A claim published on a pirate forum on August 11, 2026

A message published on August 11, 2026 on a pirate forum, detected and analyzed by the specialized site ZATAZ, claims to have infiltrated a platform associated with Santé publique France, the national public health agency. The claim is signed by a hacker identified by the pseudonym “Cybernox”, known by other aliases, who asserts to have acted with two accomplices: “artemis”, described as the main actor of the operation, and “don't call me”.

The account describes a compromise obtained not by exploiting a cryptographic secret or a complex vulnerability, but through a classic design flaw: insufficient authorization control on the server side.

A privilege escalation through request manipulation

According to the elements published by the attackers, the page allowing the modification of a user profile would send to the server a field defining the account role. By intercepting this request — a classic attack technique known as “man-in-the-browser” or via an intercepting proxy — the hackers explain they replaced the initial status of the user with an administrator role.

The critical point raised by the claim: no server-side verification would have prevented this modification. The attackers further indicate that the usable roles were directly visible in the JavaScript code loaded by the interface. They thus identified a value corresponding to a Back Office administrator — “ROLE_BO_ADMIN” — which they then injected into the request. A screenshot presented in the dossier indeed shows a structured response containing this field, corroborating the described scenario, although it does not suffice to establish all the exact conditions.

This is a typical vulnerability in the “Broken Access Control” category, ranked first (A01) in the OWASP Top 10 2021, and already fifth (A5) in the 2017 edition. OWASP reminds that such vulnerabilities allow an attacker to “act as a user or administrator, or to use privileged functions.” Prevention relies on a simple principle: access control must only be effective if it is enforced on the server side, within trusted code, and not on the client side (JavaScript, hidden fields, cookies).

Screenshots showing extensive administrative access

The elements transmitted document a presumed serious compromise. Several screenshots are presented as evidence:

  • A Front Office user profile containing identity and contact information;
  • The “Platform Management” section, with functions related to images, campaigns, emails, and order texts;
  • An image library, in which an image named “trollface” depicting a cat's head appears — this could correspond to a modification made post-intrusion, a sort of “signature” left by the attackers.

However, the most demonstrative element concerns the transactional messaging system. A screenshot from the admin area shows the template of a password change email, whose subject and body have been altered to include a message in English stating that the platform had been hacked, and asking Santé publique France to fix the issue. A second screenshot shows that an email containing these additions actually arrived in an inbox.

This ability to modify a transactional email template raises an additional risk: the dissemination of unauthorized content, the alteration of legitimate communications, or even the exploitation of the trust placed in service messages sent by a public institution.

80,682 records exfiltrated: a directory of healthcare professionals

The exfiltrated data essentially comprises what looks like a directory of healthcare professionals in France. The attackers present a sample containing detailed personal information about one person: identity, postal address, phone number, email address, and function.

The total volume claimed is 80,682 individuals and entities. The breakdown by professional category, as documented by ZATAZ, reveals the extent of the directory:

Category Occurrences
Healthcare establishments 17,061 (29.5%)
Public services 15,531 (26.8%)
Educational institutions 7,704
Freelance / Independent professions 7,014
Associations 6,490

These five categories concentrate nearly 93% of the occurrences. Among the most represented professions: 6,859 midwives, over 9,000 general practitioners, 3,672 pharmacists, 2,089 teachers, and 1,815 specialist doctors.

On the side of structures, there are 8,904 occurrences linked to town halls, 4,346 to hospitals, 4,332 to high schools, 2,932 to public establishments, and 2,796 to care centers.

As for email addresses, Gmail dominates with 13,952 occurrences, followed by Orange (7,352) and Wanadoo (5,360). Several domains from the National Education appear as well: ac-versailles.fr (465), ac-grenoble.fr (390), ac-toulouse.fr (361), ac-lille.fr (351), ac-lyon.fr (347).

The geographical distribution places Toulouse in the lead with 566 occurrences, followed by Nantes (349), Strasbourg (320), Bordeaux (311), Montpellier (310), and Lille (301).

While this data does not constitute medical records, it is nonetheless concerning. As Damien Bancal points out in his analysis for ZATAZ: “an email, a phone call, can enable malicious approaches that are by no means negligible.” This information could fuel targeted phishing, spear-phishing, or social engineering campaigns against healthcare professionals, who might be particularly gullible in response to a message appearing to stem from a legitimate institution.

