controls on portals linked to the payment of regional aid
Very likely · Within months

China opened an investigation in late September 2026 into DeepSeek and Moonshot AI after Anthropic's accusations of allegedly using fraudulent accounts to train their models on Claude's responses. CAC investigators are seeking to determine whether sensitive Chinese data was transferred to U.S. servers, rather than focusing on alleged technological theft to the detriment of Anthropic.

Ukraine's Ministry of Digital Transformation gains access to Daybreak, OpenAI's cybersecurity tool powered by GPT-5.6 Sol, to audit its aging infrastructure in the face of Russian attacks.

Cardano joins the x402 protocol, enabling automated payments for AI agents and online services. The official TypeScript kit now supports ADA and native tokens, although usage is currently limited to the staging network.

More than 52 bitcoins from the Coldcard wallet hack were transferred to a legal trust in Wyoming to be returned to their owners, after being sheltered by ethical hackers.

Anthropic unveiled Claude Opus 5.5, sold 40% cheaper, followed immediately by OpenAI and its new GPT-6 Sol and Luna models at knockdown prices. This price war comes as Anthropic's IPO on Nasdaq approaches.

X deploys X Numbers, private codes allowing you to receive messages and calls from untracked accounts without revealing your phone number, thus paving the way for the X Money payment service.