The MGEL Group, an insurance company established in 1949 that provides health, housing, and reimbursement services to individuals between the ages of 18 and 35, is reportedly involved in a major data breach. According to the FrenchBreaches platform, an individual known as RedStone claims to have put up for sale 16 databases, 387 tables, and over 38.8 million lines of data. This includes 603,845 unique email addresses, 685,676 phone numbers, and more than 1.1 million combinations of first and last names. Among the most sensitive data are 450,806 unique IBANs (International Bank Account Numbers), which could be used to attempt fraudulent transfers or highly targeted phishing attacks.
The data allegedly exposed includes names, postal addresses, dates of birth, school information, banking details, account numbers, billing data, and login credentials. Some of the tables reportedly contain passwords stored in plain text or as SHA-256 hashes, a common encryption method. However, none of these claims have been officially confirmed. MGEL has not commented on the situation, and the samples examined so far do not allow for the exact verification of the 450,806 IBANs. Therefore, this is currently a one-sided claim and should be treated with caution until MGEL provides an official statement.
If confirmed, the MGEL breach would not be the first of its kind in the mutual insurance sector. Previously, Almerys, a third-party payer provider, had 15.5 million accounts compromised, and Solimut, a mutual insurance company, experienced a breach affecting nearly 1.25 million insured individuals. Additionally, the Ficoba national file, which records the bank accounts of French citizens, suffered a leak that exposed the identity, address, and IBAN of 1.2 million accounts. These organizations hold three types of highly valuable data: health data, financial data, and identity-related information, often stored in outdated systems.
On the black market, an IBAN tied to a person’s identity is particularly valuable because it can be used directly to carry out credible scams. If you are an MGEL member, it is important to remain vigilant. Be cautious of calls or emails asking for a RIB (a French bank account identifier) or payment details, monitor your bank statements, and change your password if you use it on other services. If you have been affected by a data breach, some good practices include changing passwords immediately, using unique and strong passwords, enabling two-factor authentication (2FA) and Passkeys where possible, and being cautious of suspicious messages. Update your devices and software to address security vulnerabilities, and report any fraudulent activity through the Perceval platform.
Data Breach Alleged Against French Insurance Company MGEL Group
AI-rewritten from original reportingHow it works
data-breachmgel-groupibansfraudinsurancesecurity



