French Citizens 2024 Data Breach

French Citizens Data Compilation (2024): 28M Records Including Credit Card, Home Address & Phone

Breach Compilation · Aggregated personal records from multiple unidentified sources · Multi-source French citizen data corpus · France

French Citizens Data Compilation (2024): 28M Records Including Credit Card, Home Address & Phone

Compiled dataset of French citizen personal records aggregated from multiple breach sources'

Compilation · ObscureIQ Intelligence
Limited DisclosureThis data comes from an illicit online community. Because merely appearing in it could wrongly imply involvement, we do not confirm anyone’s presence publicly or allow third parties to look others up. Check your own exposure privately below.
Breach Risk Index i
65/100
Lower riskHigher risk
High and current: recent, valuable data circulating on the dark web now.
Data Sensitivity i
Restricted
Being associated with this breach can itself be harmful. Disclosure is limited and presence is not confirmed to unverified parties.
28.4MRecords
2024Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Crucial data exposed
FinancialCredit Card
AddressPhysical address
Classification Tags
Unknown (aggregator)Cloud MisconfigurationCybercrimeThreat Actor InfrastructureCitizen2024

Breach Summary

A large compiled dataset focused on French residents was discovered in September 2024, sitting in a publicly accessible database with no authentication required. The corpus reportedly contained over 90 million rows in total, with 28.4 million unique email addresses among them.\n\nThe data had been aggregated from multiple prior breaches, with each contributing different fields. The combined record set covered names, physical and IP addresses, phone numbers, device information, and partial credit card details including payment type and last four digits. Because the original sources were not consistently identified, affected individuals have no clear path to trace which underlying incident exposed them.\n\nThe exposure carries severe risk for population-scale identity and financial fraud. The combination of physical address, phone number, and partial card data is a strong base for targeted phishing, mail-based fraud, and impersonation. Anyone whose information may have been included should monitor financial accounts, treat unsolicited contact from "banks" or government services with caution, and update credentials reused across services.

Full threat analysis, exploitation vectors, and principal guidance below.

11 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

28.4M records analyzed

About French Citizens

The "French Citizens" dataset is not a single organization but a compiled corpus of personal records concerning residents of France, aggregated from multiple unidentified breach sources. It pools identity, contact, location, and partial financial fields from underlying incidents into a single searchable population dataset. Compilations of this kind are typically assembled by intermediaries who scrape and merge data from prior leaks, then circulate the result through dark-web forums and aggregator marketplaces. The exposure is geographic in scope rather than tied to any one company or service.

Why They Hold Your Data

Multi-source citizen data corpora aggregate identity, contact, address, government-linked, and public-record-style data drawn from multiple unidentified sources into one large population dataset.

Recent Developments

The corpus came to public attention in September 2024 after roughly 90 million rows were found left exposed in a publicly facing database. The compilation contained 28.4 million unique email addresses drawn from a mix of underlying breaches. No single source has been definitively attributed, and the original breached entities remain partly unidentified. Compilations of this kind tend to recirculate on data-broker forums and aggregator sites for years after first surfacing. France-focused datasets remain a recurring concern for regulators and identity-protection services.

Data Points Exposed

7 verified field types
Credit Card Critical
Device Information
Email Address
Full Name
IP Address
Phone Number
Physical address High

Breach Impact

n/a

Exploitation & Downstream Threats

• Financial fraud using exposed financial profile data | • SIM swap attacks where phone numbers are present | • Targeted phishing campaigns using exposed email addresses | • Doxxing risk from physical address exposure

Principal Risk Advisory

What this means for a principal

A consumer-service breach: contact and account data supports phishing, account takeover and profile enrichment. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.

What You Should Do

  1. Treat the home address as exposed: review mail and package handling and physical-security routines, and brief household staff to verify unusual requests.
  2. Guard against SIM-swap and vishing: add a carrier port-out PIN and verify any 'support' calls independently.
  3. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping and footprint neutralization: cross-reference against broker-available data and suppress still-removable elements, prioritizing address and phone, since this record re-seeds broker networks.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).
U(
Threat Actor: Unknown (aggregator)
Threat actor

Attribution based on available breach intelligence.

Read the full threat-actor profile →

Protect Yourself

Protect Yourself: Limited Disclosure

Check Your Own Exposure: Verification Required

This data originates from an illicit online forum, and being listed is not proof of involvement. To protect people from false association, we confirm exposure only to the individual concerned. Verify your identity to privately check your own exposure.

We never confirm whether a specific person appears in this breach to anyone but that person.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation