0 offers · 0 programmes
Security · News · Company search

Apprentice personal data: how to react to 2026 cyberattacks

In 2026, two major cyberattacks hit alternance candidates: the hacking of Parcoursup in Occitanie (705,000 candidates exposed, discovered in March 2026) and the Génération #HDF card data breach in Hauts-de-France at the end of June 2026. If you are an apprentice or are looking for a contract, your personal data already circulates on several platforms — it is better to know what to do.

In short: in 2026, at least 705,000 Parcoursup candidates and several thousand young holders of the Génération #HDF card have seen their personal data hacked. Apprentices are a prime target because their data (scholarship status, contract, alternance) is sold for targeted scams (fake recruiters, fake aid, phishing). Three reflexes: check whether your email is in a breach on haveibeenpwned.com, enable two-factor authentication everywhere, and never send documents or bank details before the official signing of an alternance contract.

What happened in 2026?

Two incidents have marked the year, and they directly concern alternance candidates.

The Parcoursup hack (April 2026)

  • Volume: approximately 705,000 candidates exposed.
  • Sessions affected: Parcoursup 2023 and 2025.
  • Geographic target: candidates who submitted wishes in Occitanie.
  • Date of intrusion: October 2025.
  • Date of discovery: March 2026 — i.e. 5 to 6 months later.
  • Vector: impersonation of a user account of a staff member of the academic region (no technical flaw in the platform itself).
  • Official notification: 23 April 2026 by the French Ministry of Higher Education and Research.

"The credentials of an agent of the Occitanie academic region were used to extract data between October 2025 and March 2026." — French Ministry of Higher Education press release, April 2026

The Génération #HDF leak (June 2026)

  • Revelation: 28 June 2026.
  • Source: Génération #HDF card, a scheme by the Hauts-de-France region for high-school and apprentice students.
  • Exposed data: surname, first name, date of birth, address, phone, email, school, scholarship status, contactless card ID.
  • Status: unconfirmed claim at this stage, to be confirmed with the Hauts-de-France region.

Which apprentice data is most at risk?

All the information you have submitted for your searches (Parcoursup, CFA, France Travail, regions, OPCO) can leak. The most exploited by scammers are:

DataRisk if leaked
Scholarship statusTargeted phishing on aid, fake promises of bonuses
Academic email addressImpersonation to contact schools or fake recruiters
Phone numberSmishing (fraudulent SMS) and callback attempts
Date of birth + addressBank or administrative identity theft
Online CVDiversion to fictitious alternance offers
ÉduConnect credentialsAccess to other public services

⚠️ A single piece of data is rarely dangerous. It is their cross-referencing that makes attacks credible: a scammer who knows your name, your school and your scholarship status can write a very convincing email.

What should you do concretely?

Step 1 — Check whether your data has leaked

Two free, trusted tools are enough for an initial diagnosis:

  1. haveibeenpwned.com: enter your main email address. If it appears, immediately change the passwords of the accounts that use it.
  2. cybermalveillance.gouv.fr: personalised diagnosis and connection with a local provider if you are a victim.

Step 2 — Enable two-factor authentication (2FA)

Two-factor authentication is today the best protection against account takeover, even if your password leaks. Enable it as a priority on:

  • Your main email (Gmail, Outlook, iCloud) — it is the cornerstone of all your accounts.
  • France Travail, Ameli, CAF, impots.gouv.fr and other public services.
  • ÉduConnect and any portal of your CFA or university.
  • Your online bank (often enabled by default).

Close-up on a keyboard with keys forming the word PASSWORD, symbolising vigilance on passwords

Step 3 — Adopt the right password habits

  • A unique password for every important account: email, bank, school, Apprentice space.
  • At least 14 characters mixing upper case, numbers and symbols — or better, a passphrase that is easy to remember ("MyCFA-isIn-Lyon-since-2024!").
  • A (free) password manager: Bitwarden or KeePass. It remembers your passwords and alerts you if one of them appears in a known leak.
  • Never reuse your main email password anywhere else.

Step 4 — Recognise a targeted scam

Alternance-related scams have become more professional in 2026. The most frequent warning signs:

"A so-called recruitment agency contacts you on WhatsApp about a very attractive alternance offer, asks for your ID documents and bank details before any interview, and insists that you sign an online 'confidentiality agreement'."

