CTIPilot

AFPA third-party accommodation-tool data extraction (September 2026)

incident · incident:afpa-third-party-accommodation-tool-data-extraction-2026-09

AFPA confirmed a potential data extraction, tied by its own investigation to a flaw in a third-party-hosted worker-accommodation-management tool outside its own IS, following criminal claims by xMetah (971,420 records) and Cybernox (1,732,811 records via an alleged IDOR) published 24 hours apart in mid-September 2026; up to 1.7 million people are potentially affected (AFP/franceinfo via Clubic, Cyberattaque.org, FrenchBreaches).

Coverage timeline
1
first 2026-09-21 → last 2026-09-21
Peak priority
notable
1 notable
Sources cited
3
3 hosts
Sections touched
1
active-threats
Co-occurring entities
2
see Co-occurring entities below
ATT&CK techniques
2
pinned v19.2 · see below

Hunting pivots

ATT&CK techniques

ATT&CK techniques

2 techniques observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-09-21/afpa-third-party-accommodation-tool-data-extraction · ATT&CK page ↗

Collection TA0009

T1213Data from Information Repositories×1

Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. Adversaries may also abuse external sharing features to share sensitive documents with recipients outside of the organization (i.e., Transfer Data to Cloud Account).

Evidence: 2026-09-21/afpa-third-party-accommodation-tool-data-extraction · ATT&CK page ↗

Story timeline

  1. 2026-09-21AFPA (France's national adult vocational-training agency) confirms a data extraction potentially affecting up to 1.7 million people, traced to a flaw in a third-party-hosted accommodation-management tool
    active-threatsAFPA confirms a breach in a vendor-hosted tool after two criminal claims a day apart point to the same third-party flaw

Relationships explore in graph

Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.

related to

Where this entity is cited

  • active-threats1

Source distribution

  • clubic.com1 (33%)
  • cyberattaque.org1 (33%)
  • frenchbreaches.com1 (33%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about AFPA third-party accommodation-tool data extraction (September 2026) (1)

2026-09-21 · view entry permalink →

NOTABLENATOB1

AFPA (France's national adult vocational-training agency) confirms a data extraction potentially affecting up to 1.7 million people, traced to a flaw in a third-party-hosted accommodation-management tool

AFPA (Agence nationale pour la formation des adultes), France's national public adult vocational-training agency, has confirmed a "potential data extraction" after two criminal-forum claims surfaced within 24 hours of each other in mid-September 2026 (Clubic, 2026-09-20). The handle xMetah first offered 971,420 records for sale on 2026-09-15; the following day, Cybernox (separately tracked for exposing 101 AFPA accounts a month earlier, with no established link between that exposure and this extraction) claimed 1,732,811 records via an alleged insecure direct object reference (IDOR) flaw (Cyberattaque.org, 2026-09-19). AFPA's own investigation traced the "potential extraction" to a flaw in a third-party-hosted tool it uses to manage worker accommodation, which AFPA's deputy director Pierre Prady told AFP is external to the agency's own information system, so there was "a priori" no impact on AFPA's own services. AFPA has not confirmed the IDOR mechanism Cybernox claims, and has not stated whether the two claimed datasets overlap or were extracted from the same source; FrenchBreaches states the two figures must not simply be summed to declare a combined victim count (FrenchBreaches, 2026-09-19). AFPA states the affected application held identity, address and possibly phone-number data, with no banking data or French national ID (Sécurité sociale) numbers identified so far; Cyberattaque.org's own sample review additionally found full dates of birth, internal identifiers and a "partner" field (one observed value, "LHEA," suggesting a partner-feed origin), while noting that several fields provisioned for email addresses, a second phone number or other contact details were observed empty in its samples (Cyberattaque.org, 2026-09-19); FrenchBreaches' separate, independent sample review instead found populated email addresses and nationality fields, in records spanning creation or modification dates from 2006 through 2026 (FrenchBreaches, 2026-09-19). Clubic's reporting notes AFPA has not stated whether it has notified the CNIL, despite GDPR's 72-hour breach-notification requirement.

According to AFPA, the hacked application contained people's identity and address, and possibly their phone number, but "a priori" no banking data or Social Security number. (translated from French)

This tool 'is hosted by a third-party vendor and is external to our information system, so there was, a priori, no impact on AFPA's own services and information systems.' (translated from French)

Clubic

AFPA now confirms that a data extraction potentially took place and states that the incident could affect up to 1.7 million people. (translated from French)

Cyberattaque.org 2026-09-19
incident21 Sep 04:48Zmulti-sourceOpen finding ↗