In summary: A hacker claims to have leaked a file containing the details of 111,528 employees of the Ministry of the Interior, including names, internal IDs, and work email addresses. Your small business isn’t included in this file, but a directory like this serves as raw material for highly convincing phishing emails—and that’s where the risk comes into play for you.
What Happened
On July 26, 2026, an individual using the pseudonym “misere,” acting on behalf of the CuteSec collective, claimed responsibility for obtaining and leaking the data of 111,528 employees affiliated with several government agencies, including the National Gendarmerie. According to the specialized websites Cyberattaque.org and FrenchBreaches, the file reportedly contains internal user IDs, first and last names, work email addresses, and—for some of the employees—a home address.
At this point, the ministry has not confirmed the claim. The number reported corresponds to the volume of records declared by the author, with no guarantee that they represent actual individuals or active agents. The publication comes a few days after another leak involving BANATIC, a platform hosted on the ministry’s domain, though no technical link between the two has been established.
Does this apply to me?
Your company does not appear in this file, yet this issue concerns you. A list of thousands of names associated with business addresses is ideal fodder for targeted phishing: the attacker knows who to write to, what identity to assume, and can mimic the tone of a well-known government agency.
There are two situations that put you at direct risk. If your teams communicate with government agencies, they may receive highly convincing fake emails: requests for supporting documentation, “update” links, or fake reminders. And the same mechanism applies to any corporate directory. The day your own contact information starts circulating, your employees will become the target of a tailor-made message.
What to Do Now
Three key steps, from the most urgent to the most fundamental.
1. Take your time with "official" emails that seem urgent. Any urgent or unusual request warrants verification. Check the sender's full email address—not just the displayed name—and confirm through another channel before clicking, forwarding a document, or making a payment.
2. Enable multi-factor authentication (MFA) everywhere. Start with Microsoft 365 and sensitive accounts. Even if a password is leaked or compromised, the second factor blocks access in the vast majority of cases.
3. Give your teams clear instructions this week. A specific name and a work address don’t prove anything. When in doubt, don’t respond—report it to IT. This shared approach is better than any filter.
To learn more about targeted attacks and how to detect them, our dedicated guide details the warning signs to look for: Spear Phishing in the Workplace: Understanding, Detecting, and Protecting Against It.
Not sure about your exposure?
Get an update from an IT Systems expert
A quick assessment of your exposure and the steps you should take. No obligation.
In a nutshell
A list of names and email addresses doesn’t make the news by chance—it fuels targeted scams. The precautions that keep you safe are simple: check the sender, enable MFA, and be wary of urgent requests. With these basics in place, an SME can weather this kind of news without any major issues.
— Samir Amara, CEO — IT Systèmes
Frequently asked questions
Should you notify the CNIL? You are only required to file a report if your own personal data has been leaked. In this case, the data breach involves government employees, not your company.
How can we tell if one of our email addresses has already been compromised? Monitoring services allow you to check whether an email address appears in publicly available databases. For your business accounts, the most effective step is to enable MFA immediately.



