[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f17wp4sxjl1uit":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":30,"seoTitle":31,"seoTitleEn":32,"seoDescription":31,"seoDescriptionEn":33,"logoUrl":34,"isVerified":4,"isSensitive":35,"isSpamList":35,"isMalware":35,"company":36},"68e3266eda11adda48825264","la-poste-mobile","La Poste Mobile 2022 Data Breach","lapostemobile.fr","2022-07-04T00:00:00.000Z","2022-07-14T00:29:21.000Z","2026-07-29T23:40:31.918Z","verified breach index and security reporting","https:\u002F\u002Ftherecord.media\u002Ffrench-telecom-company-la-poste-mobile-struggling-to-recover-from-ransomware-attack",[14,16],"https:\u002F\u002Fwww.lapostemobile.fr\u002F",533886,"known",null,"email_identifiers","High",[23,24,25,26,27,28,29],"Bank account numbers","Dates of birth","Email addresses","Genders","Names","Phone numbers","Physical addresses","\u003Cp>\u003Cstrong>The La Poste Mobile 2022 data breach\u003C\u002Fstrong> concerns the ransomware incident the company said began on July 4 and a subsequently verified corpus of 533,886 unique email addresses. The verified external record lists seven classes: bank account numbers, dates of birth, email addresses, genders, names, phone numbers, and physical addresses. The local index does not contain all seven classes; it holds only 532,179 unique email associations.\u003C\u002Fp>\n\n\u003Ch2>What does the company statement establish?\u003C\u002Fh2>\n\u003Cp>Contemporaneous security reporting quotes La Poste Mobile as saying that the ransomware incident began on July 4 and that it suspended the affected computer systems after learning of it. That measure temporarily closed the website and customer area. The company said the servers essential to mobile-line operation were protected and phone service was unaffected, while some files on employee computers might have been affected and might contain personal data.\u003C\u002Fp>\n\n\u003Cp>The verified external breach record attributes the event to LockBit ransomware, says company data was published publicly, and records that the site remained offline ten days after the attack. The elements directly confirmed in the company statement are separated from the actor and publication attribution in the external record. The sources do not establish the initial access method, the extent of encryption, or that every customer's file was accessed.\u003C\u002Fp>\n\n\u003Ch2>How should the count and data types be read?\u003C\u002Fh2>\n\u003Cp>The external value of 533,886 measures unique email addresses, not customers, mobile lines, or unique people. Listing seven classes also does not mean that every field occurred alongside every email. In particular, an email match does not by itself establish that the same person's bank account, address, phone number, and birth date were all present.\u003C\u002Fp>\n\n\u003Cp>Payment cards, passwords, government identifiers, call contents, and message contents are not listed. A bank account number does not by itself permit a withdrawal, but it can make a false payment or customer-support message more convincing when combined with name, address, or phone context. The entry does not add card or password claims absent from the sources.\u003C\u002Fp>\n\n\u003Ch2>What is actually held in the local index?\u003C\u002Fh2>\n\u003Cp>The completed local job processed \u003Ccode>la-poste-mobile-emails.txt\u003C\u002Fcode>, a normalized union of three explicit email fields in the source file. Bank, name, address, phone, birth-date, and gender fields were excluded from the import. The job accepted 532,199 valid email lines; after case normalization and deduplication, 532,179 unique email associations remain in production.\u003C\u002Fp>\n\n\u003Cp>The valid-line count is 20 above the local index, while the external unique-email measure is 1,707 above it. Because there is no auditable version-to-version reconciliation, the figures are not added together or interpreted as missing people. A local search result establishes only an email association and does not imply that the other six classes are locally searchable.\u003C\u002Fp>\n\n\u003Ch2>What does this mean for users?\u003C\u002Fh2>\n\u003Cp>People who know they used the service should verify unexpected payment, account-update, or identity-check requests claiming to come from La Poste Mobile or a bank through a known channel opened directly from the active lapostemobile.fr domain, not through a link in the message. Because the sources do not report exposed passwords, this entry does not assume that a general password change is required. If an unusual bank transaction appears, contact details should come from the bank's official channel rather than the incoming message.\u003C\u002Fp>","","La Poste Mobile 2022 Data Breach (533.9 Thousand Email Identifiers)","The La Poste Mobile 2022 breach contains 533,886 verified unique emails and seven data classes; the local index holds only 532,179 emails.","\u002Fuploads\u002Flogo\u002Flapostemobile_fr.webp",false,{"name":37,"sector":38,"country":39,"website":9,"websiteArchiveUrl":31,"websiteStatus":40,"websiteCheckedAt":41},"La Poste Mobile","Telecommunications","France","active","2026-07-29T23:31:48.000Z"]