2026-08-28 · view entry permalink →
La Protection Civile (France): eProtec volunteer-management platform breach, 525,000+ profiles including minors, intrusion dated to March 2026 discovered mid-August
La Fédération Nationale de Protection Civile (FNPC) confirmed on 2026-08-21 — via a spokesperson statement to AFP and a written communiqué, both quoted directly by Franceinfo — that it was the victim of a hack and "violation de données à caractère personnel" in March 2026 on the eProtec platform used to manage the volunteers, schedules and training of this state-approved civil security association: "a annoncé vendredi 21 août avoir été victime d'un piratage informatique et d'une 'violation de données à caractère personnel' au mois de mars" (Franceinfo (AFP), 2026-08-21).
The FNPC states the attack "s'inscrit dans un contexte d'attaques multiples menées au cours de la même période à l'encontre de structures comparables, notamment plusieurs fédérations sportives" (FNPC communiqué, quoted by Franceinfo, 2026-08-21) — fits a pattern of contemporaneous attacks on comparable structures, including several sports federations — framing this as part of a wider wave rather than a targeted campaign against it specifically. Exposed data includes civil-status information, phone numbers and profile photographs of current volunteers, former volunteers and people external to the organisation, including minors: "ces données concernent des bénévoles de la Protection civile, des anciens bénévoles et des personnes externes à la Protection civile" (FNPC communiqué, quoted by Franceinfo, 2026-08-21); the FNPC explicitly states no data belonging to people the Protection Civile has rescued is involved, and that neither passwords nor banking details appear in the leak.
The federation says it only became aware of the breach around 17–18 August and that its investigation cannot yet determine whether the exposed data was actually consulted or extracted, nor whether it was sold, used or made public: "à ce stade, les investigations ne permettent pas de déterminer si l'ensemble de ces données a effectivement été consulté ou extrait, ni si elles ont été vendues, utilisées ou rendues publiques" (FNPC communiqué, quoted by Franceinfo, 2026-08-21) — it has filed a complaint with the Paris prosecutor's cybercrime unit. The commonly cited "525,000+ profiles / 15,000 photographs" figure comes from FrenchBreaches, the specialist outlet that first surfaced the breach; the FNPC itself says it is still trying to establish the exact number of people affected, so that volume should be attributed to the tracker, not treated as an organisational confirmation.
No access vector is stated by any source; techniques[] carries only T1213 (Data from Information Repositories) for the confirmed outcome — personal-data records extracted from the eProtec volunteer-management platform's own data store — since nothing about how the attacker first got in is disclosed. actions[] is empty: no defender-actionable mechanism is disclosed for this organisation-specific incident.
a annoncé vendredi 21 août avoir été victime d'un piratage informatique et d'une "violation de données à caractère personnel" au mois de mars
s'inscrit dans un contexte d'attaques multiples menées au cours de la même période à l'encontre de structures comparables, notamment plusieurs fédérations sportives
Ces données concernent des bénévoles de la Protection civile, des anciens bénévoles et des personnes externes à la Protection civile
A ce stade, les investigations ne permettent pas de déterminer si l'ensemble de ces données a effectivement été consulté ou extrait, ni si elles ont été vendues, utilisées ou rendues publiques