Egidio
Case file Β· August 21, 2026

LFI / Action Populaire: a claim, partially acknowledged

A hacker claims to have exfiltrated 120,000 emails and 20,000 phone numbers of La France Insoumise (LFI) activists, from the party's digital platform, Action Populaire. LFI acknowledged the attacks without confirming their exact scale β€” this page treats the subject like any other leak documented here: platform security, not the party's politics.

⚠️ Read this before anything else. This page documents a data leak affecting Action Populaire, the digital platform of La France Insoumise (LFI), exactly as it would document one at a company or government agency. The subject is the security of an information system, not the ideas held by LFI. The party partially acknowledged the incident without confirming its exact scale.

The numbers, and their real status

120,000
Email addresses claimed by the hacker. Not confirmed to the exact figure by LFI.
Forum claim, 05/07/2026.
20,000
Phone numbers claimed in the same batch.
Forum claim, 05/07/2026.
9 years
Period covered by the claimed data (2017-2026), matching the platform's history.
Forum claim, 05/07/2026.
72h+
Delay between the claim and the first public alerts being relayed.
Trade press, 05/10/2026.

Timeline

CLAIMED
May 7, 2026
A hacker using the handle "fuzzeddffmepg" posts on a specialist forum a database presented as coming from Action Populaire, the digital platform of La France Insoumise (LFI). They claim to have exploited a security flaw on infrastructure they describe as outdated.
ACKNOWLEDGED (partially)
Around May 10, 2026
The movement acknowledges having "identified these attacks" and states it has strengthened the platform's security, without explicitly confirming the data volumes claimed by the hacker, or specifying whether the CNIL was notified or a complaint filed.

πŸ’¬What the claim adds beyond the usual

Beyond standard contact details (emails, phone numbers, addresses), the hacker claims to have accessed private messages exchanged on the platform. If confirmed, that's a more sensitive category of data than a simple contact record: the content of internal exchanges, not just the identity of their authors.

What it changes for you

Whether or not you're affected by this specific platform, the mechanism that would follow such a leak is identical to what's documented elsewhere on this site: exposed contacts allow a message or call to be fabricated that impersonates LFI or La France Insoumise, or uses activist-participation history to appear legitimate. See From Leak to Scam.

πŸ”’ A message soliciting a donation or urgent action, even if it appears to come from a movement you're close to, deserves the same verification as a banking message: through a channel you already know is official, never through the link provided. See how Medusa links channels together.

Frequently asked questions

Is the LFI / Action Populaire breach confirmed?

Partially. The movement acknowledged the attacks and strengthened security, without confirming the figures claimed by the hacker.

Why doesn't this case file take a position on LFI?

Because the subject is platform security and the mechanics of a leak, treated identically regardless of the organization involved.

What's the risk for affected activists?

A message or call using the exposed data β€” including possible private messages β€” to impersonate La France Insoumise or make a solicitation sound credible.

πŸ“Œ Last checked: August 21, 2026. No CNIL notification or complaint has been publicly mentioned as of this date. Verifiable information to report: contact@egidio.app.

Related reading

Cite this page Egidio β€” The Threat Laboratory, "LFI / Action Populaire: a claim, partially acknowledged," egidio.app/en/laboratoire/action-populaire-platform-breach/. Licensed CC BY 4.0.

Free to reuse, including commercially, with attribution. Reuse terms.