What is confirmed
On 19 September, AFPA confirmed to AFP a claimed attack involving a third-party accommodation management tool outside its main systems.
Up to 1.7 million people may be affected according to preliminary reports; the actual number and extracted fields remain under investigation.
What it means
Names and contact details could enable convincing training or accommodation messages, but such misuse has not been established in this incident.
Public reporting said the application apparently did not contain bank details or social security numbers; this depends on the scope under review.
What to do
Follow official AFPA notices and verify any request using its public contact details rather than replying to an incoming message.
Do not share identity papers or banking details with someone invoking this incident to pressure you.
Use the related SecurCheck tool, then confirm important decisions with an official source.

