ctipilot.ch
← Back to the live brief
NOTABLENATOC2incident

SUEZ Eau France notifies customers of a technical service provider's breach — identity, contract and, for some customers, bank and identity-document data exposed

first published 2026-08-28 06:46 UTCrun 2026-08-28T0409Z-intel3 sourcessingle-source · victim disclosure

SUEZ Eau France (serving 10M+ users in France, per its own figures) is notifying customers of a security incident at one of its technical service providers, which was compromised by a cyberattack that allowed data access and extraction, with part of the exfiltrated data subsequently made accessible online: "c'est un prestataire technique utilisé par SUEZ Eau France qui aurait été compromis" (Cyberattaque.org, quoting the SUEZ customer notification, 2026-08-20).

Per the notification — quoted or paraphrased independently by three specialist trackers who each state they obtained a copy — affected data may include name, contact details, contract and billing administrative documents, and for some customers identity documents, photographs and bank details (RIB/IBAN): "certaines informations échangées avec ses clients pendant la période concernée peuvent avoir été exposées" (Cyberattaque.org, quoting the SUEZ customer notification, 2026-08-20); an independent analyst roundup records the same categories as confirmed: "technical supplier to Suez Eau France | not disclosed. Bank details, identity documents, contractual papers | Confirmed" (Christophe Mazzola, 2026-08-22). SUEZ states it cannot yet confirm that every notified person's data was actually stolen, and no total affected-count or exact period has been disclosed.

Despite a fair-attempt search across major French and international outlets, none has covered this incident — the only available sourcing remains three independent specialist breach-tracking sites, each relaying the same underlying customer notification letter. That is three independent relays of a first-party document, which is why this entry carries the single-source-victim carve-out rather than a standard single-source label, but it is not independent verification of the letter's contents: no relaying outlet itself carries an established Admiralty B-or-above reliability track record, and no SUEZ public statement or CNIL filing was located.

No access vector is stated by any source; techniques[] carries only T1213 (Data from Information Repositories) for the confirmed outcome — customer data extracted from the technical supplier's own systems — since nothing about how the attacker first got into the supplier's environment is disclosed. As a supplier-origin exposure reaching a water utility serving over 10 million users, the transferable lesson is structural rather than technical: the trust boundary that failed here sits at a technical service provider rather than at SUEZ's own edge, the same shape as several other supplier-origin European disclosures this pipeline has tracked this month. actions[] is empty: no defender-actionable mechanism is disclosed for this organisation-specific incident.

c'est un prestataire technique utilisé par SUEZ Eau France qui aurait été compromis

certaines informations échangées avec ses clients pendant la période concernée peuvent avoir été exposées

Cyberattaque.org (specialist breach tracker) 2026-08-20

Technical supplier to Suez Eau France | not disclosed. Bank details, identity documents, contractual papers | Confirmed

Christophe Mazzola (independent security analyst) 2026-08-22

ATT&CK mapping

1 technique mapped from the cited reporting · MITRE ATT&CK v19.2

Collection TA0009
T1213Data from Information Repositories

Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. Adversaries may also abuse external sharing features to share sensitive documents with recipients outside of the organization (i.e., Transfer Data to Cloud Account).

overlap matrix · ATT&CK page ↗

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.