IRD: confirmed intrusion, Social Security numbers exposed, exfiltration uncertain
France's Institute of Research for Development confirmed an intrusion affecting
7,500 people, with Social Security numbers among the
exposed data — but cannot confirm this data was actually exfiltrated.
⚠️ Intrusion confirmed, exfiltration not confirmed.
IRD establishes a confidentiality risk after investigation, but explicitly states it cannot
confirm the exposed data actually left its systems. An important nuance between "access
obtained" and "data stolen."
The numbers
7,500
People notified by IRD following the intrusion.
IRD statement, August 17, 2026; Next.ink, Cyberattaque.org.
Jul 24
Date the external intrusion into IRD's information system was
detected.
IRD statement.
SSN
Social Security numbers are among the exposed data — a category
rarely documented in the leaks on this site.
IRD statement.
?
Actual exfiltration of the data: IRD states it cannot confirm this
at this stage, despite an established confidentiality risk.
IRD statement, August 17, 2026.
Timeline
CONFIRMED
July 24, 2026
IRD detects an unauthorized external intrusion into its
information system.
CONFIRMED
August 6, 2026
Investigations conducted after discovering the intrusion
establish the existence of a risk to data confidentiality.
CONFIRMED
August 17, 2026
IRD notifies roughly 7,500 people: identity data, personal
contact details, professional information and Social Security numbers potentially
exposed. The institute states it cannot confirm at this stage whether the exposed data
was actually exfiltrated.
This case file illustrates a precise, rarely explained technical distinction:
establishing that a confidentiality risk exists (access was possible) isn't the same as
confirming exfiltration took place (data was actually copied and taken). IRD explicitly
owns this nuance rather than glossing over it — a rigor worth noting, even though it
leaves affected people uncertain.
What it changes for you
If you received a notification from IRD, your Social Security number and personal
contact details are among the at-risk data. A Social Security number can't be changed like
a password — stay vigilant long-term against any solicitation citing this number or your
professional information at IRD. See
From Leak to Scam.
🔒 No legitimate organization will ask you to confirm your
Social Security number by email or phone following a breach notification — be wary of any
message that does.
Frequently asked questions
Is the IRD leak confirmed?
The intrusion is confirmed; the actual exfiltration of data is not, according to IRD
itself.
What data is affected?
Identity, personal contact details, professional information, Social Security
numbers.
What is IRD?
A French public scientific research body focused on development issues.
📌 Last checked: August 21, 2026. Verifiable
information to report: contact@egidio.app.
Cite this pageEgidio — The Threat Laboratory, "IRD: confirmed intrusion, Social Security numbers exposed, exfiltration uncertain," egidio.app/en/laboratoire/ird-sensitive-data-breach/. Licensed CC BY 4.0.
Free to reuse, including commercially, with attribution. Reuse terms.