A data breach at the French Social Security Service Pajemploi has exposed the personal information of approximately 1.2 million individuals.
“The Pajemploi service has been the victim of a theft of personal data belonging to employees of private employers using the Pajemploi service,” the agency disclosed, according to an auto-translated statement.
Pajemploi is part of the URSSAF (Unions de Recouvrement des cotisations de Sécurité Sociale et d’Allocations Familiales), which collects social contributions from employers and individual contributors.
French social security service Pajemploi confirms data breach
According to its statement, Pajemploi detected the data breach on November 14 and took immediate steps to prevent the threat actor from pivoting to other systems.
It also notified the French Data Protection Authority (CNIL) and the National Agency for the Security of Information Systems (ANSSI), as well as every affected individual, in accordance with its legal obligations. The Social Security Service also launched an investigation to determine the nature and scope of the incident.
On its conclusion, the probe determined that the data breach leaked the victims’ full names, birthplaces, postal addresses, Social Security Numbers, Pajemploi and accreditation numbers, and the names of their banking institutions.
However, the attackers did not access the victims’ bank account numbers (IBANs), email addresses, phone numbers, or account passwords. The attack also did not interrupt operations at the social security service, suggesting that ransomware was not deployed.
At the time of publication, no cybercrime gang has publicly claimed responsibility for the cyber attack, and the social security service has not confirmed receiving ransom demands.
Meanwhile, the social security service advises victims to be aware of potential phishing attacks when interacting with unsolicited emails, text messages, and phone calls.
Although the attackers did not access the victims’ contact information, which is invaluable for conducting phishing attacks, they could match that information with PII from previous data breaches and social media profiles.
Nevertheless, the data breach affected only childcare providers using the social security service, not their employers.
French social security agencies targeted by cybercriminals
Cybercriminals have previously targeted France’s social security agencies, compromising the personal information of millions of citizens. In March 2024, attackers breached France Travail, formerly Pôle Emploi, which registers unemployed individuals and provides employment assistance.
That data breach compromised the personal information of over 43 million people registered in the past two decades, nearly two-thirds of the French population. It leaked the victims’ full names, dates of birth, birthplaces, Social Security Numbers (NIR), France Travail identifiers, email addresses, postal addresses, and phone numbers.
Government-issued identifiers, such as Social Security Numbers, fetch attractive prices on underground cybercrime marketplaces because they enable scammers to commit identity theft and fraud.
In August 2023, France Travail experienced another data breach after hackers breached a third-party provider of digitization services, Majorel.
While the agency did not provide the number of impacted individuals, the data breach affected about 10 million people, according to the French news outlet Le Parisien. It also affected people who had not used the employment service for more than a year, according to the popular French publication.

