Unverified claim — August 20, 2026: French outlet La Dépêche and tracker French Breaches report that forum actor Angel_Batista claims to have breached Alaxione, a French medical appointment platform, and extracted about 6.835 million user profiles plus 10.1 million appointment rows (~12.8 GB). Alaxione had not issued a public confirmation at indexing. Canonical row: alaxione-angelbatista2026.
France’s healthcare IT stack has taken hit after hit in 2025–2026. Cegedim Santé’s MLM software breach left roughly 15.8 million patient administrative dossiers in play. Viamedis and Almerys portal incidents put insurance pathways under a microscope. Now a rendez-vous platform that sits between patients and private practitioners is in the headlines — and the claim is large enough that even an unverified listing deserves a careful walkthrough of what was alleged, what remains unproven, and what patients should do without waiting for a polished corporate FAQ.
What the Alaxione data breach claim says
According to French Breaches’ August 20 analysis of the forum post, Angel_Batista alleges weeks of access across several Alaxione subdomains, culminating in a short exfiltration window (the actor claims roughly ten minutes) from a preproduction environment that held a temporary copy of the full database. The advertised haul is precise on paper: 6,835,489 user records, more than 10.1 million appointments, and a combined dump framed as about 18 million rows / 12.8 GB.
Published schema snippets — not the same as a verified dump — list identity fields, contact details, dates of birth, Social Security (NIR) columns, practitioner identifiers, appointment metadata, consultation motives, messaging fields, insurance-related columns, and even IBAN/BIC fields. French Breaches is careful on one point that matter-of-fact summaries often blur: a column existing in a schema does not prove every one of the 6.8 million rows has a filled NIR or bank account. La Dépêche’s headline also floated about 70,000 Social Security numbers in some coverage framing; treat that figure as press shorthand pending a company or CNIL census, not as an independently attested subset.
What Alaxione is — and why appointment data cuts deep
Alaxione markets itself as a management and online booking platform for medical practices. That puts it in the same risk class as other scheduling SaaS products: it holds the connective tissue between a patient’s identity, a clinician, a time slot, and often a free-text reason for the visit. Even without a full EHR, that combination is health-adjacent. A motive field next to a dermatologist visit is one thing; the same field next to an oncology, psychiatry, or sexual-health specialty is another. Messages exchanged around appointments can amplify the exposure further if they include clinical detail, photos, or insurance context.
French patients already live with a crowded phishing environment built on real administrative facts — ameli.fr lookalikes, fake “rendez-vous reporté” SMS, CNAM-themed QR codes. An Alaxione-shaped dataset would give attackers better props: a real clinic name, a real appointment time, a real phone number on file. That is the practical risk even while the breach remains unverified.
Timeline of what we know
- Weeks before public post (actor claim): Angel_Batista says access to Alaxione-related subdomains went undetected.
- ~Two days before publication (actor claim): The actor says Alaxione was contacted ahead of the dump.
- August 20, 2026: French Breaches publishes analysis; La Dépêche amplifies the 6.8 million figure nationally.
- At indexing: No Alaxione customer letter, no CNIL public enforcement notice, and no company confirmation located in sources reviewed.
Until Alaxione or a French authority confirms, every count above is an actor-attested claim. BreachHistory indexes recordsAffected at 6835489 as the advertised user-profile count and labels the row unverified.
What data was allegedly exposed
French Breaches’ field inventory is the best public summary:
- Names, contact details, dates of birth
- Social Security number (NIR) columns — fill rate unknown
- Healthcare professional identifiers and practice context
- Appointment dates, locations, status, amounts, recurrence flags
- Consultation motives and related messaging
- Insurance-related fields
- IBAN/BIC columns — again, not proven for every user
Separately, the actor frames 16 years of appointment history in some descriptions (back to around 2009). Long retention is common in medical SaaS; it also means a single platform compromise can surface people who last booked a dentist a decade ago and forgot they ever had an Alaxione login.
What we do not know
Alaxione has not confirmed the intrusion path, the preproduction story, the ten-minute exfiltration claim, or the authenticity of the 12.8 GB archive. Independent journalists have not published a full dump analysis matching French Breaches’ column list to live production records. There is no public CNIL complaint summary tied to this specific August 20 claim at indexing time. Readers should treat social-media “I found my NIR in the leak” screenshots with skepticism unless they come with verifiable provenance.
