Egidio
Case file Β· August 21, 2026

CFDT: 1.4 million union members and former members exposed

France's CFDT trade union confirmed a cyberattack exposing data for over 1.4 million members and former members β€” name, address, and union affiliation, a specially protected category of data. CNIL and ANSSI notified, complaint filed.

⚠️ This case file documents a confirmed fact, not a claim. The CFDT published an official statement acknowledging the cyberattack. This page treats the subject exactly like any other organization affected by a data breach on this site: what's at issue is the security of an information system, not the organization itself.

The numbers, confirmed

Feb 18
Date the CFDT officially confirmed the cyberattack.
CFDT statement, 02/18/2026.
1.4M+
Members and former members affected, across French territory.
CFDT statement; Next, 02/2026.
1
Compromised account behind the intrusion β€” belonging to a regional official.
it-connect.fr, 02/2026.
3
Actions taken by the CFDT: isolating then shutting down the server, notifying the CNIL/ANSSI, filing a complaint.
CFDT statement, 02/18/2026.

Timeline

CONFIRMED
February 18, 2026
The CFDT publishes an official statement confirming it was the victim of a cyberattack that allowed the illegal download of files containing members' personal data. The server hosting the affected applications is isolated, then shut down. The CNIL and ANSSI are informed, a complaint is filed.
CONFIRMED
February 2026 (follow-up)
The investigation establishes that the attacker used the compromised credentials of a regional official to access the internal "Cnas" application and bypass access restrictions, extracting data for all current members and many former members. The CFDT confirms former members are also affected.

βš–οΈWhy this data is treated differently

The exposed data includes name, postal address, and union membership β€” member number, join date, affiliation. Union membership falls under the "special categories" of GDPR Article 9, in the same category as the health data documented elsewhere on this site for Alaxione or CareCloud. The editorial treatment is the same regardless of which union is involved: what matters is the nature of the exposed data, not the organization.

What it changes for you

A postal address and confirmed union membership are enough to make a contact posing as the union itself sound credible β€” a meeting notice, a request to update contact details, or a dues solicitation. That's the same mechanism documented in From Leak to Scam: stolen data is almost never used as-is, it's used to manufacture legitimacy.

πŸ”’ A call or message referencing your union membership, requesting urgent action or banking information, deserves the same caution as a suspicious bank call. See how Medusa links channels together.

Frequently asked questions

Is the CFDT breach confirmed?

Yes, fully, through an official statement from the CFDT itself β€” not a hacker's claim.

Why is union membership particularly sensitive data?

It falls under the "special categories" of GDPR Article 9, like health data or political opinions, which justifies heightened treatment.

How was access obtained?

Through the compromised credentials of a regional official, used to access the internal "Cnas" application and bypass access restrictions.

πŸ“Œ Last checked: August 21, 2026. Verifiable information to report: contact@egidio.app.

Related reading

Cite this page Egidio β€” The Threat Laboratory, "CFDT: 1.4 million union members and former members exposed," egidio.app/en/laboratoire/cfdt-union-membership-breach/. Licensed CC BY 4.0.

Free to reuse, including commercially, with attribution. Reuse terms.