Egidio
Case file Β· August 21, 2026

INSERM: 189,997 health-professional profiles claimed, origin uncertain

The hacker peluche911 claims 189,997 profiles of healthcare professionals linked to an Inserm.fr service. Not confirmed by INSERM, and the exact origin of the leak remains uncertain.

⚠️ Claimed by a hacker, not confirmed by INSERM. No public statement from INSERM confirming this leak was found at the time of writing. This case file documents a claim, not an established fact β€” and the exact origin of the leak remains uncertain.

The numbers

189,997
Profiles claimed in a JSON file distributed by the hacker peluche911.
Cyberattaque.org, August 3, 2026, unconfirmed claim.
June 2026
Presumed month of the extraction, per the hacker's own description β€” scraping carried out through an account with the necessary permissions.
Cyberattaque.org, unconfirmed claim.
?
Exact origin of the leak: direct INSERM intrusion, hosted application, or partner service using the inserm.fr domain β€” undetermined from available sources.
Not publicly determined.
6
Data categories per profile in the published sample: identity, professional contact, health identifiers, workplace, team, role.
Cyberattaque.org, sample published by the hacker.

Timeline

CLAIMED
August 3, 2026
The hacker peluche911 publishes a claim concerning a database linked to a service tied to Inserm.fr: 189,997 profiles allowing identification of healthcare professionals and their workplaces.
UNCONFIRMED
Since
The published sample combines identity, professional contact, health identifiers, workplace, team and role. The hacker describes scraping carried out in June 2026 via an account with the necessary permissions β€” not necessarily a classic technical intrusion. No public confirmation from INSERM has been identified to date.

❓An origin still to be established

This case file illustrates a recurring difficulty with unconfirmed claims: even taking the hacker's statement at face value, it isn't possible to determine whether the source is INSERM itself, an application hosted on its infrastructure, or a third-party service simply using its domain. The described method of acquisition β€” an authorized account used for scraping β€” also differs from a classic technical intrusion, which changes the nature of the risk to address.

What it changes for you

If you're a healthcare professional, your name, workplace, team and role could be in this file β€” pending confirmation. An attacker knowing these details can craft a particularly credible message posing as a colleague, the workplace's IT support, or a health administration. See From Leak to Scam.

πŸ”’ A message citing your workplace, team or exact role doesn't automatically make it legitimate β€” verify any unusual request through an independent channel, even if it seems well informed.

Frequently asked questions

Is the INSERM leak confirmed?

No. The hacker peluche911 claims the leak on August 3, 2026, with no public confirmation from INSERM to date.

Is this a direct intrusion into INSERM's systems?

It's not known: it could be INSERM itself, a hosted application, or a partner service using its domain.

What data is claimed?

Identity, professional contact, health identifiers, workplace, team and role of healthcare professionals.

πŸ“Œ Last checked: August 21, 2026. Verifiable information to report: contact@egidio.app.

Related reading

Cite this page Egidio β€” The Threat Laboratory, "INSERM: 189,997 health-professional profiles claimed, origin uncertain," egidio.app/en/laboratoire/inserm-health-professionals-leak/. Licensed CC BY 4.0.

Free to reuse, including commercially, with attribution. Reuse terms.