Pole emploi says MOVEit breach at a contractor exposed data on 10 million people

Organization
Pôle emploi
Exploit
Supply Chain Attack
Industry
Government

Pôle emploi, the French public agency responsible for unemployment registration and jobseeker support, said a breach at one of its service providers had exposed personal data on around 10 million people. The agency announced the incident in late August 2023.

The exposed records covered people registered with the agency as of February 2022, reported as about 6 million individuals, plus roughly 4 million who had come off the register within the previous 12 months. The data involved names, employment status and social security numbers. Pôle emploi said email addresses, telephone numbers, passwords and banking details were not affected, and that benefit payments and support services continued as normal.

The breach stemmed from the mass exploitation of a vulnerability in Progress Software's MOVEit Transfer file transfer tool, a campaign attributed to the Clop ransomware group that affected hundreds of organisations worldwide. Infosecurity Magazine identified the compromised contractor as Majorel, one of two providers handling document digitisation and jobseeker data processing for the agency. BleepingComputer reported that the agency did not name the provider itself.

Pôle emploi reported the incident to CNIL, the French data protection regulator, said it intended to file a criminal complaint, and set up a free telephone helpline while committing to notify affected individuals by email. At the time it was among the largest single victim counts disclosed in the MOVEit campaign, second only to Maximus. Clop did not list the agency on its extortion site.

Sources