Egidio
Case file · August 21, 2026

MGP: 133,000 bank account numbers stolen from a French insurer's vendor

French health insurer Mutuelle Générale de Prévoyance confirmed a cyberattack exposing 133,018 IBANs and 198,127 identities. The intrusion didn't target the insurer directly, but one of its technical vendors — a pattern that keeps recurring across the breaches documented here.

⚠️ This case isn't an unverified claim. Mutuelle Générale de Prévoyance confirmed the incident itself, filed a criminal complaint, and a judicial investigation was opened. What remains unclear is the identity of the targeted technical vendor — MGP hasn't made it public — and the exact accuracy of the volume claimed by the hacker.

The numbers

133,018
Unique IBANs claimed, confirmed in nature by the insurer itself.
FrenchBreaches, Journal du Geek, 08/20/2026.
198,127
Unique full names claimed — the order of magnitude of members affected.
FrenchBreaches, 08/20/2026.
45,771
Phone numbers, and 24,489 email addresses, also claimed in the same batch.
Journal du Geek, 08/20/2026.
0
Health data, payment card numbers, ID copies or passwords compromised, according to MGP.
MGP statement, reported 08/20/2026.

Timeline

CLAIMED
August 7, 2026
A hacker using the handle "yiranet" claims on a specialist forum to be selling two data tables sourced from MGP: identities and banking details.
CONFIRMED
August 19-20, 2026
MGP issues a statement confirming it was the "victim of a cyberattack." The organization specifies that the intrusion did not target its own systems directly, but one of its technical vendors. A criminal complaint is filed and a judicial investigation opened. Affected members are notified individually.

🏦The same pattern seen elsewhere on this site

An insurer that wasn't breached directly, but whose members are exposed because a vendor was — that's exactly the mechanism documented with CEVA Logistics: the weakest link is almost never the organization you're a customer of, but one of its technical subcontractors, whose name you never even knew.

What it changes for you

A stolen IBAN alone can't directly empty an account, but it enables an attempted fraudulent SEPA direct debit — something banking regulation constrains, but which requires active vigilance from the victim to dispute in time. Combined with the name, address, or phone number also exposed, this data can also fabricate a call posing as the insurer itself, made more credible by knowledge of your real details.

🔒 Watch your bank statements for any unrecognized direct debit in the weeks following a notification like this, and dispute it promptly with your bank. A call "from the insurer" asking you to confirm an IBAN or password is still impersonation, even if it cites your exact data. See From Leak to Scam and how Medusa links channels together.

Frequently asked questions

Is the MGP breach confirmed?

Yes. MGP officially stated it was the victim of a cyberattack, filed a criminal complaint, and a judicial investigation was opened. This is not merely a hacker's claim.

How did the attack happen?

The attacker targeted one of MGP's technical vendors, not publicly named, rather than the insurer directly.

What's the risk for the 133,000 people whose bank details leaked?

The main risk is an attempted fraudulent SEPA direct debit. Combined with other exposed data, it can also fabricate a credible call impersonating the insurer.

📌 Last checked: August 21, 2026. The name of the targeted technical vendor had not been made public as of this date. Verifiable information to report: contact@egidio.app.

Related reading

Cite this page Egidio — The Threat Laboratory, "MGP: 133,000 bank account numbers stolen from a French insurer's vendor," egidio.app/en/laboratoire/mgp-french-insurer-iban-breach/. Licensed CC BY 4.0.

Free to reuse, including commercially, with attribution. Reuse terms.