The 5 signals that should alert you:

  1. You are contacted before any application through an unusual channel (WhatsApp, Telegram, SMS).
  2. You are asked for a payment, "application fees" or a security deposit.
  3. You are pressured to send bank details, ID card or driving licence before the interview.
  4. The contact email is @gmail.com, @outlook.com while the company has an official site.
  5. The offer is too good to be true: salary 30% above the market, full remote work, immediate hire.

To recognise them and report them, see our full article on fake recruiter scams in alternance.

Your remedies if you are a victim

If, despite these precautions, you notice fraudulent use of your data, here is the procedure to follow:

StepActionWhere / how
1Keep the evidenceEmails, SMS, screenshots, disputed bank statements
2Report the scamsignal-arnaques.com and phishing@signal-spam.fr
3File a complaintPolice station, gendarmerie, or online via the THESEE platform
4Inform your bankBlock the disputed transactions within 24 hours
5Notify the CNILVia the "Notify a data breach" form on cnil.fr
6Inform your CFA and France TravailTo secure your application file

The applicable texts are article 226-4-1 of the French Penal Code (identity theft), article 313-1 (fraud) and article 323-1 (fraudulent access to a data system). The 2026 Parcoursup incidents have already led to a complaint by the Public Prosecutor of Paris and a notification to the CNIL.

Personal data and alternance: what the law says

In France, the data used for alternance is protected by three main texts:

  • GDPR (European Regulation 2016/679): right of access, rectification and erasure of your data.
  • Informatique et Libertés Act (Law no. 78-17): French adaptation of the GDPR, overseen by the CNIL.
  • Code de l'éducation (art. L. 331-3 et seq.): specific protection of school and training data.

Concretely, you can at any time ask your CFA, France Travail or an OPCO for the list of data they hold on you, and demand its deletion if it is no longer needed.

What if you are applying for an alternance right now?

Searching for an alternance mechanically exposes your data to several players. To limit the attack surface:

Key takeaways

  • Two massive breaches have hit alternance candidates in 2026: Parcoursup (705,000 candidates in Occitanie) and Génération #HDF (June 2026).
  • Apprentices are a prime target: their scholarship status, contract and card number are sold for targeted scams.
  • Three immediate reflexes: check your emails on haveibeenpwned.com, enable two-factor authentication everywhere, and strengthen your passwords with a manager.
  • Report and file a complaint in case of identity theft: THESEE, signal-arnaques.com, police station, CNIL.
  • Never send your official documents or your bank details before the effective signing of your alternance contract.

Sources: French Ministry of Higher Education and Research (enseignementsup-recherche.gouv.fr), CNIL, cybermalveillance.gouv.fr, France 3 Régions, Le Parisien Étudiant, Centre Inffo, ANSSI.

Frequently asked questions

Has my apprentice data been hacked in 2026?

If you applied via Parcoursup in Occitanie for the 2023 or 2025 sessions, your data (identity, contact details, scholarship status) is potentially in the breach revealed in April 2026. The Hauts-de-France region also confirmed a leak involving its Génération #HDF card at the end of June 2026. If in doubt, monitor your emails and enable two-factor authentication on all your accounts.

What should I do if I receive a suspicious email that mentions my real name and status?

Do not click any link, do not reply, do not call the number shown. Forward the message to signal-arnaques.com and to phishing@signal-spam.fr. If an alternance offer is proposed and you are asked for a payment, ID documents or bank details, it is a scam: real employers never ask for this kind of information before signing the contract.

How can I know if my email address is in a data breach?

Use the haveibeenpwned.com website (free, trusted service) which lists known breached databases. Enter your main email address: if it appears, immediately change the passwords of the accounts that use it and enable two-factor authentication.

Are apprentices more targeted than other students?

Yes, for two reasons: apprentices can be reached through their CFA, their company and France Travail, which multiplies attack channels; and their data includes a scholarship status or employment contract, which is heavily used in targeted scams. Regions managing youth cards (Génération card, student vocational card) are also regular targets.

What can the CNIL do if my data is leaked?

The CNIL has been notified of the 2026 incidents and can carry out checks and impose sanctions. For your part, you can file a complaint for identity theft (article 226-4-1 of the French Penal Code) via the THESEE platform or at a police station, keeping all evidence (emails, SMS, bank statements).

← Back to the blog