CTIPilot

SUEZ Eau France technical-supplier data breach (France, 2026-08)

incident · incident:suez-eau-france-supplier-breach-2026-08 single-source-victim

SUEZ Eau France notified customers in August 2026 of a breach at a technical service provider, exposing identity, contact and contract data and in some cases bank details and identity documents; sourced only through specialist breach-tracking outlets relaying the customer notification letter, no A/B-grade outlet or SUEZ public statement located as of 2026-08-28.

Coverage timeline
1
first 2026-08-28 → last 2026-08-28
Peak priority
notable
1 notable
Sources cited
3
3 hosts
Sections touched
1
active-threats
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
1
pinned v19.2 · see below

Hunting pivots

ATT&CK techniques

ATT&CK techniques

1 technique observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Collection TA0009

T1213Data from Information Repositories×1

Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. Adversaries may also abuse external sharing features to share sensitive documents with recipients outside of the organization (i.e., Transfer Data to Cloud Account).

Evidence: 2026-08-28/suez-eau-france-supplier-breach · ATT&CK page ↗

Story timeline

  1. 2026-08-28SUEZ Eau France notifies customers of a technical service provider's breach, identity, contract and, for some customers, bank and identity-document data exposed
    active-threatsA French water utility's supplier breach reaches customer identity documents and bank details, sourced only through specialist trackers

Where this entity is cited

  • active-threats1

Source distribution

  • christophemazzola.fr1 (33%)
  • cyberattaque.org1 (33%)
  • fuitesinfos.fr1 (33%)

explore in graph

Entries about SUEZ Eau France technical-supplier data breach (France, 2026-08) (1)

2026-08-28 · view entry permalink →

NOTABLENATOC2

SUEZ Eau France notifies customers of a technical service provider's breach, identity, contract and, for some customers, bank and identity-document data exposed

SUEZ Eau France (serving 10M+ users in France, per its own figures) is notifying customers of a security incident at one of its technical service providers, which was compromised by a cyberattack that allowed data access and extraction, with part of the exfiltrated data subsequently made accessible online: "it is a technical service provider used by SUEZ Eau France that is reported to have been compromised" (translated from French) (Cyberattaque.org, quoting the SUEZ customer notification, 2026-08-20).

Per the notification (quoted or paraphrased independently by three specialist trackers who each state they obtained a copy) affected data may include name, contact details, contract and billing administrative documents, and for some customers identity documents, photographs and bank details (RIB/IBAN): "certain information exchanged with its customers during the period concerned may have been exposed" (translated from French) (Cyberattaque.org, quoting the SUEZ customer notification, 2026-08-20); an independent analyst roundup records the same categories as confirmed: "technical supplier to Suez Eau France | not disclosed. Bank details, identity documents, contractual papers | Confirmed" (Christophe Mazzola, 2026-08-22). SUEZ states it cannot yet confirm that every notified person's data was actually stolen, and no total affected-count or exact period has been disclosed.

All available sourcing is three independent specialist breach-tracking sites relaying the same underlying SUEZ customer notification letter; no SUEZ public statement or CNIL filing has been located, and nothing about how the attacker first got into the supplier's environment is disclosed. The confirmed outcome is customer data extracted from the technical supplier's own systems, a supplier-origin exposure reaching a water utility serving over 10 million users, the same shape as several other supplier-origin European disclosures this month.

it is a technical service provider used by SUEZ Eau France that is reported to have been compromised. (translated from French)

certain information exchanged with its customers during the period concerned may have been exposed. (translated from French)

Cyberattaque.org (specialist breach tracker) 2026-08-20

Technical supplier to Suez Eau France | not disclosed. Bank details, identity documents, contractual papers | Confirmed

Christophe Mazzola (independent security analyst) 2026-08-22
incident28 Aug 06:46Zsingle-source · victim disclosureOpen finding ↗