Home » 90 Million Accounts in One Month: The Scale of Data Breaches in France

90 Million Accounts in One Month: The Scale of Data Breaches in France

by Christian

In January 2026, data from more than 90 million accounts was leaked in France. This unprecedented wave highlights the fragility of the regulations imposed on businesses and government agencies, as well as the consequences of centralizing personal data.

Data Breaches Reach a New Record in France

In recent months, announcements and posts regarding new data breaches affecting thousands—or even millions—of French citizens have proliferated on social media.

Although it is difficult to make an accurate comparison with leaks from previous years—since these are not always made public—it is clear that personal data leaks now affect millions of French people.

Data compiled by the monitoring site BonjourLaFuite helps quantify the scale of these breaches. According to this site, between January 1 and 31, 2026, data from more than 90 million accounts was leaked as a result of various security incidents.

Excerpt from the BonjourLaFuite website

Excerpt from the BonjourLaFuite website

These leaks can be caused by insufficient security in the databases of companies or organizations, allowing hackers to access them remotely. But the threat can also come from within; several cases reveal that some malicious employees sell the data or profiles of targeted individuals to criminal networks.

A few recent examples illustrate the seriousness of the situation: in January, the restaurant chain O’Tacos suffered a data breach involving 29 million customer profiles; Panorama Banques lost 2.3 million; the French Volleyball Federation lost approximately 1.2 million; and URSSAF lost nearly 12 million.

These data breaches exposed information such as first and last names, email addresses, and sometimes even mailing addresses, phone numbers, ID photos, IP addresses, and more.

These staggering figures, on their own, approach the total number of data breaches recorded for the entire year of 2025, estimated at approximately 100 million accounts.

France Travail was also recently fined 5 million euros by the CNIL following a data breach in 2024 that exposed the personal information of 36.8 million people. This is an absurd situation, to say the least, in which one public agency is sanctioned by another—all funded by taxpayer money.

How do these data breaches put our lives at risk?

The rise in data breaches highlights the limitations of current anti-money laundering and counter-terrorism financing (AML-CTF) measures, particularly those involving know-your-customer (KYC) verification requirements.

By requiring exchange platforms and online services to store sensitive data (identities, addresses, account balances, etc.), regulators have effectively created targets for criminals. When these databases are compromised—which is becoming increasingly common—the consequences go far beyond simple identity theft.

Since the beginning of 2025, there has been an alarming rise in “crypto-kidnappings,” in which individuals identified by their digital assets are abducted and/or assaulted in order to extort their cryptocurrencies. Criminals sometimes even target family members.

Naturally, when data breaches affect elected officials, the response is immediate. Yaël Braun-Pivet, President of the National Assembly, referred the matter to the Public Prosecutor as soon as personal information concerning members of the Assembly and its staff was published. This swift response stands in stark contrast to the usual inaction when millions of French citizens have their data exposed every month.

The most absurd thing is that these KYC identification measures have proven ineffective against fraud, which is often carried out using stolen accounts or straw men. Furthermore, the economic and human costs incurred by regulated platforms far exceed the fraudulent funds recovered by the authorities.

In this already concerning context, France has just passed a law banning children under 15 from accessing social media. Presented as a child protection measure, it actually mandates the systematic collection of all users’ identities, further increasing the attack surface in the event of a data breach.

Rather than protecting citizens, these policies expose more sensitive data, creating digital time bombs—also known as “honey pots”—that attackers will have no trouble targeting.

Related Posts

Leave a Comment