We use cookies on this website.

By clicking "Accept," you agree to the storage of cookies on your device to improve your browsing experience, analyze site usage, and contribute to our marketing efforts. See our privacy policy for more information.

Leaked Ministry of the Interior Directory: The Real Risk to Your Teams Is Targeted Phishing

A hacker has claimed responsibility for leaking a file containing information on 111,528 employees of the Ministry of the Interior, consisting mainly of names, internal IDs, and work email addresses. For an SME, the danger doesn’t come from this file itself, but from the highly credible fake messages that can be created using it. Here’s how your teams can stay one step ahead.

Leaked Ministry of the Interior Directory: The Real Risk to Your Teams Is Targeted Phishing

In summary: A hacker claims to have leaked a file containing the details of 111,528 employees of the Ministry of the Interior, including names, internal IDs, and work email addresses. Your small business isn’t included in this file, but a directory like this serves as raw material for highly convincing phishing emails—and that’s where the risk comes into play for you.

What Happened

On July 26, 2026, an individual using the pseudonym “misere,” acting on behalf of the CuteSec collective, claimed responsibility for obtaining and leaking the data of 111,528 employees affiliated with several government agencies, including the National Gendarmerie. According to the specialized websites Cyberattaque.org and FrenchBreaches, the file reportedly contains internal user IDs, first and last names, work email addresses, and—for some of the employees—a home address.

At this point, the ministry has not confirmed the claim. The number reported corresponds to the volume of records declared by the author, with no guarantee that they represent actual individuals or active agents. The publication comes a few days after another leak involving BANATIC, a platform hosted on the ministry’s domain, though no technical link between the two has been established.

Does this apply to me?

Your company does not appear in this file, yet this issue concerns you. A list of thousands of names associated with business addresses is ideal fodder for targeted phishing: the attacker knows who to write to, what identity to assume, and can mimic the tone of a well-known government agency.

There are two situations that put you at direct risk. If your teams communicate with government agencies, they may receive highly convincing fake emails: requests for supporting documentation, “update” links, or fake reminders. And the same mechanism applies to any corporate directory. The day your own contact information starts circulating, your employees will become the target of a tailor-made message.

What to Do Now

Three key steps, from the most urgent to the most fundamental.

1. Take your time with "official" emails that seem urgent. Any urgent or unusual request warrants verification. Check the sender's full email address—not just the displayed name—and confirm through another channel before clicking, forwarding a document, or making a payment.

2. Enable multi-factor authentication (MFA) everywhere. Start with Microsoft 365 and sensitive accounts. Even if a password is leaked or compromised, the second factor blocks access in the vast majority of cases.

3. Give your teams clear instructions this week. A specific name and a work address don’t prove anything. When in doubt, don’t respond—report it to IT. This shared approach is better than any filter.

To learn more about targeted attacks and how to detect them, our dedicated guide details the warning signs to look for: Spear Phishing in the Workplace: Understanding, Detecting, and Protecting Against It.

Not sure about your exposure?

Get an update from an IT Systems expert

A quick assessment of your exposure and the steps you should take. No obligation.

Request an exchange

In a nutshell

A list of names and email addresses doesn’t make the news by chance—it fuels targeted scams. The precautions that keep you safe are simple: check the sender, enable MFA, and be wary of urgent requests. With these basics in place, an SME can weather this kind of news without any major issues.

— Samir Amara, CEO — IT Systèmes

Frequently asked questions

Should you notify the CNIL? You are only required to file a report if your own personal data has been leaked. In this case, the data breach involves government employees, not your company.

How can we tell if one of our email addresses has already been compromised? Monitoring services allow you to check whether an email address appears in publicly available databases. For your business accounts, the most effective step is to enable MFA immediately.

Our latest articles

See more
software
Development & automation

"I'm afraid to install software"

In 1996, I took my first steps in computing on an Excel spreadsheet where I filed cheat codes for my favorite video games. 🕹️Le the beginning of a passion for office tools (to each his own 😅 ). There were 3,000 machines connected to the internet! 😶 But what happened next?
July 3, 2026
fishing
Cybersecurity

Phishing 2026: Definition, Examples, and Protection for Small and Medium-Sized Businesses (Comprehensive Guide)

Spear phishing, BEC, voice deepfakes: why training alone isn’t enough, the true cost of an incident (€275,000), and the security measures that will work in 2026
June 26, 2026
backup-vs-retention
Cloud & infrastructure

Comparing backup VS retention

Backup VS retention: here's the match everyone's been waiting for!!!! 🥊 (okai not at all but I needed a catchy title..🤫)
July 3, 2026