Security Incident

Last updated on 12/08/2026

A security incident involving personal data related to the Digital Vaccination Record was brought to our attention on June 15, 2026. Ongoing investigations indicate that an unauthorized third party accessed certain personal data processed by the platform and obtained a copy of it. Here is the information currently available to us.

Frequently Asked Questions

What data may have been affected?

At this stage of the investigation, the categories of data that may have been affected are as follows:

  • identification and contact information (email address and phone number). Passwords, which are stored in encrypted form, were not affected by this incident. As a general precaution, you may nevertheless change your password;
  • civil status information, residential address, and Social Security number, where provided;
  • vaccination data and health profile information, where provided. This data is stored in coded form. At this stage of the investigation, we have not identified any direct exposure of medical information in plain text;
  • no banking information was affected by this incident.

Who is affected?

We are unable to identify with certainty which individuals are affected. As a precautionary measure, we consider that all holders of a Digital Vaccination Record may potentially be affected by this incident.

What should I do?

We recommend that you remain particularly vigilant regarding unusual emails, text messages, or phone calls asking you to provide personal, medical, or financial information.

If in doubt, do not disclose any sensitive information and always verify the identity of the person contacting you.

As a general precaution, you may also change your password.

Has the incident been reported to the CNIL?

Yes. In accordance with our regulatory obligations, the CNIL (French Data Protection Authority) was notified of this incident on June 15, 2026.

Has a complaint been filed?

Yes. A complaint has been filed with the relevant authorities.

Do I need to file an individual complaint?

There is no need to take individual action unless you have suffered direct harm or become aware of an attempt to fraudulently use your data.

Are the services still available?

Yes. Colibri, the Digital Vaccination Record, and the Professional Digital Vaccination Record remain accessible and can be used as normal.

The security measures implemented following the incident have not resulted in any service interruption for users.

What are the risks associated with the incident?

Unauthorized access to personal data may, in some cases, lead to attempts by third parties to misuse that data. In particular, we recommend that you remain vigilant regarding the following:

  • phishing attempts by email, text message, or phone;
  • unsolicited marketing communications;
  • in rarer cases, attempted identity theft.

How can I limit the risks?

Be vigilant when receiving unusual messages, particularly those asking you to provide personal, medical, or banking information, or copies of identity documents.

Do not click on suspicious links or disclose sensitive information in response to an unsolicited message or phone call. If in doubt, contact the organization concerned directly using its official contact details.

For any questions or assistance, you can also consult the official platform cybermalveillance.gouv.fr

What are you doing specifically to protect us?

As soon as we became aware of this incident, we immediately implemented measures to contain it, secure our systems, and prevent any further unauthorized access.

The main actions taken are as follows:

  • Comprehensive independent audit of the infrastructure by Orange Cyberdefence.
  • Verification of the integrity of the environments.
  • Complete rebuild of the production environment.
  • Migration of development tools to a new managed software development platform operated by a specialized provider, meeting enhanced security and resilience requirements.
  • Redesign of deployment processes to better isolate development and production environments and strengthen infrastructure protection.
  • Application images signed using two independent hardware keys before any deployment to production.
  • Applications and internal services accessible exclusively through a secure virtual private network (VPN).
  • Enhanced logging, monitoring, and investigation capabilities.

The principles governing the protection of personal data are described in our legal notice and our privacy policy.