Data breach
French Ministère de l'Intérieur
- Records
- 111,512
- Breach date
- 12 December 2025Estimated
- Added
- 18 September 2026
What was exposed
2 types of data · 1 more reported
- Email addresses111,512
- Names108,210
- Criminal recordsReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
Hackers breached email servers belonging to France's Interior Ministry in December 2025 and accessed sensitive law enforcement databases, and a dataset tied to the intrusion now contains email addresses and names for roughly 111,500 individuals. According to our investigation team, the indexed dataset holds 111,512 records, including 111,512 email addresses and 108,210 names. The ministry confirmed the attack publicly, though French officials initially described the extracted material as far smaller than the figure in our listing. No group has claimed the breach on our listing.
December 11-12, 2025: The Interior Ministry detected suspicious activity overnight targeting its email systems, Interior Minister Laurent Nuñez confirmed on RTL on December 12.
December 17, 2025: Nuñez said the attack was more serious than first believed, that attackers had consulted the criminal records database (TAJ) and the wanted persons file (FPR), and that a 22-year-old suspect had been arrested, according to Reuters and Le Figaro.
January 2026: Speaking to the French Senate's law committee, the minister put the theft at 23 wanted-persons records, 72 criminal-record files, and thousands of summary entries, Le Monde later reported.
August 20, 2026: Le Monde published an investigation tracing the breach to a Rhadamanthys infostealer infection on an agriculture ministry employee's home computer, which harvested credentials used to move deeper into state networks.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses (111,512 records) and names (108,210 records).
The wider intrusion also touched police systems. Nuñez told lawmakers that attackers consulted the Treatment of Criminal Records file, known as TAJ, and the Wanted Persons File, or FPR, per Le Figaro. A hacker group claimed access to data on 16 million people; the minister called that figure false, and Euronews reported his remarks.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Email addresses and names are the building blocks of targeted phishing. Attackers can use real government-affiliated context to craft convincing messages about fines, immigration files, or court matters. Because the intrusion also reached criminal records and wanted-persons databases, people whose full records were exposed could face more serious harms, including extortion or threats tied to their legal history. Officials told the press the compromise did not endanger lives, but the full scope was never publicly settled.
What Is French Ministère de l'Intérieur Doing in Response?
The ministry's response is well documented. Nuñez said a judicial investigation was opened, led by France's anti-cybercrime office, alongside an internal administrative review. The CNIL, France's data protection authority, was notified, and the security agency ANSSI was brought in to harden systems. The minister announced immediate remediation, including account closures and mandatory two-factor authentication for staff. A suspect was arrested and later placed under formal investigation, according to Reuters and Le Monde.
What Should You Do If You Were Affected?
If your email appears in this dataset, treat any message claiming to come from a French government office with suspicion. Do not click links or open attachments in unexpected emails about fines, court dates, or identity checks, and verify such claims through official channels instead. Use a strong, unique password for your email account and turn on two-factor authentication where it is offered. If you believe your personal data from government files was misused, you can file a complaint with the CNIL or report it to the police. Watch your accounts for signs of unauthorized access over the coming months.