Who is at risk
Patients who booked through Alaxione-connected practices — especially those whose motives or messages were stored — face medical-themed phishing and social-engineering risk. Practitioners and clinic staff appear in professional tables and could be impersonated in patient outreach. People with IBAN fields populated (if any) face a narrower payment-fraud vector. Even users outside France who booked while traveling could appear if their records sat in the same tenancy.
How this fits France’s 2026 health-data wave
Put Alaxione next to Cegedim Santé (~15.8M administrative dossiers) and the broader DentaQuest / CareCloud wave in the U.S. and the pattern is clear: attackers prefer the vendors that sit behind many clinics rather than hacking each practice one by one. Appointment platforms are soft targets because they must be internet-reachable, they accumulate years of PII, and clinics rarely treat them with the same paranoia as hospital EHRs — even when the data is nearly as sensitive.
Politically, the claim landed a day after French reporting that Prime Minister Sébastien Lecornu wanted a specialized unit for intrusion and data-theft defense. That context does not prove Alaxione was breached; it does explain why a 6.8 million medical-booking claim raced through national media so quickly.
What Alaxione and regulators have said
As of BreachHistory indexing on August 20, 2026, Alaxione had not published a patient-facing security notice matching the Angel_Batista claim. French Breaches documents the claim and schema; La Dépêche relays the scale to a general audience. Watch for a future CNIL notification, an Alaxione status post, or practice-level letters — those would move this row from unverified to confirmed and may revise the count.
Action items if you use Alaxione or book through it
- Assume phishing will cite a real clinic name and appointment time. Do not click SMS or email “confirm / pay / cancel” links — open your practice’s known booking URL manually.
- If you reuse a password on Alaxione or a clinic portal, change it everywhere it was reused. Prefer a password manager and unique credentials.
- Enable MFA on email accounts that receive appointment confirmations; mailbox takeover is how fake “lab results” campaigns scale.
- Watch bank statements if you ever stored payment details with a practice that uses Alaxione; IBAN fields were listed in the claimed schema.
- For NIR exposure concerns, rely on official ameli / Assurance Maladie channels — not Telegram “check if you’re in the leak” bots.
- Practices: rotate staff portal passwords, review Alaxione admin accounts, and ask the vendor in writing whether your tenancy is in scope.
- Keep the French Breaches and La Dépêche links; ignore Breachsense-style aggregators that recycle claims without primary sources.
- If you receive a letter claiming to be from Alaxione, verify the domain and call the practice’s published number before enrolling in any “credit monitoring” upsell.
Canonical record and sources
BreachHistory indexes this as 2026 Alaxione — Angel_Batista 6.8M profiles / 10.1M appointments claim (unverified) with companyConfirmed: false and recordsAffected: 6835489 from the actor’s user-profile count.
Sources: French Breaches, La Dépêche, related catalog Cegedim Santé.
Related reading on BreachHistory: how France’s supplier-side health breaches concentrate risk for patients who never chose the vendor, why appointment motives are PHI-adjacent even without a full chart, and why unverified forum claims still belong in a public chronology when the named victim and count are concrete enough to search for.
If Alaxione later confirms a smaller census — or denies the claim entirely — this page’s catalog row will be updated. Until then, the honest summary is simple: a named French medical-booking platform is the subject of a large, detailed, still-unverified extortion-adjacent dump claim, and patients should harden against appointment phishing now rather than waiting for a polished post-mortem.
For comparison, U.S. readers tracking Amazon-owned One Medical Seniors (HHS OCR ~153,174) or CareCloud (HHS OCR ~3.76M) will recognize the same lesson: healthcare identity data travels through vendors that patients rarely Google until a breach headline forces them to. Alaxione’s claim, verified or not, is another reminder that the booking button on a clinic website is a data-trust decision.
France’s Assurance Maladie numbers are lifelong identifiers. Even a partial NIR fill rate across millions of appointment profiles would be enough to fuel long-running tax and benefits fraud. That is why French Breaches spends so much space distinguishing schema presence from filled values — and why this Alaxione data breach write-up refuses to treat La Dépêche’s 6.8 million figure as company-confirmed fact.
Security teams at French clinics should treat the Angel_Batista post as a tabletop exercise regardless of confirmation: map which booking SaaS you use, who has admin on it, whether preproduction mirrors production PII, and how you would notify patients if CNIL timelines start. Those questions remain useful even if this specific claim collapses.
