CTIPilot

La Protection Civile eProtec platform data breach (France, 2026)

incident · incident:protection-civile-eprotec-breach-2026-08

Fédération Nationale de Protection Civile confirmed on 2026-08-21 a hack and personal-data breach on its eProtec volunteer-management platform dated to March 2026 and discovered mid-August; civil-status data, phone numbers and photographs of volunteers, former volunteers, externals and minors are affected, with no passwords or banking data involved per the federation; volume (FrenchBreaches assesses 525,000+ profiles) is not itself confirmed by the FNPC, which says it is still determining the number of people affected (Franceinfo/AFP, 2026-08-21).

Aliases: Protection Civile eProtec breach, FNPC data breach 2026

Coverage timeline
1
first 2026-08-28 → last 2026-08-28
Peak priority
notable
1 notable
Sources cited
3
3 hosts
Sections touched
1
active-threats
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
1
pinned v19.2 · see below

Hunting pivots

ATT&CK techniques

ATT&CK techniques

1 technique observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Collection TA0009

T1213Data from Information Repositories×1

Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. Adversaries may also abuse external sharing features to share sensitive documents with recipients outside of the organization (i.e., Transfer Data to Cloud Account).

Evidence: 2026-08-28/protection-civile-france-eprotec-breach-volunteers · ATT&CK page ↗

Story timeline

  1. 2026-08-28La Protection Civile (France): eProtec volunteer-management platform breach, 525,000+ profiles including minors, intrusion dated to March 2026 discovered mid-August
    active-threatsA French civil-security federation confirms a five-month-old intrusion the same week several comparable sports federations were also hit

Where this entity is cited

  • active-threats1

Source distribution

  • christophemazzola.fr1 (33%)
  • franceinfo.fr1 (33%)
  • frenchbreaches.com1 (33%)

explore in graph

Entries about La Protection Civile eProtec platform data breach (France, 2026) (1)

2026-08-28 · view entry permalink →

NOTABLEupdatedNATOB2

La Protection Civile (France): eProtec volunteer-management platform breach, 525,000+ profiles including minors, intrusion dated to March 2026 discovered mid-August

La Fédération Nationale de Protection Civile (FNPC) confirmed on 2026-08-21 (via a spokesperson statement to AFP and a written communiqué, both quoted directly by Franceinfo) that it was the victim of a hack and "personal data breach" (translated from French) in March 2026 on the eProtec platform used to manage the volunteers, schedules and training of this state-approved civil security association: "announced on Friday 21 August that it had been the victim of a computer intrusion and a 'personal data breach' in March" (translated from French) (Franceinfo (AFP), 2026-08-21).

The FNPC states the attack "fits within a context of multiple attacks carried out over the same period against comparable organisations, notably several sports federations" (translated from French) (FNPC communiqué, quoted by Franceinfo, 2026-08-21) (fits a pattern of contemporaneous attacks on comparable structures, including several sports federations) framing this as part of a wider wave rather than a targeted campaign against it specifically. Exposed data includes civil-status information, phone numbers and profile photographs of current volunteers, former volunteers and people external to the organisation, including minors: "the data concerns Protection Civile volunteers, former volunteers and persons external to the Protection Civile" (translated from French) (FNPC communiqué, quoted by Franceinfo, 2026-08-21); the FNPC explicitly states no data belonging to people the Protection Civile has rescued is involved. FrenchBreaches, analysing samples of the exfiltrated data, reports a narrower and hedged non-finding: "the currently available elements do not allow us to establish the presence of passwords, banking details or ID documents in the exfiltrated data" (translated from French) (FrenchBreaches, 2026-08) - an absence of evidence in what the tracker has seen, not a statement by the federation that no such data is in the leak.

The federation says it only became aware of the breach on 17 August and that its investigation cannot yet determine whether the exposed data was actually consulted or extracted, nor whether it was sold, used or made public: "at this stage, the investigations do not make it possible to determine whether all of this data was actually accessed or extracted, nor whether it was sold, used or made public" (translated from French) (FNPC communiqué, quoted by Franceinfo, 2026-08-21); it has filed a complaint with the Paris prosecutor's cybercrime unit. The commonly cited "525,000+ profiles / 15,000 photographs" figure comes from FrenchBreaches, the specialist outlet that first surfaced the breach; the FNPC itself says it is still trying to establish the exact number of people affected, so that volume should be attributed to the tracker, not treated as an organisational confirmation.

announced on Friday 21 August that it had been the victim of a computer intrusion (translated from French)

fits within a context of multiple attacks carried out over the same period against comparable organisations, notably several sports federations. (translated from French)

The data concerns Protection Civile volunteers, former volunteers and persons external to the Protection Civile. (translated from French)

At this stage, the investigations do not make it possible to determine whether all of this data was actually accessed or extracted, nor whether it was sold, used or made public. (translated from French)

Franceinfo (AFP) 2026-08-21

the currently available elements do not allow us to establish the presence of passwords, banking details or ID documents in the exfiltrated data (translated from French)

FrenchBreaches
Correctionrun 2026-08-30T1312Z-auditevidencesourcing_notebody

The statement that neither passwords nor banking details appear in the leak was attributed here to the FNPC. The federation says no such thing. The source of that claim is FrenchBreaches, which analysed samples of the exfiltrated data and reports a hedged non-finding: "the currently available elements do not allow us to establish the presence of passwords, banking details or ID documents in the exfiltrated data" (translated from French) (FrenchBreaches, 2026-08). For anyone reasoning about credential-reuse or fraud exposure for the affected volunteers, that is a materially weaker basis than a federation assurance, and it should be read as what one tracker did not find in the sample it obtained. The date the federation became aware of the breach is also stated as a single date, 17 August, matching the source.

incident28 Aug 06:44Zmulti-sourceOpen finding ↗