Egidio
Case file · August 21, 2026

IRD: confirmed intrusion, Social Security numbers exposed, exfiltration uncertain

France's Institute of Research for Development confirmed an intrusion affecting 7,500 people, with Social Security numbers among the exposed data — but cannot confirm this data was actually exfiltrated.

⚠️ Intrusion confirmed, exfiltration not confirmed. IRD establishes a confidentiality risk after investigation, but explicitly states it cannot confirm the exposed data actually left its systems. An important nuance between "access obtained" and "data stolen."

The numbers

7,500
People notified by IRD following the intrusion.
IRD statement, August 17, 2026; Next.ink, Cyberattaque.org.
Jul 24
Date the external intrusion into IRD's information system was detected.
IRD statement.
SSN
Social Security numbers are among the exposed data — a category rarely documented in the leaks on this site.
IRD statement.
?
Actual exfiltration of the data: IRD states it cannot confirm this at this stage, despite an established confidentiality risk.
IRD statement, August 17, 2026.

Timeline

CONFIRMED
July 24, 2026
IRD detects an unauthorized external intrusion into its information system.
CONFIRMED
August 6, 2026
Investigations conducted after discovering the intrusion establish the existence of a risk to data confidentiality.
CONFIRMED
August 17, 2026
IRD notifies roughly 7,500 people: identity data, personal contact details, professional information and Social Security numbers potentially exposed. The institute states it cannot confirm at this stage whether the exposed data was actually exfiltrated.

🔬"Confidentiality risk" isn't "confirmed exfiltration"

This case file illustrates a precise, rarely explained technical distinction: establishing that a confidentiality risk exists (access was possible) isn't the same as confirming exfiltration took place (data was actually copied and taken). IRD explicitly owns this nuance rather than glossing over it — a rigor worth noting, even though it leaves affected people uncertain.

What it changes for you

If you received a notification from IRD, your Social Security number and personal contact details are among the at-risk data. A Social Security number can't be changed like a password — stay vigilant long-term against any solicitation citing this number or your professional information at IRD. See From Leak to Scam.

🔒 No legitimate organization will ask you to confirm your Social Security number by email or phone following a breach notification — be wary of any message that does.

Frequently asked questions

Is the IRD leak confirmed?

The intrusion is confirmed; the actual exfiltration of data is not, according to IRD itself.

What data is affected?

Identity, personal contact details, professional information, Social Security numbers.

What is IRD?

A French public scientific research body focused on development issues.

📌 Last checked: August 21, 2026. Verifiable information to report: contact@egidio.app.

Related reading

Cite this page Egidio — The Threat Laboratory, "IRD: confirmed intrusion, Social Security numbers exposed, exfiltration uncertain," egidio.app/en/laboratoire/ird-sensitive-data-breach/. Licensed CC BY 4.0.

Free to reuse, including commercially, with attribution. Reuse terms.