CSIDB logo
Incident

Chronopost

Incident posture

Attack window
Jan 2025
Location
France
Status
Unknown
CIA posture
Available to members
Updated
2026-09-02 17:48

Linked entities

Victim
Chronopost
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jan 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cyberattack on Chronopost, a French parcel delivery subsidiary of La Poste group, resulted in unauthorized access to personal data belonging to 210,000 clients. The attacker was able to view names, postal addresses, signatures as recorded on delivery proofs, and occasionally telephone numbers. The incident, confirmed publicly in mid-February, was reported to the French data protection authority (CNIL) as required by law. Separately, the Caisse des dépôts disclosed a distinct attack in which an intruder accessed personal data of roughly 70,000 affiliates of the Ircantec public-sector supplementary pension fund, including public employees and approximately 1,000 local elected officials, by exploiting compromised login credentials of several public employers. Both organizations notified the affected individuals and relevant authorities, and authorities warned that stolen data could be resold to facilitate further social engineering scams via SMS or email.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

Chronopost, the parcel delivery subsidiary of La Poste group, suffered a cyberattack at the end of January 2025 in which an attacker gained access to personal data belonging to approximately 210,000 customers. The company publicly disclosed the breach on Thursday, 13 February 2025, confirming the incident to the Agence France-Presse. According to Chronopost, the attacker was able to consult customers' surnames, first names, postal addresses, and signatures as they appeared on proof-of-delivery documents, and in some cases their telephone numbers. The disclosure of these categories of personal information prompted the company to notify the Commission nationale de l'informatique et des libertés (Cnil), France's independent data protection authority, in accordance with applicable law. Chronopost characterized the incident as an intrusion that allowed an external attacker to view, rather than necessarily alter, customer records held by the company.

A separate but contemporaneous data breach affected the Caisse des dépôts (CDC), which manages certain public-sector complementary pension schemes. In this distinct attack, a perpetrator was able to access personal data belonging to approximately 70,000 individuals affiliated with Ircantec, a complementary pension fund for public-sector agents administered by the CDC. Among the affected population were public-sector contractual employees and roughly 1,000 locally elected officials. The CDC confirmed the incident to AFP, corroborating prior reporting by Franceinfo, and indicated that the attacker gained access to Ircantec affiliate data by using connection identifiers belonging to several public-sector employers. The CDC did not publicly specify the precise categories of personal data that were exposed in this intrusion. As a precautionary measure, the CDC verified the absence of irregular activity originating from the personal accounts of the affected affiliates following the discovery of the breach. Like Chronopost, the CDC notified the Cnil of the incident, complying with French data protection notification obligations.

The Chronopost and Caisse des dépôts incidents occurred independently of one another and were confirmed by the two organizations on the same day. In the aftermath of these breaches, both entities informed the affected individuals. Chronopost directly notified the 210,000 customers whose data had been exposed, while the Caisse des dépôts reached out to the approximately 70,000 identified Ircantec affiliates, including the contractual public-sector employees and the 1,000 local elected officials. Once attackers obtain personal data through such intrusions, they sometimes resell the harvested information, enabling other malicious actors to attempt fraud against the victims using social engineering techniques, typically conducted by SMS or email and leveraging the stolen data. This risk of downstream fraudulent contact was noted in reporting on the broader context of these types of breaches, though no specific fraudulent campaigns tied directly to the Chronopost or CDC incidents were detailed in the source material. The Cnil received formal notifications from both organizations concerning the attacks, as required under French law, and the two incidents remained under regulatory and operational review as the affected entities worked to address the consequences of the unauthorized access to their respective data holdings.

Sources

Sources available to members: 1 source.

CSIDB