www.decryptiondigest.com
Massive Breach of France Titres Exposes 11.7 Million Citizen Records
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
On April 24, 2026, France Titres confirmed a breach of its identity portal, compromising 11.7 million citizen accounts. The breach was attributed to a group of threat actors known as EvilDump, ExtaseHunters, and Breach3d, who claimed to have extracted between 18 and 19 million records. The attack exploited an Insecure Direct Object Reference (IDOR) vulnerability in the ANTS API, allowing unauthorized access to sensitive user data. Affected records include full names, dates of birth, addresses, and unique identifiers, posing significant risks for identity fraud and phishing attacks. The dataset is currently being offered for sale on dark web forums. French authorities, including ANSSI and CNIL, are investigating the breach and have notified affected users. The incident highlights the vulnerabilities in government systems that manage sensitive identity data.
Key Points: • 11.7 million citizen records compromised due to an IDOR vulnerability in the ANTS API. • Threat actors are selling the dataset on dark web forums, increasing risks of identity fraud. • The breach affects both individual and professional accounts, with government-verified identity data.