Tech News

ASP Cyberattack Exposes 143,000 Aid Recipients' Data

September 25, 2026Pablo Navarro1 мин

Between July and October 2023, the Île-de-France Region provided €250 in aid to 160,000 low-income households, funded by a €45 million European grant. The ASP processed payment notifications for this assistance. This "Energy Boost" aid was exclusively for households with annual incomes below €14,802 for a single person. Each stolen notification contained the recipient's full name, postal address, beneficiary number, complete banking details, and the amount disbursed.

Following a breach at the sports retailer Basic-Fit, where a message stated that "with an IBAN alone, you can't do anything," it was clarified that adding a name and address allows a fraudster to create a SEPA direct debit mandate in the victim's name and withdraw funds from their account. Scammers may also impersonate ASP agents via phone, mention the exact aid amount, and request bank validation codes. Recipients should disregard any calls, texts, or emails concerning the "Energy Boost" or their banking information. They can also dispute any unauthorized direct debits with their bank within thirteen months.

In 2025, the CNIL received 6,167 data breach notifications, a 9.5% increase from 2024. Half of these were due to hacking. "Breaches are becoming increasingly massive," warned the institution's president in her annual report. The ASP experienced a prior leak in April when an intruder accessed and stole social security numbers and IBANs of vocational training interns from an agency account. The number of affected individuals was not publicly disclosed.