A hacker has claimed to have stolen 143,518 lines of data from the Agency for Payment and Services (ASP), which manages financial aid programs in Île-de-France. The data includes personal information such as names, postal addresses, IBANs (International Bank Account Numbers), and details of aid payments made under the "Coup de pouce énergie" program, which provides financial assistance to low-income households. The ASP confirmed the breach in a letter sent to affected individuals, and the incident follows a previous security breach less than a month earlier, when an intruder accessed a user account and extracted payment notices from 2023 and 2024. The agency detected this intrusion the next day and informed the CNIL, France’s data protection authority, as well as the victims, of the risks of phishing and fraudulent requests. The hacker shared details of the stolen data on a cybercriminal forum under the title "[FR] asp public," claiming to have exploited a specific vulnerability known as IDOR, or Insecure Direct Object Reference. This type of security flaw allows attackers to manipulate the reference numbers in a request to access documents they should not have access to. By changing these numbers incrementally, a hacker can retrieve thousands of documents. This same IDOR vulnerability was previously used to breach the ANTS, a national agency, leading to the exposure of nearly 19 million people’s personal data. The ASP acknowledged the unauthorized access to a user account and stated that it had identified and fixed a vulnerability, though it did not specify the exact nature of the flaw. At the time of writing, only the hacker has publicly mentioned the IDOR vulnerability. The "Coup de pouce énergie" program, which was active between July and October 2023, provided a 250 euro aid to 160,000 low-income households in Île-de-France through a 45 million euro European funding envelope. Each payment notice contains detailed personal and banking information of the recipient, including their name, address, IBAN, and the amount of aid received. The risk of fraud is significant. After a similar breach at a sports store called Basic-Fit, it was explained that having a person's name, address, and IBAN could allow a fraudster to create a SEPA direct debit mandate in their name, enabling unauthorized withdrawals from their bank account. Fraudsters might also call the victim, pretending to be an ASP agent, and ask for a bank verification code, citing the exact aid amount. Victims are advised to ignore any calls, SMS, or emails related to the "Coup de pouce énergie" or their banking details. Additionally, they can dispute any unauthorized withdrawals with their bank within 13 months. In 2025, the CNIL received 6,167 reports of data breaches, a 9.5% increase from the previous year, with half of these incidents resulting from computer hacking. The head of the CNIL warned in her annual report that data breaches are becoming more severe and widespread. The ASP had previously experienced a data leak in April 2025, when an intruder stole social security numbers and IBANs of vocational training participants, though the agency has not disclosed how many people were affected.