France's data protection authority CNIL has fined France Travail , the country's national employment agency, €5 million after a serious security breach led to the exposure of personal data of around 43 million people . It is one of the largest cyberattacks ever recorded on a public organisation in France, highlighting long-standing cybersecurity problems in the public sector.

The service, formerly known as Pôle Emploi, manages unemployment benefits and labor market reintegration programs, while maintaining huge databases of personal and financial information .
France Travail: The breach that exposed 20 years of data
According to the CNIL, the breach occurred in early 2024 and involved data stretching back two decades. In March of that year, France Travail confirmed that unknown attackers had gained access to information on up to 43 million people.
See also: CISA chief uploaded sensitive files to ChatGPT
The stolen data included names, dates of birth, social security numbers, home and email addresses, and phone numbers. While were leaked banking details or passwords, there is still a risk that the exposed information could be used in large-scale identity attacks and phishing scams.
Social engineering and human factor
The CNIL revealed that the perpetrators did not exploit a technical security vulnerability, but used social engineering techniques. By deceiving employees, they managed to gain access to the accounts of consultants at CAP EMPLOI — organizations that support the vocational rehabilitation of people with disabilities.
The attack highlighted once again that the human factor remains one of the weakest links in the cybersecurity chain, even in government organizations with developed digital infrastructures.

Sanctions and strict deadlines
In addition to the €5 million fine, the CNIL ordered France Travail to document in detail all the corrective measures it is taking and to submit a specific implementation schedule. In case of non-compliance, daily fines of €5,000 are foreseen until it is proven that the security problems have been fully resolved.
See also: EU: Significant increase in reports of GDPR violations
The supervisory authority stressed that the agency had not implemented adequate technical and organizational measures, as required by the General Data Protection (GDPR), given the sensitivity and volume of information it manages.
A recurring problem
The incident is not an isolated case. In August 2023, France Travail suffered another massive leak that affected around 10 million citizens, with the disclosure of full names and social security numbers.
The recurrence of such incidents raises serious questions about the agency's overall cybersecurity strategy and whether public organizations can respond to modern threats.
CNIL steps up its stance on GDPR
The fine on France Travail is part of a wider wave of strict GDPR enforcement by the French regulator . In the last year alone, the CNIL has fined Google €325 million for cookie-related violations, as well as €150 million on its Irish subsidiary Shein for similar practices.
Most recently, it imposed a €42 million fine on Free Mobile and its parent company following a data leak in October 2024, ruling that insufficient protection measures had been taken against cyber threats.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Russian ELECTRUM behind the cyberattack on the Polish Energy Network?

What the case means for the future
The France Travail case demonstrates that government organizations are now a prime target for cybercriminals due to the vast amount of data they manage. At the same time, it sends a clear message that GDPR compliance is not a formality, but an ongoing obligation.
As cyberattacks increase in frequency and complexity, investment in personnel training, modern security technologies , and continuous system monitoring becomes necessary — not only for the private, but also for the public sector.
The €5 million fine may not be the largest ever imposed, but it is a stark reminder that data protection remains a fundamental obligation in an increasingly vulnerable digital Europe.
Source: www.bleepingcomputer.com
