Government entity · Sports subsidy and access programs · Public funding initiative · France
French government-backed sports subsidy program for youth participation.
The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.
A data file from France's Pass'Sport youth sports subsidy program was published on a hacking forum in December 2025. The file was initially misattributed to CAF, the French family allowance fund, until security researchers identified that it cross-referenced beneficiaries from three separate French agencies, CAF, MSA, and CNOUS, in a combination only the Pass'Sport program would assemble. Each record carried a Pass'Sport-specific identifier (id_psp) confirming the attribution. The Ministry of Sports subsequently acknowledged the incident.\n\nThe published file reportedly contained around 22 million rows reflecting cumulative Pass'Sport activity from 2022 through 2025, with the same household appearing multiple times across years. After deduplication, the file covered approximately 3.5 million unique households, with around 6.4 to 6.5 million unique email addresses indexed by Have I Been Pwned. Compromised fields included names, email addresses, phone numbers, gender, and physical addresses. The longitudinal nature of the file allowed beneficiary records to be tracked across multiple years, with the data on minor beneficiaries gradually transitioning from parent-linked contact details to the young person's own contact details upon reaching adulthood.\n\nFor affected individuals, the practical risk is concentrated in targeted phishing and household-level impersonation. The combination of full name, address, phone, and gender is a strong base for fraudulent messages purporting to come from Pass'Sport, CAF, or affiliated sports clubs, particularly during the annual subsidy enrolment cycle. Young adults whose data appeared in the file face an additional risk because the historical record can be used to craft messages that reference their childhood sports participation. Affected households should treat unsolicited contact about Pass'Sport, sports-club registration, or government allowances with caution and verify any communication through the official pass.sports.gouv.fr channel.
Full threat analysis, exploitation vectors, and principal guidance below.
10 additional sections · verified field analysis · defensive doctrine
6.4M records analyzed
Pass'Sport is a French government-backed subsidy program designed to reduce the cost of sports participation for eligible young people, administered by the Ministry of Sports, Youth, and Community Life (Ministère des Sports, de la Jeunesse et de la Vie Associative). Eligible beneficiaries include minors and young adults whose households receive certain social allowances or who meet other income-based criteria. The program issues a financial allowance that can be used at affiliated sports clubs and associations across France. To administer the subsidy, the Ministry combines beneficiary data drawn from multiple government agencies including CAF (the family allowance fund), MSA (the agricultural social welfare fund), and CNOUS (the national student welfare body).
Public subsidy and access programs collect beneficiary identity, contact information, eligibility records, household-linked details, and participation data tied to government funding and sports access workflows.
The Ministry of Sports publicly acknowledged the December 2025 incident after data circulating on hacking forums was independently attributed to the Pass'Sport program. The leak was initially misattributed to CAF until French security researchers analysed the file structure and identified the cross-agency data combination as unique to Pass'Sport. The breach surfaced alongside a series of other French government-sector incidents in late 2025 and early 2026, including the French Football Federation, the French National Bank Account Registry, and the ANTS identity-document agency. French data-protection regulator CNIL has continued ongoing oversight of public-sector incidents.
The institutional impact has fallen primarily on the Ministry of Sports and on its supply chain of administrative subcontractors. Public reporting characterised the incident as another major weakness in the State's outsourcing chain for citizen data. The Ministry issued a statement acknowledging the breach, but the practical burden of customer notification fell to Pass'Sport beneficiaries discovering the issue through breach-tracking services and press coverage rather than direct outreach. There is no public record of formal CNIL enforcement action against the Ministry as of this writing. Reputationally, the breach added to a pattern of French government-sector data incidents that has fed broader political debate about state cybersecurity capacity.
• SIM swap attacks where phone numbers are present | • Targeted phishing campaigns using exposed email addresses | • Doxxing risk from physical address exposure
A government-linked breach: official identifiers and citizen records support identity fraud and credible authority-impersonation. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.
Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.
Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.
Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.
Request Consultation