LFI / Action Populaire: a claim, partially acknowledged
A hacker claims to have exfiltrated 120,000 emails and
20,000 phone numbers of La France Insoumise (LFI)
activists, from the party's digital platform, Action Populaire. LFI
acknowledged the attacks without confirming their exact scale β this page treats the
subject like any other leak documented here: platform security, not the party's
politics.
β οΈ Read this before anything else. This page
documents a data leak affecting Action Populaire, the digital platform of
La France Insoumise (LFI), exactly as it would document one at a company
or government agency. The subject is the security of an information system, not the
ideas held by LFI. The party partially acknowledged the incident without confirming its
exact scale.
The numbers, and their real status
120,000
Email addresses claimed by the hacker. Not confirmed to the exact
figure by LFI.
Forum claim, 05/07/2026.
20,000
Phone numbers claimed in the same batch.
Forum claim, 05/07/2026.
9 years
Period covered by the claimed data (2017-2026), matching the
platform's history.
Forum claim, 05/07/2026.
72h+
Delay between the claim and the first public alerts being
relayed.
Trade press, 05/10/2026.
Timeline
CLAIMED
May 7, 2026
A hacker using the handle "fuzzeddffmepg" posts on a specialist
forum a database presented as coming from Action Populaire, the digital platform of
La France Insoumise (LFI). They claim to have exploited a security flaw on infrastructure they
describe as outdated.
ACKNOWLEDGED (partially)
Around May 10, 2026
The movement acknowledges having "identified these attacks" and
states it has strengthened the platform's security, without explicitly confirming
the data volumes claimed by the hacker, or specifying whether the CNIL was notified
or a complaint filed.
π¬What the claim adds beyond the usual
Beyond standard contact details (emails, phone numbers, addresses), the hacker
claims to have accessed private messages exchanged on the platform.
If confirmed, that's a more sensitive category of data than a simple contact record:
the content of internal exchanges, not just the identity of their authors.
What it changes for you
Whether or not you're affected by this specific platform, the mechanism that would
follow such a leak is identical to what's documented elsewhere on this site: exposed
contacts allow a message or call to be fabricated that impersonates LFI or La France
Insoumise, or uses activist-participation history to appear legitimate. See
From Leak to Scam.
π A message soliciting a donation or urgent action, even if it
appears to come from a movement you're close to, deserves the same verification as a
banking message: through a channel you already know is official, never through the link
provided. See how Medusa links channels
together.
Frequently asked questions
Is the LFI / Action Populaire breach confirmed?
Partially. The movement acknowledged the attacks and strengthened security, without
confirming the figures claimed by the hacker.
Why doesn't this case file take a position on LFI?
Because the subject is platform security and the mechanics of a leak, treated
identically regardless of the organization involved.
What's the risk for affected activists?
A message or call using the exposed data β including possible private messages β to
impersonate La France Insoumise or make a solicitation sound credible.
π Last checked: August 21, 2026. No CNIL
notification or complaint has been publicly mentioned as of this date. Verifiable
information to report: contact@egidio.app.
Cite this pageEgidio β The Threat Laboratory, "LFI / Action Populaire: a claim, partially acknowledged," egidio.app/en/laboratoire/action-populaire-platform-breach/. Licensed CC BY 4.0.
Free to reuse, including commercially, with attribution. Reuse terms.