Cyber Incident Victim: Emoa Mutuelle du Var
Date:
Apr 2022
Location:
France
Summary
A French health insurer experienced two significant data breaches, with the subsequent incident exposing personal information of over 80,000 policyholders. Sensitive data including names, birthdates, postal codes, email addresses, and in some cases Social Security numbers, banking details, and passport copies were leaked onto cybercriminal platforms. The organization was unaware of the second breach until notified by external sources, despite having implemented security measures following an earlier incident. The compromised information exposes affected individuals to heightened risks of phishing attempts, financial fraud, and identity theft.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 3 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
In March 2022, confidential data belonging to policyholders of French insurance provider Emoa Mutuelle du Var was disclosed online, prompting the organization to notify affected subscribers. The company stated its technical teams urgently implemented security measures to address the breach and reinforce system protections following discovery of the malicious act. However, a significantly larger second breach occurred in April 2022, exposing personal information of over 80,000 policyholders. The organization remained unaware of this subsequent incident until informed by newspaper Libération, which discovered the data circulating on cybercriminal platforms. The compromised data included names, surnames, postal codes, birthdates, and email addresses, with more sensitive records such as Social Security numbers, banking coordinates, and passport photocopies exposed for some victims.

The exposed information appeared for sale on illicit platforms, substantially increasing risks of scams, phishing attempts, and identity theft for affected individuals. Administrative complications arising from potential identity fraud represented a significant secondary consequence for victims. Despite Emoa's previous security enhancements following the March incident, the April breach demonstrated persistent vulnerabilities in their systems. No evidence suggested the organization detected the second breach independently prior to media notification. The cumulative breaches exposed systemic security challenges at the insurer, with sensitive customer data compromised across two separate incidents within approximately one month.
