AFPA (France's national adult vocational-training agency) confirms a data extraction potentially affecting up to 1.7 million people, traced to a flaw in a third-party-hosted accommodation-management tool
AFPA confirms a breach in a vendor-hosted tool after two criminal claims a day apart point to the same third-party flaw
Analysis
AFPA (Agence nationale pour la formation des adultes), France's national public adult vocational-training agency, has confirmed a "potential data extraction" after two criminal-forum claims surfaced within 24 hours of each other in mid-September 2026 (Clubic, 2026-09-20). The handle xMetah first offered 971,420 records for sale on 2026-09-15; the following day, Cybernox (separately tracked for exposing 101 AFPA accounts a month earlier, with no established link between that exposure and this extraction) claimed 1,732,811 records via an alleged insecure direct object reference (IDOR) flaw (Cyberattaque.org, 2026-09-19). AFPA's own investigation traced the "potential extraction" to a flaw in a third-party-hosted tool it uses to manage worker accommodation, which AFPA's deputy director Pierre Prady told AFP is external to the agency's own information system, so there was "a priori" no impact on AFPA's own services. AFPA has not confirmed the IDOR mechanism Cybernox claims, and has not stated whether the two claimed datasets overlap or were extracted from the same source; FrenchBreaches states the two figures must not simply be summed to declare a combined victim count (FrenchBreaches, 2026-09-19). AFPA states the affected application held identity, address and possibly phone-number data, with no banking data or French national ID (Sécurité sociale) numbers identified so far; Cyberattaque.org's own sample review additionally found full dates of birth, internal identifiers and a "partner" field (one observed value, "LHEA," suggesting a partner-feed origin), while noting that several fields provisioned for email addresses, a second phone number or other contact details were observed empty in its samples (Cyberattaque.org, 2026-09-19); FrenchBreaches' separate, independent sample review instead found populated email addresses and nationality fields, in records spanning creation or modification dates from 2006 through 2026 (FrenchBreaches, 2026-09-19). Clubic's reporting notes AFPA has not stated whether it has notified the CNIL, despite GDPR's 72-hour breach-notification requirement.
Cited evidence
According to AFPA, the hacked application contained people's identity and address, and possibly their phone number, but "a priori" no banking data or Social Security number. (translated from French)
This tool 'is hosted by a third-party vendor and is external to our information system, so there was, a priori, no impact on AFPA's own services and information systems.' (translated from French)
AFPA now confirms that a data extraction potentially took place and states that the incident could affect up to 1.7 million people. (translated from French)
Sources3
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.