La Protection Civile (France): eProtec volunteer-management platform breach, 525,000+ profiles including minors, intrusion dated to March 2026 discovered mid-August
A French civil-security federation confirms a five-month-old intrusion the same week several comparable sports federations were also hit
Analysis
La Fédération Nationale de Protection Civile (FNPC) confirmed on 2026-08-21 (via a spokesperson statement to AFP and a written communiqué, both quoted directly by Franceinfo) that it was the victim of a hack and "personal data breach" (translated from French) in March 2026 on the eProtec platform used to manage the volunteers, schedules and training of this state-approved civil security association: "announced on Friday 21 August that it had been the victim of a computer intrusion and a 'personal data breach' in March" (translated from French) (Franceinfo (AFP), 2026-08-21).
The FNPC states the attack "fits within a context of multiple attacks carried out over the same period against comparable organisations, notably several sports federations" (translated from French) (FNPC communiqué, quoted by Franceinfo, 2026-08-21) (fits a pattern of contemporaneous attacks on comparable structures, including several sports federations) framing this as part of a wider wave rather than a targeted campaign against it specifically. Exposed data includes civil-status information, phone numbers and profile photographs of current volunteers, former volunteers and people external to the organisation, including minors: "the data concerns Protection Civile volunteers, former volunteers and persons external to the Protection Civile" (translated from French) (FNPC communiqué, quoted by Franceinfo, 2026-08-21); the FNPC explicitly states no data belonging to people the Protection Civile has rescued is involved. FrenchBreaches, analysing samples of the exfiltrated data, reports a narrower and hedged non-finding: "the currently available elements do not allow us to establish the presence of passwords, banking details or ID documents in the exfiltrated data" (translated from French) (FrenchBreaches, 2026-08) - an absence of evidence in what the tracker has seen, not a statement by the federation that no such data is in the leak.
The federation says it only became aware of the breach on 17 August and that its investigation cannot yet determine whether the exposed data was actually consulted or extracted, nor whether it was sold, used or made public: "at this stage, the investigations do not make it possible to determine whether all of this data was actually accessed or extracted, nor whether it was sold, used or made public" (translated from French) (FNPC communiqué, quoted by Franceinfo, 2026-08-21); it has filed a complaint with the Paris prosecutor's cybercrime unit. The commonly cited "525,000+ profiles / 15,000 photographs" figure comes from FrenchBreaches, the specialist outlet that first surfaced the breach; the FNPC itself says it is still trying to establish the exact number of people affected, so that volume should be attributed to the tracker, not treated as an organisational confirmation.
Cited evidence
announced on Friday 21 August that it had been the victim of a computer intrusion (translated from French)
fits within a context of multiple attacks carried out over the same period against comparable organisations, notably several sports federations. (translated from French)
The data concerns Protection Civile volunteers, former volunteers and persons external to the Protection Civile. (translated from French)
At this stage, the investigations do not make it possible to determine whether all of this data was actually accessed or extracted, nor whether it was sold, used or made public. (translated from French)
the currently available elements do not allow us to establish the presence of passwords, banking details or ID documents in the exfiltrated data (translated from French)
Updates1
The statement that neither passwords nor banking details appear in the leak was attributed here to the FNPC. The federation says no such thing. The source of that claim is FrenchBreaches, which analysed samples of the exfiltrated data and reports a hedged non-finding: "the currently available elements do not allow us to establish the presence of passwords, banking details or ID documents in the exfiltrated data" (translated from French) (FrenchBreaches, 2026-08). For anyone reasoning about credential-reuse or fraud exposure for the affected volunteers, that is a materially weaker basis than a federation assurance, and it should be read as what one tracker did not find in the sample it obtained. The date the federation became aware of the breach is also stated as a single date, 17 August, matching the source.
Sources3
Revision history
- Published 2026-08-28T0409Z-intel
- Correction 2026-08-30T1312Z-audit
Two fixes. The claim that neither passwords nor banking details appear in the leak was attributed to the FNPC; the federation's statement never mentions either, and the finding is FrenchBreaches' own hedged reading of exfiltrated samples, which says the available elements do not allow it to establish their presence. That is an absence of evidence in what one tracker saw, not an organisational assurance, and it is now attributed and hedged as such. The awareness date is also given as a single date, 17 August, matching the source, rather than as a 17-18 August range.
Changed: evidence sourcing_note body
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.