Hack Exposes Personal Data of 243,000 French Public School Employees, Government Confirms

le:

La Revue TechEnglishHack Exposes Personal Data of 243,000 French Public School Employees, Government Confirms
4.5/5 - (6 votes)

A cyberattack on a French Education Ministry HR system has exposed personal information tied to roughly 243,000 public education employees, most of them teachers, raising fears of targeted scams and identity fraud.

French officials say the breach hit a platform called Compas, used to manage student-teachers and other trainees in the country’s K-12 system. The intrusion dates back to March 15, 2026, and a sample of the stolen data has already surfaced on online marketplaces where hacked information is bought and sold.

The ministry has suspended access to Compas while investigators assess the damage. France’s cybersecurity and privacy watchdogs have been notified, and a criminal complaint is being filed in Paris.

What was stolen, and why it matters

The exposed data isn’t classified, but it’s the kind of real-world detail scammers love: names, home mailing addresses, phone numbers, and periods of absence from work (without stating the reason). Officials also say the database includes information about mentors who supervise trainees, including their names and work landline numbers.

That combination can make phishing and phone scams far more convincing. A fraudster who knows where you live, what school system you work in, and when you’re out can craft messages that sound like they’re coming from a supervisor, a district office, or an HR department, and pressure people into clicking links, sharing credentials, or sending money.

A national-scale breach, not a local IT mishap

French authorities emphasized that this wasn’t a small, isolated incident. Compas is tied to a nationwide HR process, meaning the breach potentially affects employees spread across the country.

For American readers: France’s Education Ministry runs a highly centralized public school system compared with the U.S., where districts and states control most operations. A breach in a national ministry tool can create a single, large target, more like a federal system being hit than one school district’s server going down.

What officials are doing now

The Education Ministry says it has shut down access to Compas as a containment measure and is checking other internal systems for signs the attacker moved deeper into the network.

The case has been referred to ANSSI, France’s national cybersecurity agency, roughly comparable to CISA in the U.S., and CNIL, the country’s data protection authority, similar in role to a mix of the FTC’s privacy enforcement and state-level privacy regulators. A complaint is also being pursued in Paris, which can trigger formal investigations and coordination with specialized cybercrime units.

A sample of the data is already for sale online

Officials say an excerpt of the stolen information was posted on data-resale forums, a common tactic used to prove a larger stash is real and attract buyers. Reports circulating online also referenced a pseudonymous actor name, “Hexdex”, though the ministry has not publicly detailed the full method of attack or how widely the data has spread.

That restraint is typical in major cyber investigations: revealing too much can help copycats or tip off the intruder about what investigators have, and haven’t, found.

Why teachers and trainees may be especially vulnerable

Because the system tracks trainees and their supervisors, the breach may disproportionately affect early-career educators, people who are new to the job, more likely to be moving, and less likely to have established routines for spotting sophisticated scams.

Even without highly sensitive identifiers like Social Security numbers, officials have not said those were included, basic personal data can be combined with older leaks to build fuller profiles. That’s often how identity and payroll fraud schemes scale up.

Another education-sector breach adds pressure for real security fixes

The Compas incident lands amid broader anxiety about cyberattacks in education. French officials noted the Compas database is separate from a recent breach affecting the Secretariat General of Catholic Education, which reportedly involved administrative data linked to about 1.5 million people.

Different systems, same problem: schools and education agencies hold massive amounts of personal data, rely on sprawling software ecosystems, and operate under relentless time pressure, conditions attackers exploit. The next test for French authorities won’t be the press release. It’ll be whether they can roll out security measures that work in the day-to-day reality of schools, before stolen data fuels the next wave of targeted scams.

Key Takeaways

  • A cyberattack on Compas exposed the data of 243,000 employees, mostly teachers.
  • The stolen information includes names, addresses, phone numbers, and periods of absence, without the reason.
  • The ministry suspended Compas, notified ANSSI and CNIL, and a complaint is being filed in Paris.
  • A sample was posted online on resale marketplaces, making targeted scams easier.
  • Repeated incidents in education are increasing pressure for security measures that can actually be implemented on the ground.

Frequently Asked Questions

What data was compromised in the attack targeting Compas?

The ministry says the leak includes last names, first names, mailing addresses, phone numbers, and periods of absence without stating the reason. The last names, first names, and work landline numbers of internship supervisors are also included in the affected data.

How many French National Education staff members are affected by this leak?

The reported figure is about 243,000 staff members, mostly teachers, across the entire country. According to the ministry, the attack dates back to March 15, 2026.

What steps did the authorities take after the cyberattack?

Access to Compas was suspended and checks were launched on information systems to prevent further spread. The ministry notified ANSSI and CNIL, and a criminal complaint is being filed in Paris.

Why is a leak of addresses and phone numbers a problem?

This data can enable convincing scams—calls or texts impersonating the administration—and targeted solicitation. Combined with periods of absence, it can also facilitate opportunistic fraud attempts by targeting times when the person is less available.

Is this leak related to the attack announced in Catholic education?

The ministry says the Compas database and the database affected by the attack targeting the General Secretariat for Catholic Education are separate. The two incidents happened close together in time, but they do not involve the same database.

Monsourd
Monsourd
Rédacteur pour La Revue Tech, je décrypte l'actualité technologique, les innovations numériques et les tendances du web. Passionné par l'univers tech, je rends l'info accessible à tous. Retrouvez mes analyses sur larevuetech.fr.
SEO 2023

Tendances

indicateur E reputation
Plus d'informations sur ce sujet
Autres sujet