Egidio
Case file · August 24, 2026

Axess: 18,875 accounts claimed, plaintext passwords

A hacker going by X-VDP-X claims 67 databases at Axess, a French digital services company: emails, plaintext passwords, phone numbers, SIRET numbers, IBANs, quotes and invoices. Not confirmed by the company.

⚠️ Claimed, not confirmed. Everything known comes exclusively from the hacker's own publication and its observation by independent trackers (Cyberattaque.org, FrenchBreaches). To our knowledge, Axess has neither confirmed nor denied publicly at the time of writing.

The numbers, and their real status

18,875
User accounts claimed as exposed, spread across 67 databases.
X-VDP-X's claim, not confirmed by Axess.
67
Distinct databases the hacker claims to have exfiltrated.
X-VDP-X's claim.
3
Cyberattacks claimed by the same hacker in 2026 before this one: France Cyber Défense, Evy, Klaro.
Cyberattaque.org.
0
Public confirmation from Axess found at the time of writing.
Checked August 24, 2026.

Timeline

CLAIMED
August 23, 2026
A hacker going by X-VDP-X publishes a claim targeting Axess: 67 databases, presented as containing emails, plaintext passwords, phone numbers, SIRET numbers, IBANs, quotes and invoices.
CONTEXT
2026
The same hacker, or the collective associated with the alias diable'fire, is already cited in claims against France Cyber Défense, Evy (insurance) and Klaro (employee benefits).

🔑Why plaintext passwords change everything

A properly protected password is hashed: even the database itself doesn't contain the password, only a fingerprint that can't be reversed directly. A "plaintext" password is the real password, readable as-is by anyone who accesses the database. If reused elsewhere — as most users do — access to an Axess account could open access to other accounts belonging to the same person.

What it changes for you

If you're a current or former Axess customer, the most useful reflex isn't to change your Axess password alone: it's to change every identical or similar password used on other services, particularly your email and banking accounts. See From Leak to Scam.

🔒 A password manager that generates a unique password per service makes this kind of leak harmless to your other accounts — it's the only protection that works systematically.

Frequently asked questions

Is the Axess leak confirmed?

Not to our knowledge at the time of writing.

Why are plaintext passwords particularly serious?

They're directly readable, with no computation step to crack, and immediately exploitable if reused elsewhere.

Who is X-VDP-X?

A hacker or collective already linked to claims against France Cyber Défense, Evy and Klaro in 2026.

📌 Last checked: August 24, 2026. Verifiable information to report: contact@egidio.app.

Related reading

Cite this page Egidio — The Threat Laboratory, "Axess: 18,875 accounts claimed, plaintext passwords," egidio.app/en/laboratoire/axess-plaintext-password-breach/. Licensed CC BY 4.0.

Free to reuse, including commercially, with attribution. Reuse terms.