{"id":4328,"date":"2026-01-31T06:38:24","date_gmt":"2026-01-31T06:38:24","guid":{"rendered":"http:\/\/ft365.org\/index.php\/2026\/01\/31\/france-fines-national-employment-agency-e5m-over-2024-data-breach\/"},"modified":"2026-01-31T06:38:24","modified_gmt":"2026-01-31T06:38:24","slug":"france-fines-national-employment-agency-e5m-over-2024-data-breach","status":"publish","type":"post","link":"https:\/\/ft365.org\/index.php\/2026\/01\/31\/france-fines-national-employment-agency-e5m-over-2024-data-breach\/","title":{"rendered":"France Fines National Employment Agency \u20ac5m Over 2024 Data Breach"},"content":{"rendered":"<div id=\"cphContent_pnlArticleBody\" data-layout-id=\"2\" data-edit-folder-name=\"text\" data-index=\"0\">\n<p>The French employment agency, France Travail, has received a \u20ac5m ($6m) fine for security failures that led to the compromise of an estimated 43 million jobseekers.<\/p>\n<p>In a public statement on January 29, 2026, France\u2019s data protection regulator, the Commission Nationale de l\u2019Informatique et des Libert\u00e9s (CNIL), said it issued sanctions against France Travail following an investigation into the data breach.<\/p>\n<h2><strong>France Travail Breach: Personal Data of 43m Users at Risk<\/strong><\/h2>\n<p>In March 2024, France Travail announced that its IT systems and those of Cap Emploi, a government employment service that supports people with disabilities, were breached.<\/p>\n<p>According to France Travail, exposed personal data included names, social security numbers, dates of birth, user IDs, email and postal addresses, and phone numbers of France Travail and Cap Emploi users.<\/p>\n<p>However, the attackers did not gain access to any jobseekers\u2019 complete France Travail files nor any healthcare data.<\/p>\n<p>The data breach could affect users who registered on Cap Emploi over the past 20 years, representing 43 million potential users\u2019 data exposed.<\/p>\n<div>\n<p>Following the incident, the Paris\u00a0public prosecutor&#8217;s office announced that the French police arrested three individuals, all based in France and aged 21, 22 and 23 at the time. They were suspected to be behind the breach.<\/p>\n<p> A judicial investigation was opened relating to charges of &#8220;fraudulent access to and maintenance of an automated data processing system, extraction of such data, fraud and money laundering.&#8221;<\/p>\n<\/div>\n<h2><strong>France Travail\u2019s Response Violated GDPR, Regulator Says <\/strong><\/h2>\n<p>The CNIL opened another investigation to determine whether sufficient data security measures were in place in compliance with the EU\u2019s General Data Protection Regulation (GDPR).<\/p>\n<p>This investigation concluded on January 22, 2026. It found multiple security and organizational issues at France Travail and said the agency \u201cfailed to secure the personal data of jobseekers.\u201d<\/p>\n<p>Specifically, The CNIL found the following France Travail shortcomings:<\/p>\n<ul>\n<li>Inadequate technical and organizational measures: France Travail failed to implement sufficient security controls to make the cyber-attack harder, violating Article 32 of the GDPR (obligation to ensure appropriate security)<\/li>\n<li>Weak authentication for Cap Emploi advisors: The login methods used by Cap Emploi advisors to access France Travail\u2019s systems were not robust enough, increasing vulnerability<\/li>\n<li>Poor logging and monitoring: The agency lacked effective logging measures to detect unusual or suspicious activity in its systems<\/li>\n<li>Overly broad access permissions: Cap Emploi advisors had excessive access rights, allowing them to view data of individuals they were not assisting, which expanded the breach\u2019s impact<\/li>\n<\/ul>\n<p>Furthermore, the CNIL investigation concluded that, while France Travail had identified some of the necessary security measures to mitigate such a threat in its data protection impact assessments (DPIAs), it did not implement them in practice.