French mutual Solimut Mutuelle de France confirmed on August 23, 2026 that a cyberattack caused a personal-data breach the same morning. Actor misere claims a full member-database copy covering about 1.24 million insured, hundreds of thousands of bank accounts, and social-security (NIR) fields. Solimut has not yet published its own census. Official notice: Solimut communiqué. Catalog: solimut-misere2026.
Health-mutual breaches land differently than retail dumps. NIR + IBAN + identity in the same marketing claim is why French coverage treated this as a Sunday emergency.
What Solimut confirmed
Solimut says it identified the attack the morning of August 23, isolated the intrusion, kept services running, notified the ACPR the same day, and will notify the CNIL on the statutory timeline. Investigations continue to inventory exactly which personal data left. Members are warned about phishing by email or phone from entities outside the mutuelle.
What misere claims (unverified counts)
Trade coverage summarizing misere’s listing cites roughly 1,244,445 insured, 770,467 bank accounts, ~1.38 million individual files, ~1.08 million DSN social declarations, and large address/history tables. Sample CSVs reviewed by Cyberattaque.org allegedly show identity, contact, banking, DSN, contract, and AGIRA-related tables. ZeroBytes separately claimed ~4.4M rows / ~1.37M NIR / ~780k IBAN via SQLi — also unverified and not Solimut’s numbers.
BreachHistory indexes recordsAffected at 1244445 as the actor insured floor until Solimut publishes an attested count.
Who is at risk
Adhérents and beneficiaries (including children in family contracts), employees appearing in DSN extracts, prospects, and partners in management tables if the actor dump is accurate. Even people who left Solimut years ago may sit in history tables.
Action items
- Treat unexpected “Solimut reimbursement” SMS as hostile until verified in your member space.
- Do not read IBAN or NIR aloud to inbound callers.
- Watch bank accounts for unfamiliar SEPA mandate changes.
- Enable MFA on the member portal when offered.
- Parents: monitor minor beneficiaries’ identity-fraud risk separately.
- Employers using Solimut collective covers: brief HR about DSN-themed phishing.
- Keep only the official solimut-mutuelle.fr domain for news.
- Wait for Solimut’s individual notification before assuming you are out of scope.
Canonical record
solimut-misere2026 — companyConfirmed true for the Aug 23 notice; actor insured count 1,244,445 pending mutuelle census. Sources: Solimut + Cyberattaque.org.
Phishing after a named breach almost always arrives before the polished FAQ. Attackers do not wait for your insurer or mutuelle to finish forensics. They need a headline and a few accurate fields.
Reuse of passwords across sports, travel, and health portals remains the fastest path from an email dump to account takeover. Unique passwords plus MFA beat regret.
Journalists should separate confirmed company sentences from actor table counts in every headline. Collapsing them produces false precision.
Regulators measuring notification quality will look at how quickly individuals learn actionable steps — not how quickly a leak site posts screenshots.
If you forward breach news in family chats, forward the official domain and the BreachHistory canonical link, not a screenshot of a forum sales thread.
Secondary scams include fake credit-monitoring signups, fake CNIL or PIPEDA complaint portals, and “leak lookup” apps that harvest more data than they return.
Companies reading this as a peer incident should tabletop: Sunday discovery, same-day regulator notice, member SMS without payment links, and a holding statement that refuses to invent a census.
Data minimization still wins. NIR and IBAN in the same wide analytics table is a gift to whoever lands a SQLi or supplier foothold.
International readers with French or Canadian accounts should not assume “local only.” Diaspora inboxes get the same personalized lures.
BreachHistory updates rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture.
Call-center staff should use out-of-band verification when a caller recites breach trivia. Accuracy is not authentication.
Clubs, brokers, and HR partners often become the weak redistribution channel for stolen contact lists. Brief them early.
Open browser bookmarks to official portals now so you are not searching under panic later.
When samples appear in trade press, demand schema description without republishing identifiable rows.