Patients who never heard of Alaxione may still be in a practice’s export. Ask your médecin traitant or specialist office which online booking tool they use. If the answer is Alaxione, ask whether they have received vendor guidance since August 20. Document the answer. If a convincing SMS arrives tomorrow citing tomorrow’s appointment, you will already know which vendor name is legitimate and which domain to type by hand.
Finally, do not download alleged Alaxione archives from forums “to check if you’re in them.” That is how secondary malware and further doxxing spreads. Use official notices, practice letters, and reputable trade press. BreachHistory’s job is the chronology and the caveats — not a mirror of the dump.
Phishing patterns to expect after an Alaxione headline
French breach news cycles follow a familiar script. Within hours of a La Dépêche-style headline, SMS traffic spikes with “Votre rendez-vous est annulé — confirmez ici” links. Emails arrive from lookalike domains that swap a digit in alaxione.com or hide behind free mail. Voice calls claim to be the secretariat of a named clinique and ask the patient to “verify” a NIR “because of the cyberattaque.” Attackers do not need the dump to be real for that playbook to work — they only need the public claim to sound plausible.
Concrete defenses beat generic “stay vigilant” advice. Save your practice’s published phone number in contacts under the clinic’s real name. When a message cites an appointment, call that saved number and ask whether they sent it. Never read back a full NIR to an inbound caller. If a page asks you to upload a carte Vitale photo “for re-enrollment after the hack,” close the tab.
For clinic IT and practice managers
If your cabinet uses Alaxione, treat August 20 as an incident-response drill even without vendor confirmation. Inventory admin users. Disable accounts for former staff. Confirm whether you still have patients in a shared tenancy versus a dedicated instance. Ask Alaxione — in writing — whether preproduction environments ever held production copies of patient tables, how long those copies are retained, and whether your organization appears in any forensic scope. Document the answers for CNIL readiness.
Also review what your practice stores in motive and messaging fields. Free-text “motif” boxes are where clinicians type the sensitive part. If your workflow can move clinical detail into the EHR and leave booking notes generic, do that going forward. Breach claims like Angel_Batista’s are a reminder that scheduling SaaS is not a low-sensitivity system.
How BreachHistory will update this story
We will revise alaxione-angelbatista2026 if Alaxione confirms, denies, or publishes a smaller attested census; if CNIL or another authority posts a formal notice; or if reputable trade press authenticates a dump sample against production records. Until one of those happens, search results for “Alaxione data breach” should keep the unverified label in the first screen of results — which is why this blog leads with it.
Readers comparing this claim to verified French health incidents should start with Cegedim Santé, where ministry-level confirmation and a ~15.8 million administrative-dossier figure changed the evidentiary bar. Alaxione is not in that category yet. The difference matters for patients deciding whether to freeze credit, file complaints, or simply harden against phishing.
One more practical note for expatriates and cross-border patients: if you booked a French specialist while traveling and used an email you still monitor, watch that inbox. Appointment platforms often keep foreign patients in the same tables as domestic ones. Language barriers make phishing easier — an English-language “Alaxione security team” email can look official to someone who never read the French UI carefully.
Parents booking for children should remember that pediatric appointment motives (developmental, mental health, chronic disease follow-up) are among the most sensitive strings a scheduling system can hold. If a school or activity later asks for medical paperwork after a “data leak,” verify the request through the school’s known channel, not through a link in an unexpected SMS.
Insurers and mutuelles sometimes appear in booking metadata. A convincing fake “your mutuelle needs you to re-validate after Alaxione” message is predictable. Log into your insurer’s official app or site from a bookmark, not from the message. The same rule applies to ameli.fr: type it yourself.
Journalists and researchers reading the Angel_Batista schemas should avoid republishing sample rows that contain real patient names. French Breaches’ caution on fill rates is the right model. Amplifying identifiable samples helps the actor’s extortion narrative more than it helps the public.
If you are an Alaxione customer practice and you already received a private vendor note that has not been posted publicly, consider whether your professional association or ARS guidance requires a local patient notice even before a national press release. Local letters beat silence when appointment phishing is already circulating in your département.
Bottom line for searchers landing on this page from “Alaxione data breach 2026” or “piratage Alaxione 6,8 millions”: the claim is large, detailed, and still unverified; the phishing risk is real either way; and the canonical BreachHistory record will track confirmation if and when it arrives.