The numbers, confirmed
Timeline
βοΈWhy this data is treated differently
The exposed data includes name, postal address, and union membership β member number, join date, affiliation. Union membership falls under the "special categories" of GDPR Article 9, in the same category as the health data documented elsewhere on this site for Alaxione or CareCloud. The editorial treatment is the same regardless of which union is involved: what matters is the nature of the exposed data, not the organization.
What it changes for you
A postal address and confirmed union membership are enough to make a contact posing as the union itself sound credible β a meeting notice, a request to update contact details, or a dues solicitation. That's the same mechanism documented in From Leak to Scam: stolen data is almost never used as-is, it's used to manufacture legitimacy.
Frequently asked questions
Is the CFDT breach confirmed?
Yes, fully, through an official statement from the CFDT itself β not a hacker's claim.
Why is union membership particularly sensitive data?
It falls under the "special categories" of GDPR Article 9, like health data or political opinions, which justifies heightened treatment.
How was access obtained?
Through the compromised credentials of a regional official, used to access the internal "Cnas" application and bypass access restrictions.
Related reading
Egidio β The Threat Laboratory, "CFDT: 1.4 million union members and former members exposed," egidio.app/en/laboratoire/cfdt-union-membership-breach/. Licensed CC BY 4.0.
Free to reuse, including commercially, with attribution. Reuse terms.