In summary: The Services and Payments Agency (ASP) has confirmed a data breach affecting more than 143,000 recipients of the “Coup de pouce énergie” assistance program, with IBANs and Social Security numbers exposed. For an SME, this incident highlights a risk that is easy to check internally: a vulnerability in document access that a public or private website may have without realizing it.
What Happened
The ASP, the agency responsible for distributing government subsidies for energy, vocational training, and agriculture, announced on September 24, 2026, that the personal data of 143,000 recipients of the “Coup de pouce énergie” program had been exposed. Between July and October 2023, this program had provided €250 to approximately 160,000 low-income households in the Île-de-France region, subject to means testing.
According to the ASP, the incident stemmed from unauthorized access to an internal account, which allowed for the exfiltration of documents containing personal identification information, mailing addresses, IBANs, social security numbers (NIR), and the amounts of aid paid out. The attacker, for his part, claims the breach involved an IDOR vulnerability, which involves retrieving documents one by one simply by modifying a reference number in a URL or query. The ASP has not confirmed this specific point. The organization has notified the CNIL and the affected individuals, and urges them to ignore any calls, text messages, or emails requesting confirmation of bank account information related to the program.
This is the second known security incident at the ASP in 2026, following a data breach involving intern data in April.
Does this apply to me?
Direct exposure applies to households in the Île-de-France region that received energy assistance in 2023. However, the ASP administers many other payments to which an SME or its employees may be linked: apprenticeship grants, vocational training funding, agricultural subsidies, and partial-time work programs. If your company or one of your employees has ever received a payment through this agency, caution is advised, even if it falls outside the scope announced today.
The most immediate risk is not the leak itself, but what it enables afterward: a fraudster who possesses a genuine IBAN and NIR can set up a credible SEPA direct debit, or impersonate an ASP agent or your bank representative using accurate supporting information. Incidents like this also fuel broader waves of phishing attacks, which don’t just target the actual payees.
What to Do Now
1. If you or an employee has received assistance from the ASP in recent years, keep an eye on your bank statements over the next few weeks. An unauthorized SEPA direct debit can be disputed with the bank within 13 months.
2. Never disclose your bank account information over the phone, via text message, or by email, even if the person you’re speaking with already knows your name, address, or the amount of financial aid you receive: this information proves nothing; it could have come from the data breach itself.
3. If your small or medium-sized business operates an extranet, a customer portal, or a document submission portal, make sure that access to a document isn’t simply protected by a number that can be viewed in the URL. This is exactly the type of vulnerability (IDOR) discussed here, and one of the easiest things to test during a penetration test.
Not sure about your exposure?
Get an update from an IT Systems expert
A quick assessment of your exposure and the steps you should take. No obligation.
In a nutshell
A government agency exposed the IBANs and Social Security numbers of 143,000 people after unauthorized access to an internal account. The risk to a company lies less in the data breach itself than in the subsequent fraud attempts—and in whether its own document access systems are vulnerable to the same type of breach. A simple control measure can often prevent the worst from happening.
Frequently asked questions
Should I be concerned if I’ve never received the “Energy Assistance” payment? You’re not directly at risk from this data breach, but remain vigilant against emails or calls impersonating the ASP or your bank: incidents like this often lead to broader phishing campaigns.
What exactly is an IDOR vulnerability? It is an access control flaw where all you need to do is change a number in an address or a request to view another user's document, without needing an additional password.
— Samir Amara, CEO — IT Systèmes


.png)



