ASP hacking: a hacker claims the data of 30,000 people, including Social Security numbers
Quick Look
A hacker claims the data of nearly 30,000 people at the Services and Payment Agency (ASP) was leaked, including names, dates of birth, Social Security numbers and email addresses, the third incident since April 2026, with an increased risk of identity theft targeting cryptocurrency holders.
AI-generated summary
Why It Matters
The ASP experienced two previous data leaks in April and August 2026, respectively concerning vocational training trainees and beneficiaries of the Ile-de-France “Energy Boost”.
The Goldfinger rule applies this Friday, October 9 to the Services and Payment Agency (ASP). This public establishment pays a good part of state aid and a hacker claims the data of nearly 30,000 people with some 24,000 Social Security numbers. Third alert since April. The leak of the IBANs of beneficiaries of Ile-de-France aid was revealed just two weeks ago. And if you hold cryptocurrencies, this file concerns you more than you think.
The announcement comes from a certain ChimeraZ. According to the alert published this October 9 by FrenchBreaches, a site specializing in monitoring French leaks, it highlights 31,028 lines for 29,611 people. The batch reportedly contains 26,871 email addresses and 24,065 Social Security numbers. The compromise dates back to September 29.
The detail is dizzying. It contains names, birth names, dates and countries of birth, postal addresses, telephone numbers, family situation and even the number of dependent children. The sample examined does not show any banking details or password, which does not exclude their presence elsewhere in the database.
Still keep a cool head. FrenchBreaches judges the claim “credible” after examining a sample, without having verified the announced volumes. The ASP has not reacted at this stage and the exact origin of the file remains to be confirmed.
Let's pick up the thread. In April 2026, a compromised internal account exposed the identities, Social Security numbers and IBANs of vocational training trainees. The number of victims has never been made public. On August 27, do it again with the Ile-de-France “Energy Boost”. The agency recognizes 108,555 people affected when the hacker claimed more than 143,000.
Should we deduce three distinct intrusions from this? FrenchBreaches has not established any link between the new file and the two previous incidents, and there is nothing to prevent it from either of these accesses. Three heists or a single loot sold at retail, the nuance matters for the investigators and much less for the victims.
The agency has company. In its situation update of September 30, ANSSI (the state cybersecurity agency) identified 99 violations reported in state services since August 1, including 67 confirmed.
Let's be honest, this file contains no wallet or balance. There is no indication that its victims are whales, and yet the lot is worth a lot. A name, date of birth, Social Security number and telephone number are enough to create credible identity theft.
First use, SIM swap. The scammer pretends to be you from your operator, retrieves your number from his own SIM card then intercepts the codes received by SMS. Your account on an exchange platform can then go down in a few minutes. Second use, the fake advisor who knows your address and your family situation, enough to inspire confidence on the phone.
The postal address remains. According to CertiK, France concentrated 33 of the 52 physical attacks on cryptocurrency holders recorded around the world in the first half of the year, and each leaked file helps the criminals find a door to ring. Your reflexes are contained in a few words. Replace SMS with an authentication application, never confirm information to someone who calls you, and keep the amount of your assets to yourself.
What to Watch
AI outlook — possibilities, not facts
The ASP will release an official statement in the coming days to address the claimed data leak.
Likely · Within days
Phishing or identity theft attempts targeting the people concerned will increase in the coming weeks.
Very likely · Within weeks
Open Questions
- Has the ASP confirmed the authenticity of the claimed data?
- What is the exact vector of compromise of the ASP system?
- Are banking data (IBAN) actually present in the leak?
- Will the ASP notify the people affected by this leak?






