Back to all articles
data-breachfrancedark-webthreat-intelligenceidentity-theftgovernment-breach

French Data Index: 52M Records from ANTS, CAF, SFR and 22 More Breaches

Threat actor compiles 52.5M French records from government agencies, telecoms, and retailers into dark web index. ANTS, CAF, Hellowork, and SFR data exposed.

CIFER Security Team8 min read

A threat actor known as Addka72424 has compiled a massive database index containing 52,511,569 verified records from 25 separate French datasets, according to dark web forum postings reported by security researchers.

The threat actor describes France as "currently a very leaky country" and has created what they call a "temporary unofficial index" of leaked French databases. All datasets are claimed to be verified, backed up, and downloadable after unlocking with forum credits.

The Scale of Exposure

MetricValue
Total records52,511,569
Source datasets25
Country targetedFrance πŸ‡«πŸ‡·
Industries affectedMultiple
Sample dataAvailable on forum
Threat actorAddka72424
Access methodForum credits unlock

Complete Database Index

The following 25 databases comprise the full index:

Government & Public Services (16.6M+ records)

SourceRecordsYearDescription
ANTS12,091,9142025French National Agency for Secure Documents
CAF.fr / Pass'Sport6,368,6772025French social security & youth sports program
Francetravail.fr302,3132025French government job agency
Pajemploi.fr689,4152025Childminder employment service

Telecommunications & ISPs (19.7M+ records)

SourceRecordsYearDescription
France.fr ISP19,192,9472024French Internet Service Provider
SFR / OSIRIS490,1532024French telecom operator

Employment & Education (3.6M+ records)

SourceRecordsYearDescription
Hellowork2,864,1362025French job platform
Grenoble EM448,0022024–2025French business school
Allegromusique.fr161,4132025French music education platform
Gofluent.com89,4592025Language learning platform

Retail & E-Commerce (2.3M+ records)

SourceRecordsYearDescription
Cultura.com1,219,2632025French cultural retailer
Truffaut.com277,8262025Gardening & home dΓ©cor retailer
Cybertek.fr241,1252024Computer & networking retailer
Clin-d'Oeil.fr459,8612025French optician company

Sports Federations (3.4M+ records)

SourceRecordsYearDescription
French Sports Federations3,277,6872025Collection of sports federation breaches
Echecs.asso.fr113,9532025French Chess Federation

Financial & Professional Services (2.4M+ records)

SourceRecordsYearDescription
Reduction-impots.fr1,927,0772025French wealth management
Clyosystems.com147,8202023French financial software company
Europages French clients205,4032025Business directory clients

Other Services (2.5M+ records)

SourceRecordsYearDescription
Multiple French websites1,654,1112025Various French websites collection
Chronopost.fr861,0842025French shipping company
Murfy.fr497,6472025Home appliance repair company
Homedesign3d.net300,4632025Interior design application
Auto-ici.fr180,7832025French auto dealer
Trescal.com70,9812025Metrology & calibration services
EDF.fr32,167UnknownFrench energy company

Why Data Aggregation Is Dangerous

While individual breaches expose isolated data points, aggregated databases compound risk exponentially:

1. Cross-Referencing Enables Identity Reconstruction

When records from 25 different sources are merged, attackers can:

  • Match partial records across datasets
  • Fill gaps in victim profiles
  • Verify data accuracy through correlation
  • Build comprehensive identity packages

2. Verified Data Commands Premium Prices

The listing emphasizes "verified records" β€” meaning the data has been:

  • De-duplicated and cleaned
  • Validated against live systems
  • Tested for freshness and accuracy
  • Organized for immediate exploitation

3. Searchable Indexes Enable Targeted Attacks

Unlike raw data dumps, indexed databases allow attackers to:

Query: "Find all records matching:
  - Age: 35-55
  - Income: >€80,000
  - Location: Paris
  - Has mortgage: Yes"

Result: Targeted list for financial fraud

Attack Vectors Enabled

With 52 million French records indexed, criminal operations can scale dramatically:

Identity Fraud

Attack TypeEnabler
Loan fraudFull identity packages
Account takeoverEmail + password combinations
Tax fraudPersonal + financial data
Insurance fraudHealth + identity records
Benefit fraudGovernment ID details

