CTIPilot

Hôpital privé de la Loire (Ramsay Santé) DPI breach and 2026 CNIL sanction

incident · incident:hopital-prive-de-la-loire-dpi-breach-2025 single-source-national-cert

Summer-2025 breach of Hôpital privé de la Loire's externally-reachable electronic patient record system via a single compromised physician account lacking VPN/MFA, exposing 727,113 individuals' data; sanctioned by CNIL with a EUR 500,000 GDPR fine on 2026-09-03 for Article 32 and 34 failures (CNIL, BleepingComputer, 2026-09-03).

Aliases: HPL breach, Loire private hospital breach

Coverage timeline
1
first 2026-09-04 → last 2026-09-04
Peak priority
notable
1 notable
Sources cited
3
3 hosts
Sections touched
1
active-threats
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
2
pinned v19.2 · see below

Hunting pivots

ATT&CK techniques

ATT&CK techniques

2 techniques observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-09-04/cnil-fine-hopital-prive-de-la-loire-dpi-breach · ATT&CK page ↗

Persistence TA0003

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-09-04/cnil-fine-hopital-prive-de-la-loire-dpi-breach · ATT&CK page ↗

Privilege Escalation TA0004

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-09-04/cnil-fine-hopital-prive-de-la-loire-dpi-breach · ATT&CK page ↗

Stealth TA0005

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-09-04/cnil-fine-hopital-prive-de-la-loire-dpi-breach · ATT&CK page ↗

Collection TA0009

T1213Data from Information Repositories×1

Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. Adversaries may also abuse external sharing features to share sensitive documents with recipients outside of the organization (i.e., Transfer Data to Cloud Account).

Evidence: 2026-09-04/cnil-fine-hopital-prive-de-la-loire-dpi-breach · ATT&CK page ↗

Story timeline

  1. 2026-09-04CNIL fines Hôpital privé de la Loire EUR 500,000 over a 727,000-record breach traced to a single unprotected external physician account
    active-threatsFrance's data regulator details exactly how one compromised doctor account exposed an entire hospital's patient records

Where this entity is cited

  • active-threats1

Source distribution

  • bleepingcomputer.com1 (33%)
  • cnil.fr1 (33%)
  • databreaches.net1 (33%)

explore in graph

Entries about Hôpital privé de la Loire (Ramsay Santé) DPI breach and 2026 CNIL sanction (1)

2026-09-04 · view entry permalink →

NOTABLENATOA2

CNIL fines Hôpital privé de la Loire EUR 500,000 over a 727,000-record breach traced to a single unprotected external physician account

France's CNIL imposed a EUR 500,000 GDPR fine on 3 September 2026 against Hôpital privé de la Loire (HPL, Saint-Étienne, part of the Ramsay Santé group) over a summer-2025 breach of its externally-reachable electronic patient-record system, which exposed 524,867 patients and 202,246 people designated as "trusted third parties", 727,113 individuals total (CNIL, 2026-09-03). CNIL's investigation names three compounding failures. First, the authentication procedure for external users (private-practice physicians accessing the record system from outside the hospital) required no VPN and no multi-factor authentication, and the attacker used the credentials of a single compromised physician account to get in. Second, the access-control model had no concept of "care team" restricting an account to the patients that physician actually treats, so one set of valid credentials opened every hospital patient's record. Third, with no real-time or near-real-time anomaly detection on the record system, the attacker was able to enumerate and extract records over several days undetected; CNIL states this absence "contributed to exacerbating the scale of the data breach." A self-identified attacker using the alias "Marak" told the French outlet Le Progrès via Telegram at the time that the intrusion began with a single doctor's account, and separately attempted to sell the stolen data for EUR 2,000-5,000; it was later reported that the data was in fact neither sold nor published. These are unconfirmed criminal self-claims, consistent with but not independently verified against CNIL's own findings (BleepingComputer, 2026-09-03).

CNIL separately sanctioned HPL under GDPR Article 34 for notifying only the direct patients affected and never notifying the 202,246 trusted third parties whose data was also taken. HPL has begun remediation and has three to fifteen months, depending on measure type, to complete it.

The authentication procedure to connect to the hospital's e-Health Patient Summary, used by users outside the hospital, in particular liberal doctors, was not sufficiently robust, due to the lack of VPNs and multifactor authentication means. The attacker took advantage of this vulnerability to access the data.

This lack of access limitation allowed the attacker, using the credentials of a single user account, to access the data of all hospital patients.

the attacker was able to explore the hospital's e-Health Patient Summary for several days and extract a very large volume of data, without that abnormal activity being detected

CNIL
incident04 Sep 05:30Zsingle-source · national CERTOpen finding ↗