Egidio
Case file Β· August 21, 2026

HelloAsso: the claim that doesn't match the data

A file claiming 160,000 association leaders and IBANs presented as coming from HelloAsso is circulating on a specialist forum. The company's investigation found no vulnerability, and the file doesn't match its own data β€” a rare case where verification counts against the claim.

⚠️ This case file documents the opposite of a confirmed breach. A file claimed to come from HelloAsso is circulating on a specialist forum β€” but the company's own investigation found no security vulnerability, and the file doesn't match its own data. This is a case of a likely mistaken claim, not a confirmed incident.

What was claimed, and what the investigation found

160,000
Association leaders and IBANs claimed in the circulating file β€” the hacker's figure, not validated.
Forum claim, reported by cyberattaque.org.
0
Security vulnerability identified by HelloAsso's internal investigation that could explain a leak.
HelloAsso analysis, reported by cyberattaque.org.
Inconsistencies
Numerous entries in the claimed file don't match any data held by HelloAsso, per the company's comparison.
HelloAsso analysis.
?
The file's actual origin β€” several hypotheses (multi-source compilation, mistaken attribution), no certainty as of writing.
As of 08/21/2026.

What HelloAsso's investigation established

Faced with the claim, HelloAsso obtained a copy of the circulating file and compared it methodically against its own databases. The result: numerous inconsistencies. Some rows in the file don't match any record held by the company; the structure and content of several entries don't match its internal systems. These differences strengthen the hypothesis that the database came from another source, was compiled from several distinct files, or was mistakenly attributed to HelloAsso.

πŸ”Why this case earns its own page

Most case files on this site distinguish what's confirmed from what's claimed β€” Alaxione is the clearest example, with a sample of roughly 1,000 rows that doesn't prove possession of eighteen million. This case goes a step further: here, the targeted company actively verified the claim and found nothing corroborating it. That's not an absence of proof β€” it's the beginning of proof to the contrary.

What it changes for you

If you manage an association through HelloAsso, nothing so far indicates your data is affected by this specific file. The general vigilance documented in From Leak to Scam remains valid for any other confirmed leak, but this particular claim doesn't warrant specific action from you.

πŸ”’ A circulating leak claim doesn't automatically mean it's well-founded. Checking the cited organization's official response β€” and whether it actively compared the file to its own data, as HelloAsso did here β€” is part of the same rigor that applies to any unverified information.

Frequently asked questions

Was HelloAsso breached?

According to the company's own investigation, no. No security vulnerability was identified, and no technical evidence links the claimed file to a compromise of its services.

Why doesn't the claimed file prove anything?

HelloAsso's comparison with its own data revealed numerous inconsistencies, suggesting a different origin or a mistaken attribution.

What should I do if I manage an association through HelloAsso?

Nothing specific to this particular incident, since it isn't established that HelloAsso is the source.

πŸ“Œ Last checked: August 21, 2026. This page will be updated if new information further confirms or refutes the file's origin. Verifiable information to report: contact@egidio.app.

Related reading

Cite this page Egidio β€” The Threat Laboratory, "HelloAsso: the claim that doesn't match the data," egidio.app/en/laboratoire/helloasso-unverified-claim/. Licensed CC BY 4.0.

Free to reuse, including commercially, with attribution. Reuse terms.