The Agence de services et de paiement (ASP) is at the center of a new controversy following the confirmation of a data breach affecting thousands of citizens. In late August 2026, the public agency identified fraudulent access to a user account, which led to the massive exfiltration of payment notices. While the agency has not released an official count, cybersecurity experts and forums estimate that over 143,000 files have been compromised. These records primarily concern the “Coup de pouce énergie” scheme deployed in the Île-de-France region for the 2023 and 2024 fiscal years.

The exploited flaw, identified as an IDOR vulnerability, allowed attackers to access sensitive documents without proper authorization checks. The stolen data is particularly critical for victims: it includes full names, postal addresses, beneficiary numbers, amounts of aid received, as well as complete bank details (IBAN and BIC). This level of detail provides prime material for sophisticated phishing campaigns or identity theft attempts, as attackers can easily impersonate administrative or banking services when contacting targeted individuals.

This latest incident undermines the credibility of the ASP, which was already strained by a similar breach in April 2026 that exposed the identities and bank details of trainees. The recurrence of these failures highlights a structural problem within public services. According to CNIL reports, the administrative sector is increasingly being targeted, accounting for a growing share of data breach notifications. This raises serious questions regarding the inadequacy of cybersecurity measures, particularly the widespread lack of multi-factor authentication.

Beyond the immediate impact on beneficiaries, this case illustrates the major challenges associated with the centralization of personal data. The increase in leaks fuels a black market where cross-referenced information enables increasingly targeted fraud. While authorities frequently emphasize the protection of digital assets and cryptographic transactions, this episode serves as a brutal reminder that the primary risk to the assets of French citizens lies in the recurring hemorrhaging of administrative files, which turns data meant to be protected into tools for cybercrime.