2026-08-28 · view entry permalink →
SUEZ Eau France notifies customers of a technical service provider's breach — identity, contract and, for some customers, bank and identity-document data exposed
SUEZ Eau France (serving 10M+ users in France, per its own figures) is notifying customers of a security incident at one of its technical service providers, which was compromised by a cyberattack that allowed data access and extraction, with part of the exfiltrated data subsequently made accessible online: "c'est un prestataire technique utilisé par SUEZ Eau France qui aurait été compromis" (Cyberattaque.org, quoting the SUEZ customer notification, 2026-08-20).
Per the notification — quoted or paraphrased independently by three specialist trackers who each state they obtained a copy — affected data may include name, contact details, contract and billing administrative documents, and for some customers identity documents, photographs and bank details (RIB/IBAN): "certaines informations échangées avec ses clients pendant la période concernée peuvent avoir été exposées" (Cyberattaque.org, quoting the SUEZ customer notification, 2026-08-20); an independent analyst roundup records the same categories as confirmed: "technical supplier to Suez Eau France | not disclosed. Bank details, identity documents, contractual papers | Confirmed" (Christophe Mazzola, 2026-08-22). SUEZ states it cannot yet confirm that every notified person's data was actually stolen, and no total affected-count or exact period has been disclosed.
Despite a fair-attempt search across major French and international outlets, none has covered this incident — the only available sourcing remains three independent specialist breach-tracking sites, each relaying the same underlying customer notification letter. That is three independent relays of a first-party document, which is why this entry carries the single-source-victim carve-out rather than a standard single-source label, but it is not independent verification of the letter's contents: no relaying outlet itself carries an established Admiralty B-or-above reliability track record, and no SUEZ public statement or CNIL filing was located.
No access vector is stated by any source; techniques[] carries only T1213 (Data from Information Repositories) for the confirmed outcome — customer data extracted from the technical supplier's own systems — since nothing about how the attacker first got into the supplier's environment is disclosed. As a supplier-origin exposure reaching a water utility serving over 10 million users, the transferable lesson is structural rather than technical: the trust boundary that failed here sits at a technical service provider rather than at SUEZ's own edge, the same shape as several other supplier-origin European disclosures this pipeline has tracked this month. actions[] is empty: no defender-actionable mechanism is disclosed for this organisation-specific incident.
c'est un prestataire technique utilisé par SUEZ Eau France qui aurait été compromis
certaines informations échangées avec ses clients pendant la période concernée peuvent avoir été exposées
Technical supplier to Suez Eau France | not disclosed. Bank details, identity documents, contractual papers | Confirmed