CSIDB logo
Incident

Caisse des Dépôts

Incident posture

Attack window
Oct 2025
Location
France
Status
Unknown
CIA posture
Available to members
Updated
2026-08-13 03:24

Linked entities

Victim
Caisse des Dépôts
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Undetermined
Disclosed
Feb 2025
Resolved
Pending

Summary

The Caisse des dépôts reported that personal data of approximately 70,000 individuals, including about 1,000 elected officials, were compromised after attackers fraudulently used login credentials of several public employers to access its retirement‑management platform. The compromised credentials allowed illegitimate access to personal information of affiliates of the Ircantec retirement scheme, comprising contract workers from state, local and hospital public sectors as well as hospital practitioners. In response, the organization notified affected individuals by mail or email, blocked the fraudulent connections, strengthened account‑creation controls, enhanced overall system security, and informed its partners so they could adjust their monitoring for abnormal activity.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On Wednesday 12 February 2025, franceinfo learned from the Caisse des dépôts that a breach had occurred affecting 70 000 individuals, of whom 1 000 were elected officials. The incident involved the fraudulent use of login credentials belonging to several public employers that access the Caisse des dépôts’ retirement‑management platform. Those credentials were used to gain illegitimate entry to the system and to retrieve personal data of certain affiliates of the Ircantec scheme. All of the persons whose data were exposed are affiliated with Ircantec, which includes contract agents of the state, territorial and hospital civil service, local elected officials and hospital practitioners. The breach was discovered after the Caisse des dépôts detected anomalous connections to its platform and subsequently confirmed that the credentials had been misused.

The compromised data consist of personal information held for Ircantec affiliates, although the article does not specify the exact fields that were exfiltrated. Because the attackers accessed the platform through the employers’ credentials, they were able to view the personal data stored for the affiliates linked to those employers. The scale of the exposure—70 000 individuals—represents a significant portion of the Ircantec population managed by the Caisse des dépôts. The incident prompted the organization to notify the affected individuals directly by mail or email, as required by data‑protection obligations. The Caisse des dépôts also stated that it had taken the measures necessary to remediate the violation and to limit any negative consequences for the affiliates.

In response, the Caisse des dépôts blocked the fraudulent connections that had enabled the unauthorized access and strengthened the controls governing the creation of new accounts on the platform. It reinforced the overall security of its information system and instituted precautionary checks to verify the absence of irregular activity originating from the personal spaces of affiliates managed by the organization. Furthermore, the Caisse des dépôts informed all of its partners so that they could update or adjust their own alert systems to detect abnormal activity on their data‑processing environments. These actions were described as the steps taken to address the breach and to mitigate further risk.

Sources

Sources available to members: 1 source.

CSIDB