When old leaks become a complete identity kit

Nicolas | 10 minutes | Articles
Nick

Nicolas

CEO, Security Engineer

OSCP GXPN CCNP JNCIP-SP

Your name is now a search query

In June 2026, a website appeared that let anyone type a person's first and last name and get back a detailed identity profile. Depending on the person, results could include date and place of birth, postal address, passport and social security numbers, bank details (IBAN) and licence plate.

The site claimed to index around 1.2 billion records about people in France, drawn from more than a hundred sources. Most of the data was not new: it came from earlier cyberattacks, including breaches at public bodies, cross-referenced with legitimate public databases.

Within days, France's data protection authority (CNIL) said such services do not comply with the law, and the government referred the matter to the justice system. The site switched to a paid model shortly after launch. But the lesson goes far beyond one website.

Where the data came from

The site's creator never published his list of sources, but journalists identified several. Reports confirmed databases stolen from the ANTS (France's ID and passport agency) and the Assurance maladie, cross-referenced with public sources such as the Insee. Entries seen by reporters were also tagged with breached companies including Free, Bouygues, Cegedim, LinkedIn, Pôle Emploi, LDLC, Bourse des Vols and Autosur. Many others were simply labelled as compilations of earlier leaks.

Other major French breaches hold exactly the kind of data these profiles contain. One example is the Fédération française de tir (FFTir), hacked in October 2025: civil status, postal address, phone, email and licence number of around 250,000 current and 750,000 former licence holders. Whether it feeds this particular site has not been publicly confirmed.

When a leak leads to your front door

Some leaks reveal more than identity: they reveal that you own something worth stealing. After the FFTir breach, authorities warned licence holders that police, gendarmerie or customs would never come to their home to collect their weapons, and said suspicious scouting had already been reported. A later parliamentary question linked the leak to targeted burglaries and weapon thefts. Months later, a breach at the Fédération nationale des chasseurs exposed around 1.4 million hunting permit holders.

The pattern applies well beyond firearms. Any database that ties a name and home address to valuable equipment, whether a membership list, a customer file or a delivery record, can become a shopping list for burglars.

Why aggregation is the real danger

A single leak rarely gives a criminal everything. One breach exposes your email and phone number, another your address, a third your bank details, a fourth an ID number. Each is a fragment.

The risk multiplies when someone stitches the fragments together and makes them searchable by name. A bank detail, a phone number and an official document number in one place form a ready-made kit for identity theft: opening accounts, setting up direct debits, or impersonating a bank or public agency convincingly.

And shutting down one site does not end the problem. Security experts point out that when one such site closes, others quickly appear, and exposed data can circulate indefinitely. That is why prevention and preparation matter more than removal.

How it happens: a hypothetical kill chain

The seven steps below are an illustrative scenario, not a real incident. They show how a flaw in one small online shop can end with a stranger opening a bank account in a customer's name. Look at who can stop each step: the first three depend on the shop, the next two cannot be stopped by anyone once they have happened, the sixth is the one place where the customer can still block the attacker, and the last depends on the bank.

Select a step, press Play, or try stopping the chain at different points.

  • The shop
  • Nobody, once it has happened
  • You
  • The bank
  1. 1Vulnerable shop
  2. 2SQL injection
  3. 3Exfiltration and leak
  4. 4Compilation
  5. 5Lookup
  6. 6Email takeover
  7. 7Identity forgery

A shop with a hole in it

Who can stop it: the shop

A small online store runs an out-of-date plugin, or a search box that passes whatever visitors type straight to its database. Nothing looks wrong: orders keep coming in.

What the attacker gains
A way in that nobody has noticed.
How to break the chain
Keep the shop software and its plugins up to date, scan for known flaws, and make one person responsible for doing it.

The database is tricked into answering

Who can stop it: the shop

The attacker types specially crafted text into a form field. The site mistakes it for a database instruction and obeys, returning data it was never meant to show.

What the attacker gains
Read access to the customer tables: names, email addresses, postal addresses, phone numbers, order history and password hashes.
How to break the chain
Fix the flaw itself: never build database queries from raw input (use parameterised queries). Then add layers around it: a web application firewall in front of the site to filter crafted input, a database firewall or activity monitoring to block or flag abnormal queries, and a database account that can read only what the shop needs. Layers reduce the risk while a flaw is being fixed; they do not replace fixing it.