<\/p>\n<p>The \u20ac5m penalty takes into account the failure to comply with fundamental security principles, the number of individuals affected and the volume and sensitivity of the data processed.<\/p>\n<p>Additionally, the CNIL has ordered France Travail to provide evidence of corrective measures implemented, following a strict timeline. Failure to meet these deadlines will result in a \u20ac5000 ($5980) daily fine.<\/p>\n<p>The CNIL also noted that, as a publicly funded administrative body \u2013 financed through employer and employee social contributions \u2013 France Travail\u2019s budget is legally fixed. Because of this, GDPR fines (under Article 32) are not tied to revenue but instead fall within a set range, with a maximum penalty of \u20ac10m ($11.9m) for data security failures.<\/p>\n<p>France Travail suffered another data breach in July 2025 on its \u201cemployment\u201d portal, used by its partners, that could have exposed personal data of 340,000 users<em>. <\/em>The latest CNIL fine does not cover this incident.<\/p>\n<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>The French employment agency, France Travail, has received a \u20ac5m ($6m) fine for security failures that led to the compromise of an estimated 43 million jobseekers. In a public statement on January 29, 2026, France\u2019s data protection regulator, the Commission Nationale de l\u2019Informatique et des Libert\u00e9s (CNIL), said it issued sanctions against France Travail following<\/p>\n","protected":false},"author":2,"featured_media":4329,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-4328","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"featured_image_urls":{"full":["https:\/\/ft365.org\/wp-content\/uploads\/2026\/01\/4328-30f1be91-3875-4aef-8d64-8cd1a8e60551.jpg",300,300,false],"thumbnail":["https:\/\/ft365.org\/wp-content\/uploads\/2026\/01\/4328-30f1be91-3875-4aef-8d64-8cd1a8e60551-150x150.jpg",150,150,true],"medium":["https:\/\/ft365.org\/wp-content\/uploads\/2026\/01\/4328-30f1be91-3875-4aef-8d64-8cd1a8e60551.jpg",300,300,false],"medium_large":["https:\/\/ft365.org\/wp-content\/uploads\/2026\/01\/4328-30f1be91-3875-4aef-8d64-8cd1a8e60551.jpg",300,300,false],"large":["https:\/\/ft365.org\/wp-content\/uploads\/2026\/01\/4328-30f1be91-3875-4aef-8d64-8cd1a8e60551.jpg",300,300,false],"1536x1536":["https:\/\/ft365.org\/wp-content\/uploads\/2026\/01\/4328-30f1be91-3875-4aef-8d64-8cd1a8e60551.jpg",300,300,false],"2048x2048":["https:\/\/ft365.org\/wp-content\/uploads\/2026\/01\/4328-30f1be91-3875-4aef-8d64-8cd1a8e60551.jpg",300,300,false],"morenews-featured":["https:\/\/ft365.org\/wp-content\/uploads\/2026\/01\/4328-30f1be91-3875-4aef-8d64-8cd1a8e60551.jpg",300,300,false],"morenews-large":["https:\/\/ft365.org\/wp-content\/uploads\/2026\/01\/4328-30f1be91-3875-4aef-8d64-8cd1a8e60551.jpg",300,300,false],"morenews-medium":["https:\/\/ft365.org\/wp-content\/uploads\/2026\/01\/4328-30f1be91-3875-4aef-8d64-8cd1a8e60551.jpg",300,300,false],"crawlomatic_preview_image":["https:\/\/ft365.org\/wp-content\/uploads\/2026\/01\/4328-30f1be91-3875-4aef-8d64-8cd1a8e60551-146x146.jpg",146,146,true]},"author_info":{"display_name":"henry","author_link":"https:\/\/ft365.org\/index.php\/author\/henry\/"},"category_info":"<a href=\"https:\/\/ft365.org\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","_links":{"self":[{"href":"https:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/posts\/4328","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/comments?post=4328"}],"version-history":[{"count":0,"href":"https:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/posts\/4328\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/media\/4329"}],"wp:attachment":[{"href":"https:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/media?parent=4328"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/categories?post=4328"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/tags?post=4328"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}