What is confirmed
Cnam says malicious activity affecting some of its information systems led to a data breach on October 2, 2026. A crisis response team was mobilised.
For students enrolled within the previous ten years, the institution lists names, dates and places of birth. Teachers listed in the Adage platform since 2017 may also have had contact and professional information exposed.
What it means
The publication identifies potentially affected data categories, not necessarily the records of every individual. The exact scope depends on the investigation and individual notifications.
Combining identity details and contact data may enable personalised phishing even without leaked passwords.
What this incident reveals
The publication identifies potentially affected data categories, not necessarily the records of every individual. The exact scope depends on the investigation and individual notifications.
Practical steps to take
Watch for messages claiming to be from Cnam; open its official website rather than unexpected email links.
If uncertain, verify the sender and never provide login codes or identity documents in response to unsolicited requests.
What to do
Watch for messages claiming to be from Cnam; open its official website rather than unexpected email links.
If uncertain, verify the sender and never provide login codes or identity documents in response to unsolicited requests.
Retain official notices and report impersonation attempts.
Use the related SecurCheck tool, then confirm important decisions with an official source.