Egidio
Case file · August 21, 2026

SUEZ Eau France: bank details and ID documents exposed via a vendor

SUEZ Eau France confirmed an incident at an unnamed technical vendor: bank details, ID documents and photos of customers potentially exposed. The company states it cannot guarantee that each notified customer's data was specifically stolen.

⚠️ Confirmed by SUEZ, but with an explicit caveat. SUEZ Eau France acknowledges the incident at a vendor and the publication of some data online, while stating it cannot guarantee that each notified customer's data was specifically stolen. A middle case between full confirmation and an unverified claim.

The numbers

Aug 20
Date SUEZ Eau France notified its affected customers.
FrenchBreaches, August 20, 2026.
6
Categories of data potentially exposed: identity, contact, contract documents, ID document and photo, bank details, personal situation.
SUEZ client notice.
?
Number of customers actually affected, vendor identity, exact date and duration of the compromise, total volume exfiltrated: none of this is made public by SUEZ.
Not publicly disclosed.
0
Direct compromise of SUEZ Eau France's own systems, according to the company — the incident happened at a technical vendor.
SUEZ client notice.

Timeline

CONFIRMED
August 20, 2026
SUEZ Eau France notifies some customers of a cybersecurity incident affecting one of its technical vendors. Data was reportedly extracted and, in part, made accessible online.
SUEZ'S EXPLICIT CAVEAT
Same notice
SUEZ states: "at this stage, we cannot confirm that your [personal] data" was actually stolen. The company acknowledges the incident and the publication of some data, without being able to guarantee completeness at the individual level.
CONFIRMED
Follow-up
An investigation is underway with the vendor and cybersecurity experts. The vendor's identity, the exact volume exfiltrated, and the duration of the compromise are not made public at this stage.

⚖️Neither full confirmation nor a bare claim

This case file sits in a middle position in this site's methodology: SUEZ does confirm the incident and the publication of data — this isn't a mere unverified hacker claim. But the company itself acknowledges it cannot guarantee that each notified person's data was specifically stolen. This caution, rare in corporate communication, deserves both credit and note: it makes the level of certainty more honest, but leaves each customer uncertain about their individual case.

What it changes for you

If you're a SUEZ Eau France customer and received a notification, your bank details and an ID document could be among the exposed data. The main risk is a call or email posing as SUEZ, asking you to "verify" a bank account or ID document. See From Leak to Scam.

🔒 Watch your bank statements for any unrecognized charge, and never share bank details or an ID document in response to an unsolicited call or email, even if it cites your exact SUEZ contract.

Frequently asked questions

Is the SUEZ Eau France breach confirmed?

Yes, partially: SUEZ confirms the incident at a vendor and the publication of some data, without guaranteeing each customer's data was specifically stolen.

What data is affected?

Identity, contact, contract documents, ID document and photo, bank details, personal situation.

Who is the vendor involved?

Not publicly identified by SUEZ, which states only that its own systems were not directly compromised.

📌 Last checked: August 21, 2026. Verifiable information to report: contact@egidio.app.

Related reading

Cite this page Egidio — The Threat Laboratory, "SUEZ Eau France: bank details and ID documents exposed via a vendor," egidio.app/en/laboratoire/suez-eau-france-vendor-breach/. Licensed CC BY 4.0.

Free to reuse, including commercially, with attribution. Reuse terms.