We use cookies on this website.

By clicking "Accept," you agree to the storage of cookies on your device to improve your browsing experience, analyze site usage, and contribute to our marketing efforts. See our privacy policy for more information.

ASP: The Data Breach Explained, and What an SME Should Check Immediately Afterward

The Services and Payment Agency (ASP) has confirmed a data breach affecting more than 143,000 recipients of the “Coup de pouce énergie” assistance program, with IBANs and Social Security numbers exposed. For an SME, this incident highlights a risk that is easy to check internally: a vulnerability in document access that a public or private website may have without realizing it.

ASP: The Data Breach Explained, and What an SME Should Check Immediately Afterward

In summary: The Services and Payments Agency (ASP) has confirmed a data breach affecting more than 143,000 recipients of the “Coup de pouce énergie” assistance program, with IBANs and Social Security numbers exposed. For an SME, this incident highlights a risk that is easy to check internally: a vulnerability in document access that a public or private website may have without realizing it.

What Happened

The ASP, the agency responsible for distributing government subsidies for energy, vocational training, and agriculture, announced on September 24, 2026, that the personal data of 143,000 recipients of the “Coup de pouce énergie” program had been exposed. Between July and October 2023, this program had provided €250 to approximately 160,000 low-income households in the Île-de-France region, subject to means testing.

According to the ASP, the incident stemmed from unauthorized access to an internal account, which allowed for the exfiltration of documents containing personal identification information, mailing addresses, IBANs, social security numbers (NIR), and the amounts of aid paid out. The attacker, for his part, claims the breach involved an IDOR vulnerability, which involves retrieving documents one by one simply by modifying a reference number in a URL or query. The ASP has not confirmed this specific point. The organization has notified the CNIL and the affected individuals, and urges them to ignore any calls, text messages, or emails requesting confirmation of bank account information related to the program.

This is the second known security incident at the ASP in 2026, following a data breach involving intern data in April.

Does this apply to me?

Direct exposure applies to households in the Île-de-France region that received energy assistance in 2023. However, the ASP administers many other payments to which an SME or its employees may be linked: apprenticeship grants, vocational training funding, agricultural subsidies, and partial-time work programs. If your company or one of your employees has ever received a payment through this agency, caution is advised, even if it falls outside the scope announced today.

The most immediate risk is not the leak itself, but what it enables afterward: a fraudster who possesses a genuine IBAN and NIR can set up a credible SEPA direct debit, or impersonate an ASP agent or your bank representative using accurate supporting information. Incidents like this also fuel broader waves of phishing attacks, which don’t just target the actual payees.

What to Do Now

1. If you or an employee has received assistance from the ASP in recent years, keep an eye on your bank statements over the next few weeks. An unauthorized SEPA direct debit can be disputed with the bank within 13 months.

2. Never disclose your bank account information over the phone, via text message, or by email, even if the person you’re speaking with already knows your name, address, or the amount of financial aid you receive: this information proves nothing; it could have come from the data breach itself.

3. If your small or medium-sized business operates an extranet, a customer portal, or a document submission portal, make sure that access to a document isn’t simply protected by a number that can be viewed in the URL. This is exactly the type of vulnerability (IDOR) discussed here, and one of the easiest things to test during a penetration test.

‍

Not sure about your exposure?

Get an update from an IT Systems expert

A quick assessment of your exposure and the steps you should take. No obligation.

Request an exchange

‍

In a nutshell

A government agency exposed the IBANs and Social Security numbers of 143,000 people after unauthorized access to an internal account. The risk to a company lies less in the data breach itself than in the subsequent fraud attempts—and in whether its own document access systems are vulnerable to the same type of breach. A simple control measure can often prevent the worst from happening.

Frequently asked questions

Should I be concerned if I’ve never received the “Energy Assistance” payment? You’re not directly at risk from this data breach, but remain vigilant against emails or calls impersonating the ASP or your bank: incidents like this often lead to broader phishing campaigns.

What exactly is an IDOR vulnerability? It is an access control flaw where all you need to do is change a number in an address or a request to view another user's document, without needing an additional password.

— Samir Amara, CEO — IT Systèmes

Our latest articles

See more
AI and Cybersecurity Illustration
Cybersecurity

AI and Cybersecurity: The 3 Key Challenges for SMEs and Mid-Sized Companies

AI and Cybersecurity: Securing Your Use of AI, Using It to Defend Yourself, and Countering AI-Powered Attacks. A Guide for Small and Medium-Sized Businesses.
September 25, 2026
Illustration of an agent-based infrastructure operator
Cybersecurity

Agent-Based Infrastructure Operator: Definition and Role

An agent-based infrastructure operator designs, secures, and continuously operates the layer that enables AI agents to act within the information system. Definition, components, a Microsoft 365 example, and eight questions to help you choose an operator.
September 24, 2026
Illustration: iA Agent
Cybersecurity

Agent-Based AI: Definition, How It Works, and Applications

Agent-based AI refers to AI systems capable of pursuing a goal autonomously: they gather information, plan steps, take action within software, and adjust their plan based on the outcome. Definition, operation, risks, governance, and business applications.
September 24, 2026
Abstract illustration of cybersecurity
Cybersecurity

Brevo: The Data Breach Explained, and What an SME Should Check Immediately Afterward

Brevo, the French email marketing platform used by tens of thousands of small and medium-sized businesses, suffered two security incidents in early September 2026: a breach via an authentication vulnerability, followed by the theft of a technical key that allowed malicious code to be injected into client websites. This week, Trezor and Paymium confirmed the extent of the impact on their users. Here’s what an SME that uses Brevo—or one of its widgets—needs to check.
September 24, 2026
Illustration: Protecting Your Small Business from Cyber Threats
Cybersecurity

How to Protect Your Small Business from Cyberattacks in 2026

Technical prevention, business continuity planning (BCP)/disaster recovery planning (DRP), and cyber insurance: the three lines of defense to protect your small business from cyberattacks in 2026.
September 24, 2026
Processing Electronic Invoices Using an AI Accounting Agent
Development & automation

AI Accounting Agent: What It Does with Electronic Invoices

Receiving electronic invoices will be mandatory starting in September 2026: what an AI accounting agent adds to your software, starting at what volume, and at what price.
September 23, 2026