Following the tax administration, the National Education ministry, and the Ministry of Ecological Transition, it is now the turn of the National Service for Youth (SNU) website to be the target of a cyberattack.
According to information from the specialized site French Breaches, the hacker, whose pseudonym is LunarisSec, claims to have compromised the data of 275,000 accounts, including 5,000 accounts of managers of partner structures involved in the program.
The nature of the stolen data: Names, first names, email addresses, or even phone numbers would have been stolen. Many accounts belong to public administrations such as local authorities, municipalities, departmental fire and rescue services (SDIS), but also associations like the Red Cross and the Restos du Cœur, or organizations linked to the gendarmerie. As for the roughly 5,000 accounts of the managers of partner structures, the leak is more significant since more precise data were stolen.
In addition to names, first names, email addresses and phone numbers, the role and status of the account, the region and the department, the associated cohort (cohort identifiers), the structure identifiers, the account creation date, the last modification date and the last activity date, or various internal technical identifiers, were also compromised.
A first cyberattack in late 2023. This is not the first time the SNU site has been hacked, since a previous cyberattack at the end of 2023 had allowed the hackers to recover data of nearly 150,000 people, including 62,500 young volunteers.
In response to these recurring data leaks, Prime Minister Sébastien Lecornu had called, on August 19, for the creation of a “first-intervention unit, engaged from the breach of a sensitive access and present until the restoration.”