Motivations presented as “activist”

The attackers claim not to want to provoke “war or destruction” and present the operation as a desire to raise awareness about the level of digital protection of public services. The pseudonym “don't call me” questions the supposed ease with which the service may have been compromised.

The publication also contains a reference to “Chat Control”, the name given by its detractors to the European regulation project aimed at detecting child sexual abuse content in encrypted communications — a highly debated text for its implications on privacy. Insulting remarks directed against the authorities accompany the claim.

These statements provide insight into the communication claimed by the authors, without establishing their true motivations or identities. The profile is more akin to that of hacktivists than financially motivated cybercriminals, but this distinction does not diminish the seriousness of the incident.

An official silence for now

At the time of writing this article (August 12, 2026), no official communication has been published by Santé publique France regarding this incident. The agency's press page, updated on August 10, 2026, only mentions the launch of the CaniculePrev study. The institutional site continues to operate normally.

Similarly, the CNIL has not published any specific communication on this matter in its recent news. Under the GDPR, a breach of personal data must be reported to the CNIL within 72 hours of becoming aware of it. If the incident is confirmed, Santé publique France will not only have to notify the regulator but also inform the affected individuals when the breach presents a high risk to their rights and freedoms.

The absence of communication at this stage may be explained by several factors: the agency may be in a phase of verification and internal investigation, the incident may be under evaluation by the ANSSI (National Agency for Information System Security), or initial analyses may not have confirmed the claimed extent. It is also possible that the targeted platform is a subset or a third-party service associated with Santé publique France, whose exact impact assessment takes time.

An intensified threat context for the French health sector

This claim fits into a particularly charged context for cybersecurity in France. The ZATAZ site, in its publications from the preceding days, documents a remarkable intensity of cyber incidents affecting the territory:

  • On August 8, 2026, ZATAZ revealed the discovery of 1.7 billion French credentials (email/password pairs) stored in a pirate cloud, about 69% of which originated from phishing campaigns conducted over thirteen years;
  • On August 11, 2026, phishing targeting Ameli (Health Insurance) was reported, using cloaking techniques and fake AI stores to qualify future victims;
  • On August 7, 2026, the ransomware group Qilin threatened to publish stolen data from the Stade français, with identity documents already exposed;
  • ZATAZ also counted 43 ransomware claims targeting France in a single month, dominated by the groups The Gentlemen and Qilin.

The health sector is particularly exposed. French hospitals have been the targets of numerous ransomware attacks in recent years (Centre Hospitalier de Villefranche-sur-Saône, CH d'Arles, CH de Concarneau, etc.), with major operational consequences — cancellations of procedures, reverting to paper, disruption of emergency services. An intrusion into a platform of the national public health agency, even limited to a directory, carries strong symbolic significance.

What to do if you are a concerned healthcare professional?

Even in the absence of official confirmation, healthcare professionals whose data may be in this directory can already adopt several reflexes:

  1. Heightened vigilance regarding emails: attackers potentially have names, functions, postal addresses, phones, and emails. Targeted phishing (spear-phishing) using this information would be particularly credible.
  2. Never click on a link from an unexpected email, even if the sender appears legitimate. Prefer manually entering the URL.
  3. Verify communications from Santé publique France via the official site (santepubliquefrance.fr) rather than through links contained in emails.
  4. Enable two-factor authentication (2FA) on all professional and personal accounts when the option is available.
  5. Monitor for any unusual activity on professional and personal accounts, and immediately report any suspicious email to the IT team or the institution's management.

A matter to follow

The absence of official confirmation at this stage invites caution, but the elements presented by the attackers — screenshots, modification of email templates, data sample — document a presumed serious compromise that deserves consideration. The technique exploited, a privilege escalation through request manipulation, is a well-known and referenced vulnerability, which reinforces the technical credibility of the claim.

The response from Santé publique France, the CNIL, and ANSSI in the coming days will allow for gauging the real extent of the incident. In the meantime, this episode serves as a reminder that the platforms of public institutions, including those managing health data, must rigorously apply the fundamental principles of web application security — particularly server-side access control, which remains the primary cause of compromise according to OWASP.