The numbers, and their real status
Timeline
🔑Why plaintext passwords change everything
A properly protected password is hashed: even the database itself doesn't contain the password, only a fingerprint that can't be reversed directly. A "plaintext" password is the real password, readable as-is by anyone who accesses the database. If reused elsewhere — as most users do — access to an Axess account could open access to other accounts belonging to the same person.
What it changes for you
If you're a current or former Axess customer, the most useful reflex isn't to change your Axess password alone: it's to change every identical or similar password used on other services, particularly your email and banking accounts. See From Leak to Scam.
Frequently asked questions
Is the Axess leak confirmed?
Not to our knowledge at the time of writing.
Why are plaintext passwords particularly serious?
They're directly readable, with no computation step to crack, and immediately exploitable if reused elsewhere.
Who is X-VDP-X?
A hacker or collective already linked to claims against France Cyber Défense, Evy and Klaro in 2026.
Related reading
Egidio — The Threat Laboratory, "Axess: 18,875 accounts claimed, plaintext passwords," egidio.app/en/laboratoire/axess-plaintext-password-breach/. Licensed CC BY 4.0.
Free to reuse, including commercially, with attribution. Reuse terms.