The customer file walks out the door

Who can stop it: the shop

The data is copied out in bulk, often quietly, then sold or posted on a forum. The shop may only learn about it weeks or months later, from a customer or a journalist rather than from its own alerts.

What the attacker gains
A complete copy of the customer file, now outside the shop's control for good.
How to break the chain
Watch for unusual bulk reads and outbound transfers, keep only the data you genuinely need (no ID scans, no full card details), and store passwords with a slow, salted hash.

One leak is merged with the others

Who can stop it: nobody, once it has happened

The dump is combined with older leaks, matched on email address and name. Fragments from different breaches become one record per person: an address from one, a phone number from another, an ID number from a third.

What the attacker gains
A rich profile that no single breach contained.
How to break the chain
Nothing can un-merge it. What you can do is make each fragment worth less: a unique password and a separate email address for each service mean that a match on one leak reveals less about you.

The profile goes behind a search box

Who can stop it: nobody, once it has happened

The compiled database is put online. Typing a first and last name returns the whole profile, for free or for a fee, to anyone: not only skilled attackers.

What the attacker gains
Anyone can pull a person's profile in seconds.
How to break the chain
Regulators and courts can shut such a site down, but as this article explains, others quickly appear. Removal is not a defence you can rely on.

The personal mailbox falls

Who can stop it: you

The profile contains an email address, and often a password from an older leak. Many people reuse a password, so it opens their personal mailbox. From the inbox the attacker can reset the password of almost every other account and read what was ever sent there, including scans of documents.

What the attacker gains
Control of the mailbox, which is the key to every password reset, plus a trove of documents and correspondence.
How to break the chain
Use a unique password for your email account, turn on two-factor authentication for it, and now and then check its forwarding rules and sign-in history.

A bank account opened in your name

Who can stop it: the bank; you can only spot it early and limit the damage

With a name, date of birth, address, ID number and a scan of an ID card, the attacker applies for a bank account in the victim's name, perhaps abroad, where the victim will not hear about it for months. It can then receive stolen money or back a loan.

What the attacker gains
An account or a credit line in the victim's name, and a paper trail that leads to the victim rather than to the attacker.
How to break the chain
This one is the bank's to stop: it should verify identity beyond a document scan (a liveness check, and confirmation with the issuing authority) before opening an account remotely. Once your ID details are out you cannot take them back, so your part is to spot it early and limit the damage: watch for unexpected letters, credit notices and bank alerts, and report identity theft to the police and your bank at once. From now on, mark any ID copy you send (write its purpose and the date across it); that protects future copies, not ones that have already leaked.

Real attacks are usually shorter

The kill chain above has seven steps because it is built to show every stage. Real attacks of this kind are often simpler: fewer steps, and the same result for the victim.

An attacker who finds a flaw in a shop can go straight from the database to selling or using the customer file. There is no compilation and no search box, because a file that already holds names, addresses, phone numbers and order history is enough for a convincing phishing call or fake delivery message. A password reused from an older leak can open a mailbox in one step, with no shop involved at all.

Fewer steps do not mean less harm. The outcome is the same, and there is less time and fewer places in which anyone can notice and stop it. That is why the first steps, the ones the shop controls, carry so much weight.

Who is responsible for what

In the chain above, the first three steps depend on the shop. That is not only good practice: in Switzerland it is a legal duty for anyone who handles personal data, and it applies to a small local shop as much as to a large company. This is general information, not legal advice.

The company that stores your data is expected, under the revised Federal Act on Data Protection (FADP, in force since 1 September 2023), to:

  • Protect the data. Whoever decides how personal data is used must secure it with technical and organisational measures that fit the risk (art. 8). For a shop that holds customer files, passwords or ID copies, that means keeping software patched, building database queries safely and limiting who and what can reach the database.
  • Collect and keep only what it needs. Data must be proportionate to its purpose and not kept longer than necessary (art. 6). Data a company does not hold cannot leak.
  • Answer for its suppliers. A hosting provider, plugin vendor or agency that handles customer data on the company's behalf does not remove its responsibility: it must make sure they keep the data secure too (art. 9).
  • Report a serious breach. When a breach is likely to create a high risk for the people concerned, the company must notify the Federal Data Protection and Information Commissioner (FDPIC) as soon as possible, and inform the people affected when that is needed to protect them or the FDPIC asks for it (art. 24). If it also serves customers in the EU, the GDPR may apply too, with a 72-hour deadline to notify the authority.
  • Accept that it can become personal. Intentionally failing to meet the minimum data-security requirements can be punished with a fine of up to CHF 250,000 (art. 61). The fine is aimed at the individuals responsible rather than at the company as such (art. 64), so an owner or manager cannot treat it as somebody else's problem.

