
The French Government’s unemployment agency suffered a significant data security incident last week that compromised the sensitive personal information of as many as 43 million individuals.
France Travail, formerly known as Pôle Emploi, is a French government agency that is responsible for registering unemployed individuals, providing financial aid, and assisting them in finding jobs.
In a recent data security incident notice published on its website, France Travail said that it has become a victim of a cyber attack that has compromised the sensitive personal information of 43 million users.
“Following a cyberattack of which France Travail and Cap emploi were victims, personal information concerning job seekers currently registered with France Travail, people previously registered over the last 20 years as well as people not registered on the list of applicants employment but having a candidate space on francetravail.fr are likely to be disclosed and exploited illegally,” the agency said.
Immediately after identifying the security incident, France Travail launched an investigation to understand the nature and scope of the incident. In accordance with its obligations under the GDPR, the agency also notified Commission Nationale de l’Informatique et des Libertés (CNIL) and filed a complaint with the judicial authorities.
The investigation revealed that threat actors infiltrated France Travail’s internal network between February 6 and March 5 and accessed personal data associated with the agency’s users.
The compromised data included names, social security numbers, dates of birth, France Travail identifiers, email and postal addresses and telephone numbers. The French government agency has clarified that passwords and banking details were not accessed by the threat actors.
France’s National Commission of Informatique and Liberties (CNIL) said that it has received reports of a data security incident at France Travail and is looking into the issue.
“On March 8, France Travail (formerly Pôle emploi) and Cap emploi informed the CNIL that they had been the victim of an intrusion into their information systems. This attack would have potentially allowed the extraction of data from 43 million users,” CNIL said.
“This number, to be confirmed, concerns people currently registered on the list of job seekers or who have been registered over the last 20 years, as well as people with a candidate space on francetravail.fr.”
France Travail added that a preliminary investigation is being carried out by the Paris Public Prosecutor’s Office and entrusted to the Cybercrime Brigade of the Paris Judicial Police Department. The law enforcement authorities have set up a dedicated webpage for individuals who might be affected by the incident.
“Although this incident does not present a risk to compensation or access to the personal space of francetravail.fr, we nevertheless invite you to remain vigilant in the face of any type of approach or proposal that could appear fraudulent,” the agency added.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543