CRITICAL SEVERITYBreach Compilation

French Citizens Data Breach

French Citizens Data Compilation (2024): 28M Records Including Credit Card, Home Address & Phone

Compiled dataset of French citizen personal records aggregated from multiple breach sources'

Verified by ObscureIQ Intelligence

8.5Severity
28.4MRecords
7Fields
2024Year

ObscureIQ Breach Intelligence Scores
6.3
Breach Risk Index
17
Data Value
25
Market Recency
493
days
Since Breach

Risk Interpretation

Severe risk of identity theft, fraud, profiling, and mass targeting. Population-scale citizen datasets are especially dangerous because they enable large-scale lookups, correlation, and government-themed impersonation.

🎯 Impact & Downstream Threats

n/a

Primary downstream threats:
  • Financial fraud using exposed financial profile data
  • SIM swap attacks where phone numbers are present
  • Targeted phishing campaigns using exposed email addresses
  • Doxxing risk from physical address exposure

🔓 Threat Vectors

Card-present & card-not-present fraud
Card identification & social engineering
Device fingerprinting & targeted exploitation
Phishing, credential stuffing & account takeover
Name-based social engineering
Geolocation & account flagging
SIM swapping, vishing & SMS phishing
Physical stalking, mail fraud & identity verification

📋 Breach Intelligence

EntityFrench Citizens
Organization • France
Breach Date2024-09-01
HIBP Added2024-12-20
Records~28.4M (28,400,000 records)
Attack VectorMisconfiguration
Threat ActorUnknown (compilation; multiple unattributed sources)
Data SubjectsCitizen
Breach PathwaySupply_Chain:Aggregator
SourceHave I Been Pwned / ObscureIQ
SensitivityStandard
Breach ID548.0
StatusConfirmed

📝 Executive Summary

A large compiled dataset focused on French residents was discovered in September 2024, sitting in a publicly accessible database with no authentication required. The corpus reportedly contained over 90 million rows in total, with 28.4 million unique email addresses among them.\n\nThe data had been aggregated from multiple prior breaches, with each contributing different fields. The combined record set covered names, physical and IP addresses, phone numbers, device information, and partial credit card details including payment type and last four digits. Because the original sources were not consistently identified, affected individuals have no clear path to trace which underlying incident exposed them.\n\nThe exposure carries severe risk for population-scale identity and financial fraud. The combination of physical address, phone number, and partial card data is a strong base for targeted phishing, mail-based fraud, and impersonation. Anyone whose information may have been included should monitor financial accounts, treat unsolicited contact from "banks" or government services with caution, and update credentials reused across services.

🏢 About French Citizens

The "French Citizens" dataset is not a single organization but a compiled corpus of personal records concerning residents of France, aggregated from multiple unidentified breach sources. It pools identity, contact, location, and partial financial fields from underlying incidents into a single searchable population dataset. Compilations of this kind are typically assembled by intermediaries who scrape and merge data from prior leaks, then circulate the result through dark-web forums and aggregator marketplaces. The exposure is geographic in scope rather than tied to any one company or service.

Breach Compilation | Aggregated personal records from multiple unidentified sources | Multi-source French citizen data corpus | France
France* compilation

🗂 Why They Hold Your Data

Multi-source citizen data corpora aggregate identity, contact, address, government-linked, and public-record-style data drawn from multiple unidentified sources into one large population dataset.

📰 Recent Developments

The corpus came to public attention in September 2024 after roughly 90 million rows were found left exposed in a publicly facing database. The compilation contained 28.4 million unique email addresses drawn from a mix of underlying breaches. No single source has been definitively attributed, and the original breached entities remain partly unidentified. Compilations of this kind tend to recirculate on data-broker forums and aggregator sites for years after first surfacing. France-focused datasets remain a recurring concern for regulators and identity-protection services.

🔍 Data Points Exposed

7 verified field types:
Device information
Email
IP addresses
Names
Partial credit card data
Phone numbers
Physical addresses

Exposure Categories

LocationPHYS ADDR
FinancialCCARD PARTIAL

Canonical Fields

credit_card:partial, device_information, email_address, full_name, ip_address, phone_number, physical_address

🌐 Dark Web Verification

Confirmed
  • Dataset containing ~28.4M records identified in breach intelligence sources
  • Data indexed and searchable across breach notification platforms
  • Source: French Citizens Data Breach

🛡 Recommended Actions

⚠️ Do not assume this is low sensitivity.

1Freeze Your Credit
Place a credit freeze with Equifax, Experian, and TransUnion.
2Expect Targeted Phishing
Watch for emails referencing this breach. Verify through official channels.
3Enable MFA Everywhere
Enable multi-factor authentication on all accounts.
4Monitor Accounts
Watch for unauthorized activity on financial and personal accounts.
5Check Your Exposure
ObscureIQ clients: this breach is indexed in your profile.

Protect Yourself

Check If You’re Affected

Enter your email to check if your data appears in this breach.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed.

High-Risk? Get an Exposure Audit

Full-spectrum exposure audits for executives and public figures.

Request Consultation

ObscureIQ Advisory

We combine proprietary dark web access with commercial and restricted breach intelligence to verify exposure and assess real-world risk.

If you are:
  • A public-facing individual
  • A high-profile executive
  • A customer of French Citizens
  • Or concerned about credential reuse
Services
AuditsWipesThreat MonitoringTraining

Classification Tags

MisconfigurationEmailPhoneAddressFinancial Data

Powered by the ObscureIQ Breach Intelligence Database

© 2026 ObscureIQ · All Rights Reserved · Data Licensing

Latest from ObscureIQ

Credit

What Is Credit Monitoring? And Do I Want It? (Answer: Not Really)

July 14, 2025
Every time there’s a major data breach, companies scramble to offer “free” credit monitoring. It sounds like a responsible move.…
breach economycredit freezecredit scoreequifaxexperian
Credible Threats

Lock Down Browsers. Wipe Employee Footprints. Win Breach Wars.

September 2, 2025
Lock Down Browsers. Wipe Employee Footprints. Win Breach Wars. Over 80% of security incidents now start in the browser. Chrome.…
brave browserbreachesbrowser exploitbrowserschrome
Analysis

Sextortion Spam

May 10, 2025
Sextortion scams aren’t new, but they remain one of the most effective forms of cyber-enabled fraud. These scams don’t rely…
bitcoindeadlinefeargoogle maps apiransom