You, as a customer, have no legal duty to protect a shop's database, but your habits decide how far a leak travels: a unique password and two-factor authentication on your mailbox stop step 6 even after your data is out. The practical steps are listed below, and you also have the right to ask a company what personal data it holds about you (art. 25).

If you own or run a small company that holds customer data, taking that duty seriously usually starts with finding out where you actually stand: which systems hold the data, what could reach it, and what you would do on the day it leaks. That is the work we do for small businesses: reviewing and securing websites, services and networks so that customer data is not exposed in the first place.

What you can do as an individual

You cannot un-leak your data, but you can make it far less useful to criminals.

  1. Check where your email appears using a reputable service such as Have I Been Pwned or Mozilla Monitor. Type the address yourself; never click a "you've been leaked" link in a message.
  2. Stop reusing passwords. A password manager gives every account a unique password, so one breach cannot unlock the rest.
  3. Turn on two-factor authentication, starting with your email account, which can reset everything else.
  4. Watch your bank account for unfamiliar direct debits, and dispute any you did not authorise. An IBAN is meant to be shared, so its exposure alone is not a way into your account; the risk is a debit set up in your name without you knowing. Unauthorised debits can usually be disputed, but only for a limited time, so check your statements regularly.
  5. Distrust messages that "know" you. Leaked data makes phishing calls, texts and emails sound credible. Contact your bank or any agency through its official number or website instead.
  6. Share only what a service really needs. Ask why a shop wants a copy of your ID before you give one, and mark any copy you do send.
  7. Ask what a company holds about you. Under the FADP (art. 25) you can ask a company which personal data it holds about you.
  8. Report misuse. In France, see cybermalveillance.gouv.fr, the CNIL and the police; in Switzerland, the Federal Office for Cybersecurity (NCSC) and your cantonal police.

What businesses should do

Your employees' leaked data is also your company's attack surface. A fraudster who knows an employee's address, phone number and role can run a far more convincing CEO fraud, fake-supplier scam or password-reset attack. The same data lets them aim a fake job application at exactly the right person: a CV or portfolio sent straight to a manager or executive, carrying a link or attachment that delivers malware, or an approach from a fake recruiter meant to win trust or extract information. It works because the message arrives addressed to the right person, on a subject that person expects to receive.

  • Know your exposure. Monitor which company email addresses appear in known breaches, using verified domain monitoring or a threat intelligence provider working within a legal framework.
  • Train people on targeted phishing. Show staff what a message built from leaked personal data looks like, using fictional or anonymised examples.
  • Handle unsolicited applications with care. Open CVs and attachments from unknown candidates in a safe viewer rather than on a machine with access to company systems, route applications addressed to executives through HR, and verify a recruiter through the company's official channels before sharing anything.
  • Harden verification. Require call-back or second-channel checks for any change to a supplier's or employee's bank details, any unusual payment request and any password reset.
  • Enforce strong authentication and a password manager across the company.
  • Detect data leaving. Deploy data loss prevention (DLP) and monitoring that flag unusual bulk reads, large transfers and unfamiliar destinations, so a leak is caught in hours rather than discovered months later by a customer or a journalist.
  • Filter outbound traffic. Stolen data has to leave your network to be of any use. A secure web gateway, such as our own EnforceGate vX, inspects and filters outbound web traffic, including encrypted traffic, so that transfers to unknown or malicious destinations can be blocked and flagged.
  • Have a response plan for when an employee or customer discovers they are exposed: who to call, what to lock down, how to report.

The takeaway

Data breaches are no longer isolated events. Leaks accumulate, get combined, and resurface years later in forms far more dangerous than the original. The best defence is to assume your data is already out there, and make sure it cannot be turned against you.

Need help securing your website, services and network, or preparing your team?

Sources