We use cookies on this website.

By clicking "Accept," you agree to the storage of cookies on your device to improve your browsing experience, analyze site usage, and contribute to our marketing efforts. See our privacy policy for more information.

Cybersecurity

Ministry of the Interior Directory Leak: The Risk of Phishing

A hacker has leaked a file containing information on 111,528 employees of the Ministry of the Interior (names, work email addresses). The danger for small and medium-sized businesses: highly credible fake messages.

Ministry of the Interior Directory Leak: The Risk of Phishing

In summary: A hacker claims to have leaked a file containing the details of 111,528 employees of the Ministry of the Interior, including names, internal IDs, and work email addresses. Your small business isn’t included in this file, but a directory like this serves as raw material for highly convincing phishing emails—and that’s where the risk comes into play for you.

What Happened

On July 26, 2026, an individual using the pseudonym “misere,” acting on behalf of the CuteSec collective, claimed responsibility for obtaining and leaking the data of 111,528 employees affiliated with several government agencies, including the National Gendarmerie. According to the specialized websites Cyberattaque.org and FrenchBreaches, the file reportedly contains internal user IDs, first and last names, work email addresses, and—for some of the employees—a home address.

At this point, the ministry has not confirmed the claim. The number reported corresponds to the volume of records declared by the author, with no guarantee that they represent actual individuals or active agents. The publication comes a few days after another leak involving BANATIC, a platform hosted on the ministry’s domain, though no technical link between the two has been established.

Does this apply to me?

Your company does not appear in this file, yet this issue concerns you. A list of thousands of names associated with business addresses is ideal fodder for targeted phishing: the attacker knows who to write to, what identity to assume, and can mimic the tone of a well-known government agency.

There are two situations that put you at direct risk. If your teams communicate with government agencies, they may receive highly convincing fake emails: requests for supporting documentation, “update” links, or fake reminders. And the same mechanism applies to any corporate directory. The day your own contact information starts circulating, your employees will become the target of a tailor-made message.

What to Do Now

Three key steps, from the most urgent to the most fundamental.

1. Take your time with "official" emails that seem urgent. Any urgent or unusual request warrants verification. Check the sender's full email address—not just the displayed name—and confirm through another channel before clicking, forwarding a document, or making a payment.

2. Enable multi-factor authentication (MFA) everywhere. Start with Microsoft 365 and sensitive accounts. Even if a password is leaked or compromised, the second factor blocks access in the vast majority of cases.

3. Give your teams clear instructions this week. A specific name and a work address don’t prove anything. When in doubt, don’t respond—report it to IT. This shared approach is better than any filter.

To learn more about targeted attacks and how to detect them, our dedicated guide details the warning signs to look for: Spear Phishing in the Workplace: Understanding, Detecting, and Protecting Against It.

Not sure about your exposure?

Get an update from an IT Systems expert

A quick assessment of your exposure and the steps you should take. No obligation.

Request an exchange

In a nutshell

A list of names and email addresses doesn’t make the news by chance—it fuels targeted scams. The precautions that keep you safe are simple: check the sender, enable MFA, and be wary of urgent requests. With these basics in place, an SME can weather this kind of news without any major issues.

— Samir Amara, CEO — IT Systèmes

Frequently asked questions

Should you notify the CNIL? You are only required to file a report if your own personal data has been leaked. In this case, the data breach involves government employees, not your company.

How can we tell if one of our email addresses has already been compromised? Monitoring services allow you to check whether an email address appears in publicly available databases. For your business accounts, the most effective step is to enable MFA immediately.

Our latest articles

See more
Helpy Barometer: Resolution rate for Level 1 tickets among customers with IT Systems' full-service management contracts
MSP & Managed IT Services: Proactive IT Management for Small and Medium-Sized Businesses

Helpy Barometer 2026: 60% of Level 1 tickets resolved without human intervention

60% of Level 1 tickets are closed without human intervention, in an average of 3 minutes. Three months of data collection from 55 contracted customers, including the methodology.
September 10, 2026
Cybersecurity

Chrome Vulnerability CVE-2026-85046: Should Small and Medium-Sized Businesses Patch It Immediately?

On September 3, Google patched a vulnerability—identified as CVE-2026-85046—that had already been exploited in Chrome’s V8 engine. A malicious web page is all it takes to execute code on the user’s device. Since Edge, Brave, and Opera are all based on the same Chromium framework, the issue of update timelines is a concern for all small and medium-sized businesses.
September 9, 2026
Cybersecurity

Safety Maintenance (MCS): Definition and Method

Security Maintenance (MCS) ensures a system remains secure over time: definition, differences from MCO, ANSSI and NIS2 requirements, and methodology.
September 8, 2026
Custom Software Development Providers for Small and Medium-Sized Businesses and Mid-Size Companies
Development & automation

Top Custom Software Development Providers for Small and Medium-Sized Businesses in France in 2026

Which company can develop your custom business software? A comparison of four French service providers based on market positioning, starting price, and turnaround time, for small and medium-sized businesses.
September 10, 2026
Cybersecurity

PaperCut Vulnerability Exploited (CVE-2026-82078): Is Your Print Server Affected?

On August 27, 2026, PaperCut released an emergency patch for two vulnerabilities in its NG and MF print servers, which had already been exploited by attackers. CERT-FR relayed the alert and updated it on August 31 with new indicators. Here’s how to find out in just a few minutes if your company is affected—and what to do in the hours that follow.
September 3, 2026
Cybersecurity

Hello, E.Leclerc: The leak came from a service provider—here’s what an SME should check with its own staff

LCommerce, the company that operates the Allo E.Leclerc service, has informed some of its customers that one of its external logistics providers had been hacked. Names, email addresses, and phone numbers were compromised, but no banking information was exposed. The incident was reported to the CNIL and serves as a reminder that a company can be affected even if its own system has not been compromised.
September 1, 2026