Expect copycat leak posts that paste the same victim name with inflated numbers. Check dates and primary URLs.
Legal teams drafting class notices should wait for inventory rather than marketing every actor CSV as gospel.
Members who already froze credit or enabled MFA after older breaches still need a fresh look at SEPA mandates and email filters.
The practical closing line: confirm via official channels, rotate reused passwords, and treat hyper-accurate outreach as hostile.
Phishing after a named breach almost always arrives before the polished FAQ. Attackers do not wait for your insurer or mutuelle to finish forensics. They need a headline and a few accurate fields.
Reuse of passwords across sports, travel, and health portals remains the fastest path from an email dump to account takeover. Unique passwords plus MFA beat regret.
Journalists should separate confirmed company sentences from actor table counts in every headline. Collapsing them produces false precision.
Regulators measuring notification quality will look at how quickly individuals learn actionable steps — not how quickly a leak site posts screenshots.
If you forward breach news in family chats, forward the official domain and the BreachHistory canonical link, not a screenshot of a forum sales thread.
Secondary scams include fake credit-monitoring signups, fake CNIL or PIPEDA complaint portals, and “leak lookup” apps that harvest more data than they return.
Companies reading this as a peer incident should tabletop: Sunday discovery, same-day regulator notice, member SMS without payment links, and a holding statement that refuses to invent a census.
Data minimization still wins. NIR and IBAN in the same wide analytics table is a gift to whoever lands a SQLi or supplier foothold.
International readers with French or Canadian accounts should not assume “local only.” Diaspora inboxes get the same personalized lures.
BreachHistory updates rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture.
Call-center staff should use out-of-band verification when a caller recites breach trivia. Accuracy is not authentication.
Clubs, brokers, and HR partners often become the weak redistribution channel for stolen contact lists. Brief them early.
Open browser bookmarks to official portals now so you are not searching under panic later.
When samples appear in trade press, demand schema description without republishing identifiable rows.
Expect copycat leak posts that paste the same victim name with inflated numbers. Check dates and primary URLs.
Legal teams drafting class notices should wait for inventory rather than marketing every actor CSV as gospel.
Members who already froze credit or enabled MFA after older breaches still need a fresh look at SEPA mandates and email filters.
The practical closing line: confirm via official channels, rotate reused passwords, and treat hyper-accurate outreach as hostile.
Phishing after a named breach almost always arrives before the polished FAQ. Attackers do not wait for your insurer or mutuelle to finish forensics. They need a headline and a few accurate fields.
Reuse of passwords across sports, travel, and health portals remains the fastest path from an email dump to account takeover. Unique passwords plus MFA beat regret.
Journalists should separate confirmed company sentences from actor table counts in every headline. Collapsing them produces false precision.
Regulators measuring notification quality will look at how quickly individuals learn actionable steps — not how quickly a leak site posts screenshots.
If you forward breach news in family chats, forward the official domain and the BreachHistory canonical link, not a screenshot of a forum sales thread.
Secondary scams include fake credit-monitoring signups, fake CNIL or PIPEDA complaint portals, and “leak lookup” apps that harvest more data than they return.
Companies reading this as a peer incident should tabletop: Sunday discovery, same-day regulator notice, member SMS without payment links, and a holding statement that refuses to invent a census.
Data minimization still wins. NIR and IBAN in the same wide analytics table is a gift to whoever lands a SQLi or supplier foothold.
International readers with French or Canadian accounts should not assume “local only.” Diaspora inboxes get the same personalized lures.
BreachHistory updates rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture.
Call-center staff should use out-of-band verification when a caller recites breach trivia. Accuracy is not authentication.
Clubs, brokers, and HR partners often become the weak redistribution channel for stolen contact lists. Brief them early.
Open browser bookmarks to official portals now so you are not searching under panic later.
When samples appear in trade press, demand schema description without republishing identifiable rows.
Expect copycat leak posts that paste the same victim name with inflated numbers. Check dates and primary URLs.
