Friday, August 21, will remain a dark date for personal data protection in France. Five organizations were targeted on the same day: four commercial brands and one humanitarian association. Together, they account for several million potentially exposed profiles.
Key points of this article:
Beauty Success and Bureau Vallée, a wave possibly from the same provider
According to FrenchBreaches, a hacker using the pseudonym misere claims to have a database attributed to Beauty Success. It contains 5,169,727 unique records after deduplication, out of a gross total of over 10.27 million lines. Names, first names, emails, and dates of birth are included in the leaked sample.
Bureau Vallée suffers the same fate. Indeed, nearly 4.82 million records have been claimed this time. This volume is incomparable to the more modest leak of 55,949 records already reported in early August at the brand. The hacker claims in both cases that a single third-party provider gave him access to numerous databases of different companies.
Made in Bébé and Allobébé: family data in circulation
Two specialists in childcare complete this grim picture. Made in Bébé is said to be affected with 1.4 million records, including postal addresses, order details, and billed amounts among the visible data. Allobébé follows with 1.1 million claimed profiles, with emails and postal addresses topping the exposed fields.
These four cases share a common point: none are officially confirmed by the concerned company. At this stage, these are claims deemed credible by the analysts who examined them, not confirmations of incidents.
Civil Protection confirms its breach
The fifth case changes nature. The National Federation of Civil Protection confirms that it has been the victim of a cyberattack affecting its eProtec platform in March 2026. An intrusion that went undetected at the time of the events. More than 525,000 volunteer profiles and about 15,000 photographs are said to be involved, with names, dates of birth, phone numbers, professions, and assignment sections included.
Profiles of minors, registered under the status of "cadet", are among the analyzed data. The federation has filed a complaint with the Paris prosecutor's office. No group has publicly claimed responsibility for the attack to date, unlike the other four cases of the day.
To give a sense of the risks involved, the CNIL had imposed a fine of 5 million euros on France Travail in January after a leak affecting nearly 37 million job seekers. A similar sanction cannot be ruled out for Civil Protection. The presence of minor data generally weighs heavily on the regulator's assessment.
Five organizations, one Friday. France is now among the most targeted countries in Europe, with a 680% increase in reported incidents in recent times. FrenchBreaches has recorded over 930 hacked sites and nearly one billion people affected worldwide since the launch of its monitoring.
Those affected by any of these five leaks should therefore keep an eye on their emails, change their passwords as a precaution, and be wary of any messages purporting to come from these organizations in the coming weeks. For parents whose child is registered as a cadet with Civil Protection, particular vigilance is also required against phishing attempts that could directly target minors.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.





























