www.decryptiondigest.com Massive Breach of France Titres Exposes 11.7 Million Citizen Records
Article Content
- •11.7 million citizen records compromised due to an IDOR vulnerability in the ANTS API.
- •Threat actors are selling the dataset on dark web forums, increasing risks of identity fraud.
- •The breach affects both individual and professional accounts, with government-verified identity data.
On April 24, 2026, France Titres confirmed a breach of its identity portal, compromising 11.7 million citizen accounts. The breach was attributed to a group of threat actors known as EvilDump, ExtaseHunters, and Breach3d, who claimed to have extracted between 18 and 19 million records. The attack exploited an Insecure Direct Object Reference (IDOR) vulnerability in the ANTS API, allowing unauthorized access to sensitive user data. Affected records include full names, dates of birth, addresses, and unique identifiers, posing significant risks for identity fraud and phishing attacks. The dataset is currently being offered for sale on dark web forums. French authorities, including ANSSI and CNIL, are investigating the breach and have notified affected users. The incident highlights the vulnerabilities in government systems that manage sensitive identity data.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track France Titres in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
BlueMoon Exploit Kit Targeting Chrome and Windows by Multiple State Actors A new exploit kit named BlueMoon has been rapidly adopted by at least four espionage groups, primarily linked to China, exploiting vulnerabilities in Google Chrome and Microsoft Windows. The first observed use of BlueMoon was on August 28, 2026, by the China-aligned threat actor TA412, with subsequent adoption by…