2026-08-28 · view entry permalink →
SUEZ Eau France notifies customers of a technical service provider's breach, identity, contract and, for some customers, bank and identity-document data exposed
SUEZ Eau France (serving 10M+ users in France, per its own figures) is notifying customers of a security incident at one of its technical service providers, which was compromised by a cyberattack that allowed data access and extraction, with part of the exfiltrated data subsequently made accessible online: "it is a technical service provider used by SUEZ Eau France that is reported to have been compromised" (translated from French) (Cyberattaque.org, quoting the SUEZ customer notification, 2026-08-20).
Per the notification (quoted or paraphrased independently by three specialist trackers who each state they obtained a copy) affected data may include name, contact details, contract and billing administrative documents, and for some customers identity documents, photographs and bank details (RIB/IBAN): "certain information exchanged with its customers during the period concerned may have been exposed" (translated from French) (Cyberattaque.org, quoting the SUEZ customer notification, 2026-08-20); an independent analyst roundup records the same categories as confirmed: "technical supplier to Suez Eau France | not disclosed. Bank details, identity documents, contractual papers | Confirmed" (Christophe Mazzola, 2026-08-22). SUEZ states it cannot yet confirm that every notified person's data was actually stolen, and no total affected-count or exact period has been disclosed.
All available sourcing is three independent specialist breach-tracking sites relaying the same underlying SUEZ customer notification letter; no SUEZ public statement or CNIL filing has been located, and nothing about how the attacker first got into the supplier's environment is disclosed. The confirmed outcome is customer data extracted from the technical supplier's own systems, a supplier-origin exposure reaching a water utility serving over 10 million users, the same shape as several other supplier-origin European disclosures this month.
it is a technical service provider used by SUEZ Eau France that is reported to have been compromised. (translated from French)
certain information exchanged with its customers during the period concerned may have been exposed. (translated from French)
Technical supplier to Suez Eau France | not disclosed. Bank details, identity documents, contractual papers | Confirmed