Hack of a La Poste mail service in France exposes addresses of 22 million people
An attacker got into Maileva, the online mailing service of French postal group La Poste, and reached a database with the names and postal addresses of about 22 million people. The figure comes from a data breach notice that Docaposte, the La Poste subsidiary that runs Maileva, drew up on October 5 and that the French breach tracker FrenchBreaches reported on October 9. Most of those people never used Maileva themselves: they simply received a letter that a company or public body sent through it.
From "fake letters" to a data breach
Businesses use Maileva to send letters, registered mail, payslips and invoices from a computer, and the platform prints and posts them. On September 23 at 7 a.m. it shut down for all customers. At the time Maileva told clients it had seen "unauthorized access attempts by a cybercriminal" aiming to send letters illegitimately, had blocked the accounts involved and filed a police complaint. Service came back on September 29, and Docaposte called it "a cybersecurity incident".
The October 5 notice, written by Docaposte's data protection officer, goes further. According to FrenchBreaches, it says an external attacker exploited a flaw in an application and gained unauthorized access to Maileva's production systems. The timeline it gives:
- September 9: first suspicious activity;
- September 16 and 17: the intrusion is detected;
- September 23: the service is shut down and France's data protection authority, the CNIL, is notified the same evening;
- September 28: a gradual restart begins.
What was exposed
The database the attacker could reach tracks 39 million letters. After removing people who received several, Maileva estimates 22 million individuals, with records going back up to ten years depending on the client. For them the notice lists gender, first and last name and postal address.
For business customers there is more: names, logins and email addresses of platform users, and the names of uploaded files, which can hint at what a letter was about even without its content. A second part of the incident hit OpenCell, the billing tool, which held invoice amounts, billing contacts and client companies' IBANs. The bank details belong to Maileva's business customers, not to the 22 million recipients.
Several things are still unknown. The notice does not confirm that letter contents or attachments were viewed or copied, and it does not say how much data actually left the system. No data was altered or deleted, and investigations were ongoing as of October 5.
What to watch for
Names and home addresses are exactly what is needed for convincing paper scams: a letter that looks like it came from a bank, an insurer or a public office. Business customers face the classic invoice fraud, where a "supplier" announces new bank details. In late September data on 1.43 million members of the French Hiking Federation went up for sale, and such files are often combined.
- Treat any letter asking for a payment, a card number or a call to an unfamiliar number with suspicion, even if it carries a familiar logo.
- Before paying an invoice with changed bank details, call the supplier on a number you already have, not the one printed on the letter.
- If your company uses Maileva, change the account passwords, turn on two-factor login where it is offered and warn whoever handles accounts payable.
There is no way to check whether you are in the database: Maileva has not published a lookup, and a suspicious letter does not prove your data came from this breach.
• Cyberattaque : les données de 22 millions de personnes exposées chez un service du groupe La Poste - FrenchBreaches
• Cyberattaque Maileva : six jours de coupure après une tentative de détournement de la plateforme - Solutions Numériques
• Maileva : cyberattaque contre sa plateforme d'envoi de courriers - Fuites Infos
• Maileva, filiale de La Poste victime d'une cyberattaque - Cyberattaque.org