Legal teams drafting class notices should wait for inventory rather than marketing every actor CSV as gospel.
Members who already froze credit or enabled MFA after older breaches still need a fresh look at SEPA mandates and email filters.
The practical closing line: confirm via official channels, rotate reused passwords, and treat hyper-accurate outreach as hostile.
BreachHistory will revise this page when primary sources publish a tighter census, field list, or confirmation status. Until then, treat actor marketing numbers as labeled claims and company notices as the floor of what is confirmed.
BreachHistory will revise this page when primary sources publish a tighter census, field list, or confirmation status. Until then, treat actor marketing numbers as labeled claims and company notices as the floor of what is confirmed.
BreachHistory will revise this page when primary sources publish a tighter census, field list, or confirmation status. Until then, treat actor marketing numbers as labeled claims and company notices as the floor of what is confirmed.
BreachHistory will revise this page when primary sources publish a tighter census, field list, or confirmation status. Until then, treat actor marketing numbers as labeled claims and company notices as the floor of what is confirmed.
BreachHistory will revise this page when primary sources publish a tighter census, field list, or confirmation status. Until then, treat actor marketing numbers as labeled claims and company notices as the floor of what is confirmed.
BreachHistory will revise this page when primary sources publish a tighter census, field list, or confirmation status. Until then, treat actor marketing numbers as labeled claims and company notices as the floor of what is confirmed.
BreachHistory will revise this page when primary sources publish a tighter census, field list, or confirmation status. Until then, treat actor marketing numbers as labeled claims and company notices as the floor of what is confirmed.
BreachHistory will revise this page when primary sources publish a tighter census, field list, or confirmation status. Until then, treat actor marketing numbers as labeled claims and company notices as the floor of what is confirmed.
BreachHistory will revise this page when primary sources publish a tighter census, field list, or confirmation status. Until then, treat actor marketing numbers as labeled claims and company notices as the floor of what is confirmed.
BreachHistory will revise this page when primary sources publish a tighter census, field list, or confirmation status. Until then, treat actor marketing numbers as labeled claims and company notices as the floor of what is confirmed.
BreachHistory will revise this page when primary sources publish a tighter census, field list, or confirmation status. Until then, treat actor marketing numbers as labeled claims and company notices as the floor of what is confirmed.
BreachHistory will revise this page when primary sources publish a tighter census, field list, or confirmation status. Until then, treat actor marketing numbers as labeled claims and company notices as the floor of what is confirmed.
BreachHistory will revise this page when primary sources publish a tighter census, field list, or confirmation status. Until then, treat actor marketing numbers as labeled claims and company notices as the floor of what is confirmed.
BreachHistory will revise this page when primary sources publish a tighter census, field list, or confirmation status. Until then, treat actor marketing numbers as labeled claims and company notices as the floor of what is confirmed.
BreachHistory will revise this page when primary sources publish a tighter census, field list, or confirmation status. Until then, treat actor marketing numbers as labeled claims and company notices as the floor of what is confirmed.
BreachHistory will revise this page when primary sources publish a tighter census, field list, or confirmation status. Until then, treat actor marketing numbers as labeled claims and company notices as the floor of what is confirmed.
BreachHistory will revise this page when primary sources publish a tighter census, field list, or confirmation status. Until then, treat actor marketing numbers as labeled claims and company notices as the floor of what is confirmed.
BreachHistory will revise this page when primary sources publish a tighter census, field list, or confirmation status. Until then, treat actor marketing numbers as labeled claims and company notices as the floor of what is confirmed.
BreachHistory will revise this page when primary sources publish a tighter census, field list, or confirmation status. Until then, treat actor marketing numbers as labeled claims and company notices as the floor of what is confirmed.
BreachHistory will revise this page when primary sources publish a tighter census, field list, or confirmation status. Until then, treat actor marketing numbers as labeled claims and company notices as the floor of what is confirmed.