Social Engineering

  • Spear phishing: Personalized attacks using real employer, bank, or family details
  • Vishing: Phone scams leveraging verified phone numbers with personal context
  • CEO fraud: Targeting executives with researched profiles
  • Romance scams: Building fake personas using real-world details

Financial Crimes

  • SIM swapping at scale using verified phone/identity combinations
  • Credit card fraud using aggregated payment histories
  • Cryptocurrency theft through targeted phishing
  • Real estate fraud with complete identity documentation

High-Value Targets in the Index

ANTS β€” National Secure Documents Agency

The 12 million records from ANTS (Agence Nationale des Titres SΓ©curisΓ©s) are particularly concerning. This agency handles:

  • Passports and national ID cards
  • Driver's licenses
  • Vehicle registration documents
  • Foreigner residence permits

Breach of ANTS data could enable:

  • Document fraud at scale
  • Identity theft with government-level verification data
  • Border crossing fraud
  • Vehicle registration fraud

CAF / Pass'Sport β€” Social Security Data

The 6.4 million records from CAF (Caisse d'Allocations Familiales) and Pass'Sport contain:

  • Social security numbers
  • Family composition data
  • Income declarations
  • Youth sports program enrollment

This data enables benefit fraud and targeted social engineering against families.

Hellowork β€” Employment Data

The 2.8 million job seeker records include:

  • CVs with full work history
  • Salary expectations
  • Contact information
  • Professional qualifications

Ideal for recruiter impersonation and employment scams.


Why France Is a "Leaky Country"

The threat actor's characterization reflects systemic issues:

FactorImpact
Centralized government servicesSingle breaches expose millions
Rich social welfare dataHigh-value targets for fraud
Fragmented corporate securityMultiple retail/service breaches
Valuable EU citizenshipPremium for identity documents
Strong purchasing powerAttractive for financial fraud

The index spans 2023–2025 breaches, indicating ongoing vulnerability rather than isolated incidents.


What This Means for French Organizations

Immediate Risks

Organizations whose data may be included in these 25 source datasets face:

  1. Regulatory exposure: GDPR notification requirements and potential fines
  2. Reputational damage: Loss of customer trust when breaches surface
  3. Fraud liability: Increased fraud attempts against customers
  4. Legal action: Potential class action from affected individuals

Customer Impact

French citizens should assume their data may be compromised and:

  • Enable fraud alerts with credit agencies
  • Monitor accounts for unauthorized activity
  • Use unique passwords across all services
  • Enable MFA on financial and email accounts
  • Be skeptical of unsolicited contact (even if caller knows personal details)

Defensive Measures

For Organizations

Immediate:

  • Audit recent data access logs for anomalies
  • Review third-party vendor security posture
  • Implement or enhance data classification
  • Enable database activity monitoring

Strategic:

  • Adopt encryption at rest for all sensitive data
  • Implement data minimization (don't store what you don't need)
  • Deploy behavioral analytics for account monitoring
  • Conduct regular penetration testing

For Individuals

ActionPriority
Credit freeze/alertsπŸ”΄ High
Password manager adoptionπŸ”΄ High
MFA on all accountsπŸ”΄ High
Identity theft monitoring🟑 Medium
Reduce data sharing🟑 Medium

The Aggregation Economy

This incident highlights a maturing cybercrime ecosystem where:

  1. Initial access brokers steal raw data
  2. Data processors clean, verify, and enrich records
  3. Index operators aggregate and organize for searchability
  4. Fraud operators purchase targeted subsets for specific schemes

Each layer adds value β€” and increases danger. A threat actor like Addka72424 specializing in aggregation represents the industrialization of identity fraud.


Key Takeaways

  • 52.5M French records from 25 sources now searchable on dark web
  • Government agencies breached: ANTS (12M), CAF/Pass'Sport (6.4M), Francetravail
  • Major corporations affected: France.fr ISP (19M), SFR, Chronopost, Cultura, EDF
  • Threat actor describes France as "very leaky country" β€” systemic vulnerability
  • Data spans 2023–2025 β€” indicating ongoing, unresolved security failures
  • Verified and indexed β€” ready for immediate exploitation

The most effective defense against aggregated data attacks is ensuring that even when data is stolen, it remains encrypted and unusable. Traditional perimeter security cannot prevent data aggregation β€” only data-level protection can limit the damage.


Concerned about data aggregation attacks? Learn how CIFER's encryption architecture ensures your data remains protected even when systems are compromised.