Santé publique France: 80,000 contacts exposed, the platform stayed isolated
Santé publique France confirmed a breach of a platform run by an external
vendor, exposing contact data for nearly 80,000 people.
No health data, bank card, or password was stolen.
⚠️ Confirmed by Santé publique France. The agency
confirmed the incident two days after hackers publicly claimed it. What remains to be
clarified is the exact identity of those affected beyond the reported volume.
The numbers
80,000
People roughly whose contact data was exposed.
Santé publique France, franceinfo, August 13, 2026.
3
Hackers who claimed the attack under the aliases cybernox, artemis
and "d'ont call me."
Incyber News, August 11, 2026.
0
Health data, bank card number or password stolen, according to
Santé publique France.
Santé publique France statement.
1
Platform targeted: moncoupon.santepubliquefrance.fr, hosted by an
external vendor and independent from the agency's other systems.
Franceinfo, August 13, 2026.
Timeline
CLAIMED
August 11, 2026
Three hackers using the aliases cybernox, artemis and "d'ont call
me" claim to have breached a Santé publique France platform.
CONFIRMED
August 13, 2026
Santé publique France confirms that a platform run by an external
vendor, moncoupon.santepubliquefrance.fr, was breached, exposing contact data for
nearly 80,000 people who had ordered free health-prevention documents.
CONFIRMED
Follow-up
The agency states only contact data (email, postal address, phone
number used for shipping documents) is affected — no health data, bank card, or
password.
🧱An isolated platform, a contained incident
This case illustrates good segmentation: the document-ordering platform operated
independently from Santé publique France's other systems. Breaching a peripheral service
therefore did not expose health data — the same containment principle appears in the
Hospices Civils de
Lyon case file.
What it changes for you
If you ordered free health-prevention documents through this platform, your email,
postal address and phone number may have leaked. The main risk is a phishing email or text
posing as an official health agency. See
From Leak to Scam.
🔒 Be wary of any message claiming to be from Santé publique
France that requests urgent action (payment, confirming contact details): the agency never
asks for banking data this way.
Frequently asked questions
Is the Santé publique France breach confirmed?
Yes, by the agency itself on August 13, 2026, after a public claim on August
11.
Is health data affected?
No, according to Santé publique France: only contact data is affected.
Why wasn't the rest of the system affected?
The breached platform was independent from the agency's other systems, which limited
the spread.
📌 Last checked: August 21, 2026. Verifiable
information to report: contact@egidio.app.
Cite this pageEgidio — The Threat Laboratory, "Santé publique France: 80,000 contacts exposed, the platform stayed isolated," egidio.app/en/laboratoire/sante-publique-france-contact-breach/. Licensed CC BY 4.0.
Free to reuse, including commercially, with attribution. Reuse terms.