We use cookies on this website.

By clicking "Accept," you agree to the storage of cookies on your device to improve your browsing experience, analyze site usage, and contribute to our marketing efforts. See our privacy policy for more information.

Cybersecurity

INSEE Data Breach: What an SME Should Check

On June 26, 2026, INSEE confirmed a data breach involving its internal directory (12,800 employees). The real risk for small and medium-sized businesses: highly targeted phishing campaigns.

INSEE Data Breach: What an SME Should Check

In summary: INSEE experienced a leak of its internal directory, affecting 12,800 current and former employees, with no banking or sensitive data exposed. The danger for a company is not the leak itself, but what attackers can do with a verified professional contact list.

What Happened

On June 26, 2026, INSEE announced that it had been the target of a cyberattack aimed at its internal directory, known as Trombi. The incident was detected on June 19. It exposed the identities and work contact information of approximately 12,800 current and former employees and members of its staff, according to reports by Usine Digitale and Le Monde Informatique.

The institute states that no banking information or sensitive data was compromised. The data breach involves names, job titles, assignments, and work contacts. As required by the GDPR, INSEE has notified the CNIL and filed a complaint with the public prosecutor.

Does this apply to me?

You may not be INSEE, but the following mechanism affects you directly. A stolen business directory provides attackers with high-quality raw material: exact names, real job titles, and valid addresses. With this information, they craft credible messages addressed to the right person, in the name of a colleague or business partner who actually exists.

The risk shifts to you as soon as one of your employees, suppliers, or customers is included in a database of this kind. A fake email “from” a known contact, a request for an urgent wire transfer, a malicious attachment—it all becomes harder to spot when the sender appears legitimate. Contact information alone is enough. No password is needed to launch a spear-phishing attack.

What to Do Now

1. Remind employees of the double-check rule. Any request for a wire transfer, an IBAN change, or access received via email or text message must be verified through a second, pre-approved channel—such as a call to a previously registered number. This simple precaution prevents the majority of fraud attempts, even the most sophisticated ones.

2. Strengthen authentication on Microsoft 365. Enable MFA everywhere and monitor rules for automatic mailbox forwarding, which attackers often set up after an initial compromise. A protected account significantly limits the damage caused by a single malicious email that slips through.

3. Alert your teams with a concrete example. A short note is better than a training session that gets forgotten. Show them what a well-crafted phishing email looks like, and designate someone to whom they can report any concerns without fear of bothering them.

For more information on this type of targeted attack, see our feature on spear-phishing in the workplace.

‍

Not sure about your exposure?

Get an update from an IT Systems expert

A quick assessment of your exposure and the steps you should take. No obligation.

Request an exchange

‍

In a nutshell

The leak of the INSEE directory isn't aimed at you, but it fuels attacks that can target any company. The right response isn't to panic; it's to secure bank transfers with a double-check process and tighten access to email accounts. With these two measures in place, stolen contact information will have no effect.

Frequently asked questions

Is my data included in this data breach? Only if you work or have worked for INSEE. However, any company may receive fraudulent emails created using this contact information.

Should you change your passwords? This data breach does not contain any passwords. The best practice remains using two-factor authentication and being vigilant about unusual emails.

— Samir Amara, CEO — IT Systèmes

Our latest articles

See more

ASP: The Data Breach Explained, and What an SME Should Check Immediately Afterward

The Services and Payment Agency (ASP) has confirmed a data breach affecting more than 143,000 recipients of the “Coup de pouce énergie” assistance program, with IBANs and Social Security numbers exposed. For an SME, this incident highlights a risk that is easy to check internally: a vulnerability in document access that a public or private website may have without realizing it.
September 25, 2026
AI and Cybersecurity Illustration
Cybersecurity

AI and Cybersecurity: The 3 Key Challenges for SMEs and Mid-Sized Companies

AI and Cybersecurity: Securing Your Use of AI, Using It to Defend Yourself, and Countering AI-Powered Attacks. A Guide for Small and Medium-Sized Businesses.
September 25, 2026
Illustration of an agent-based infrastructure operator
Cybersecurity

Agent-Based Infrastructure Operator: Definition and Role

An agent-based infrastructure operator designs, secures, and continuously operates the layer that enables AI agents to act within the information system. Definition, components, a Microsoft 365 example, and eight questions to help you choose an operator.
September 24, 2026
Illustration: iA Agent
Cybersecurity

Agent-Based AI: Definition, How It Works, and Applications

Agent-based AI refers to AI systems capable of pursuing a goal autonomously: they gather information, plan steps, take action within software, and adjust their plan based on the outcome. Definition, operation, risks, governance, and business applications.
September 24, 2026
Abstract illustration of cybersecurity
Cybersecurity

Brevo: The Data Breach Explained, and What an SME Should Check Immediately Afterward

Brevo, the French email marketing platform used by tens of thousands of small and medium-sized businesses, suffered two security incidents in early September 2026: a breach via an authentication vulnerability, followed by the theft of a technical key that allowed malicious code to be injected into client websites. This week, Trezor and Paymium confirmed the extent of the impact on their users. Here’s what an SME that uses Brevo—or one of its widgets—needs to check.
September 24, 2026
Illustration: Protecting Your Small Business from Cyber Threats
Cybersecurity

How to Protect Your Small Business from Cyberattacks in 2026

Technical prevention, business continuity planning (BCP)/disaster recovery planning (DRP), and cyber insurance: the three lines of defense to protect your small business from cyberattacks in 2026.
September 24, 2026