Unverified Data Source
CriticalReportedHealthcare
In January 2021, Unverified Data Source suffered a data breach. 11 million accounts were affected. The exposed data includes banking data, dates of birth, email addresses, employment data, health data, connection data, names, phone numbers, postal addresses and social security numbers. Have I Been Pwned flags this breach as unverified: its origin could not be confirmed.
- Disclosed on
- March 24, 2021
- Incident dated
- January 26, 2021
- Accounts affected
- 11M
- Sector
- Healthcare
- Country
- International or undetermined
- Cause
- Undisclosed
Exposed data
- Banking data (IBAN, card)
- Date of birth
- Email address
- Employment data
- Health data
- Connection data (IP, logs)
- Full name
- Phone number
- Postal address
- Social security number
You are only affected if you had an account or an order with this organisation.
What you can do
- Expect phishing attempts quoting your name and this company. A message that knows your details is not legitimate for that reason.
- Watch your statements. On any unknown debit, block the card and request a refund — French law (art. L133-18) entitles you to it.
- These documents enable identity theft, and cannot be reissued at will. Keep the notification letter: it proves where the leak came from if an account is opened in your name.
- Health data is “special category” data under the GDPR: a leak opens a right to compensation, and the organisation must notify the DPA within 72 hours.
- You can ask the organisation exactly what was exposed about you (right of access), and complain to the DPA if no answer comes within a month.
Sources
Entry built from Have I Been Pwned’s structured data, with no model rewriting. Spotted an error, or have a correction? Write to us and the entry will be fixed. Contact