MGP: 133,000 bank account numbers stolen from a French insurer's vendor
French health insurer Mutuelle Générale de Prévoyance confirmed a cyberattack
exposing 133,018 IBANs and 198,127 identities. The
intrusion didn't target the insurer directly, but one of its technical vendors — a
pattern that keeps recurring across the breaches documented here.
⚠️ This case isn't an unverified claim.
Mutuelle Générale de Prévoyance confirmed the incident itself, filed a criminal complaint,
and a judicial investigation was opened. What remains unclear is the identity of the
targeted technical vendor — MGP hasn't made it public — and the exact accuracy of the
volume claimed by the hacker.
The numbers
133,018
Unique IBANs claimed, confirmed in nature by the insurer itself.
FrenchBreaches, Journal du Geek, 08/20/2026.
198,127
Unique full names claimed — the order of magnitude of members
affected.
FrenchBreaches, 08/20/2026.
45,771
Phone numbers, and 24,489 email addresses, also claimed in the same
batch.
Journal du Geek, 08/20/2026.
0
Health data, payment card numbers, ID copies or passwords
compromised, according to MGP.
MGP statement, reported 08/20/2026.
Timeline
CLAIMED
August 7, 2026
A hacker using the handle "yiranet" claims on a specialist forum
to be selling two data tables sourced from MGP: identities and banking details.
CONFIRMED
August 19-20, 2026
MGP issues a statement confirming it was the "victim of a
cyberattack." The organization specifies that the intrusion did not target its own
systems directly, but one of its technical vendors. A criminal complaint is filed and
a judicial investigation opened. Affected members are notified individually.
🏦The same pattern seen elsewhere on this site
An insurer that wasn't breached directly, but whose members are exposed because a
vendor was — that's exactly the mechanism documented with
CEVA Logistics: the weakest
link is almost never the organization you're a customer of, but one of its technical
subcontractors, whose name you never even knew.
What it changes for you
A stolen IBAN alone can't directly empty an account, but it enables an attempted
fraudulent SEPA direct debit — something banking regulation constrains,
but which requires active vigilance from the victim to dispute in time. Combined with the
name, address, or phone number also exposed, this data can also fabricate a call posing as
the insurer itself, made more credible by knowledge of your real details.
🔒 Watch your bank statements for any unrecognized direct debit
in the weeks following a notification like this, and dispute it promptly with your bank.
A call "from the insurer" asking you to confirm an IBAN or password is still
impersonation, even if it cites your exact data. See
From Leak to Scam and
how Medusa links channels together.
Frequently asked questions
Is the MGP breach confirmed?
Yes. MGP officially stated it was the victim of a cyberattack, filed a criminal
complaint, and a judicial investigation was opened. This is not merely a hacker's
claim.
How did the attack happen?
The attacker targeted one of MGP's technical vendors, not publicly named, rather than
the insurer directly.
What's the risk for the 133,000 people whose bank details leaked?
The main risk is an attempted fraudulent SEPA direct debit. Combined with other
exposed data, it can also fabricate a credible call impersonating the insurer.
📌 Last checked: August 21, 2026. The name of
the targeted technical vendor had not been made public as of this date. Verifiable
information to report: contact@egidio.app.
Cite this pageEgidio — The Threat Laboratory, "MGP: 133,000 bank account numbers stolen from a French insurer's vendor," egidio.app/en/laboratoire/mgp-french-insurer-iban-breach/. Licensed CC BY 4.0.
Free to reuse, including commercially, with attribution. Reuse terms.