Search engines powered by stolen data

On Friday, June 12, 2026, BFM-TV revealed that Anne Le Hénanff, the Digital Minister, had reported to the authorities a website allowing queries into dozens of stolen databases. Following this, Éric Bothorel, Renaissance deputy from Côtes-d'Armor, announced that he too had approached the authorities to report three different lookup services, stating on BlueSky: “It must be said firmly, the possession of stolen data is a crime.”

These services are not new. As early as April 2026, the Paris public prosecutor's office had opened several investigations concerning platforms of this type. On May 14, a 19-year-old man was indicted and placed in provisional detention in a similar case, as revealed by ZDNET.

How do lookups work?

A lookup functions like a conventional search engine, but powered by data exfiltrated during hacks: leaks from e-commerce databases, hospitals, administrations, telecom operators. By entering a simple name, email address, or phone number, the user can obtain in a matter of seconds:

  • IBAN and banking details
  • Postal address and date of birth
  • Social security number
  • Membership in sports federations
  • Data obtained from breaches of public and private organizations

This reflects a structural problem: in 2025, the CNIL recorded 6,167 data breaches in France. Each leak feeds databases that eventually are cross-referenced, resold, and indexed by these engines. The risk extends beyond the moment of the breach: stolen data continues to circulate years after.

Increased risk of identity theft

For organizations and their DPOs, the danger is twofold. On one hand, their company's data may find its way into these databases without their knowledge. On the other hand, the individuals involved — employees, customers, patients — are exposed to identity theft risks that may materialize months after the initial leak.

The existence of lookup services also alters the assessment of risks post-breach. When a company suffers a data leak, the level of risk for the affected individuals partly depends on whether that data can be aggregated with other already compromised databases.

Recommendations for organizations

Several reflexes must be integrated in response to this threat:

  1. Regularly monitor if your data has leaked using dedicated monitoring tools.
  2. Strengthen notifications to the affected individuals: in case of a breach involving data that could feed a lookup (identifiers, financial data, contact details), the communication required by Article 34 of the GDPR must be precise about the risks of identity theft.
  3. Test your incident response procedure: notifying the CNIL within 72 hours (Article 33) is the first step, but reacting quickly requires a documented and pre-tested procedure.
  4. Minimize collected data: every piece of data not collected is a piece of data that cannot end up in a lookup. The principle of minimization in the GDPR is a concrete reduction of the exposure surface.

A political signal that does not replace internal maturity

Political actions against lookups are welcome, but they will not erase the databases already in circulation. The real response lies upstream: organizations that minimize their data, encrypt what needs to be, and DPOs who treat data breaches not as a simple box to check, but as an ongoing operational risk to manage.

Political awareness is a strong signal — however, it does not replace the internal maturity of organizations in the face of this persistent threat.


Sources: Le Monde, BFM-TV, ZDNET, Leto.legal