The National Agency for Adult Training (Afpa), a French organization that provides training and support for adults in the workforce, has been hit by a cyberattack that could affect up to 1.7 million people. The breach was revealed on Saturday, September 19, just days after the agency announced plans to restructure its operations. According to Pierre Prady, Afpa’s deputy director, two hackers claimed to have accessed personal data from the agency on Wednesday and Thursday. The data reportedly came from a tool used to manage accommodations, which is hosted by a third-party provider and not directly connected to Afpa’s main information systems. Initial investigations suggest that the breach may have occurred due to a vulnerability in the external tool used for managing accommodations. Because this tool is separate from Afpa’s internal systems, there was no disruption to its services or data security. The agency is now working to determine the full extent of the data breach and identify the individuals affected. Afpa stated that the compromised data does not include highly sensitive information such as bank details or social security numbers. Instead, the hackers may have accessed personal information like names, addresses, and possibly phone numbers. Afpa has not yet informed the affected individuals, as it continues to assess the situation. The agency emphasized that the breach does not pose an immediate threat to users’ financial security, but it remains cautious about the potential risks. Afpa is cooperating with cybersecurity experts to investigate the incident further and to ensure that similar vulnerabilities are addressed in the future. The attack has raised concerns about the security of third-party tools used by public institutions, highlighting the need for stronger oversight and protection of personal data. In response to the breach, Afpa has pledged to keep the public informed as more details emerge. The agency is also reviewing its data management practices and the tools it uses to safeguard personal information. While no major services have been impacted, the incident serves as a reminder of the growing threat of cyberattacks and the importance of maintaining robust digital security measures, especially for organizations handling large amounts of personal data.