
Hauts-de-France reports contractor data breach with up to 700,000 records exposed
The regional administration of Hauts-de-France confirmed on 3 October 2026 that a cyberattack on service providers Atexo and Docaposte compromised citizen files and banking records, with online claims citing over 700,000 victims.
External contractors breached
The regional council of Hauts-de-France announced on Saturday, 3 October 2026, that a cyberattack had compromised databases managed by two external contractors. The targeted companies are Atexo, a software publisher specializing in digital tools for public sector authorities, and Docaposte, a digital subsidiary of La Poste that manages secure professional document workflows. Unauthorised intruders breached the contractors' digital environments and accessed personal records processed under regional administration contracts. Regional authorities disclosed the breach following initial technical findings from both service partners.
Two of its service providers, Atexo and Docaposte, were victims of a cyberattack that allowed unauthorized access to personal data processed on its behalf.
Stolen personal and banking records
Initial technical assessments confirmed that exposed citizen data includes surnames, first names, and email addresses. Regional officials warned that French bank identity statements, known as RIBs, and additional identity records were also potentially exposed during the intrusion. Regional administrators stated that they could not yet verify the exact number of individuals impacted or whether additional data categories were extracted. According to FrenchBreaches, a cybersecurity breach tracking platform, an individual on a cybercriminal forum claimed responsibility on Saturday, asserting possession of personal files covering more than 700,000 people.
Names, first names, email addresses, as well as potentially bank details and other identification data are among the data likely to have been compromised.
Student aid and business grants targeted
The exfiltrated documents relate to specific regional subsidy mechanisms, according to details published by FrenchBreaches. One prominent target was the Génération#HDF portal, an initiative that provides financial cards to high school pupils and apprentices for textbooks and school equipment. Compromised files allegedly leaked by the cybercriminal include signed apprenticeship contracts, official certificates of accommodation, and direct bank details. The leaked cache also encompasses records from regional enterprise programs that assist local entrepreneurs, company founders, and project leaders seeking public aid and administrative guidance.
Platform shutdowns and legal response
Regional officials initiated emergency containment procedures prior to making the cyberattack public on Saturday. Technical teams immediately closed down the affected online platforms, and the administration began issuing direct warnings to impacted users starting on Friday. Hauts-de-France authorities also filed a formal legal complaint with law enforcement and judicial authorities to trigger an official criminal investigation into the intrusion. The regional administration affirmed that it remains mobilized alongside its technical providers to determine the complete perimeter of the attack. Cybersecurity specialists note that stolen administrative and banking records are routinely resold on illicit data markets to fuel fraudulent financial schemes and identity theft.
- Regional authorities close compromised platforms and begin alerting users
- FrenchBreaches identifies database leak claims on a cybercriminal forum
- Regional council confirms the cyberattack and files a formal legal complaint

