French Hospital Fined €500,000 Over Data Breach Affecting 700K+ People
September 8, 2026Read also: Honeywell Aerospace fined for cybersecurity violations; an Australian telco penalized for failure to protect customers from fraud; and more.

A French hospital fined €500,000 after a data breach exposed over 700K people
France’s data protection authority CNIL has fined Hôpital privé de la Loire (HPL) €500,000 for failing to properly protect the personal data of patients and their relatives.
The fine comes after a data breach in summer 2025 exposed sensitive information belonging to 524,867 patients and 202,246 trusted third parties. An attacker reportedly gained access through a doctor’s account and was able to access the hospital’s wider patient record system.
CNIL found several security problems, including a lack of multi-factor authentication for some external users, weak access controls and insufficient monitoring. Weak security allowed the attacker to access and extract a large amount of data over several days without being detected.
The authority also found that HPL did not directly notify the 202,246 affected trusted third parties, although the hospital did inform patients. A teenage hacker using the alias “Marak” claimed responsibility for the attack and reportedly tried to sell the stolen data for between €2,000 and €5,000.
HPL strengthened its security measures during CNIL’s investigation. The violations concerned Articles 32 and 34 of the EU’s General Data Protection Regulation (GDPR).
Honeywell Aerospace to pay $2.04M for failure to meet cybersecurity requirements
Honeywell Aerospace Inc. has agreed to pay $2.04 million (~€1.76 million) to settle allegations that it failed to meet cybersecurity requirements in a US Department of Defense contract, the US Department of Justice announced.
Honeywell Aerospace, based in Phoenix, Arizona, provides aerospace products and services to government and commercial customers.
The allegations involve a Honeywell business unit that, between April 2020 and December 2023, failed to comply with cybersecurity standards set out in the National Institute of Standards and Technology’s NIST SP 800-171. The requirements applied to one of Honeywell’s networks.
The settlement resolves claims brought under the False Claims Act, which allows whistleblowers to sue on behalf of the government. A former Honeywell employee who filed the lawsuit will receive $375,823 (€323,700) from the settlement.
Australia’s largest telco fined A$277,000 for failure to protect customers from scams
Australia’s biggest telecommunications provider Telstra has been fined A$277,000 (~€171,700) for failing to properly protect customers from scams.
The Australian Communications and Media Authority (ACMA) found Telstra failed to complete required identity checks in 15 unauthorized SIM card swaps. A SIM swap allows a customer to replace an existing SIM card or eSIM, but scammers can use the process to gain access to a victim’s phone number and accounts.
The investigation also found 13 cases where Telstra staff failed to apply additional fraud protections to customers who had raised concerns or were identified as being at risk.
In addition to the fine, Telstra has agreed to court-enforceable undertakings to strengthen its fraud prevention procedures and improve staff training.
The investigation followed previous ACMA enforcement action against Telstra for similar breaches. It is the seventh action under the regulator’s crackdown on mobile number fraud, with telecommunications companies paying more than $5 million in penalties so far.
HSE fined €645,000 after medical records found in bad conditions
The Health Service Executive (HSE), which provides all of Ireland's public health services in hospitals and communities across the country, has been fined €645,000 after medical records were found in poor conditions at two former psychiatric hospitals.
Ireland’s Data Protection Commission (DPC) launched an investigation after people gained unauthorized access to paper records at St. Loman’s Hospital in Mullingar and St. Conal’s Hospital in Letterkenny.
During inspections, the DPC found records damaged by mold and water, covered in rubble and animal droppings, or badly affected by the inadequate storage conditions. Some records were kept in disused bathrooms, rooms without heating or lighting, and even a shipping container.
The DPC carried out 12 inspections across the country and found that the issues were not isolated incidents. It said the HSE had failed to properly protect personal data stored in paper records.
The HSE has accepted the findings and said work is ongoing to fix the problems. The DPC has also ordered the HSE to carry out a full audit of its storage facilities.
A Romanian cosmetics maker fined €5,000 after a cyber-attack
Major Romanian cosmetics manufacturer Gerocossen SRL has been fined €5,000 after a cyber-attack exposed customers’ personal data. Romania’s National Supervisory Authority for Personal Data Processing (ANSPDCP) found that Gerocossen had violated Article 32(1)(b) and Article 32(2) of the EU General Data Protection Regulation (GDPR).
The company was fined 26,236.50 lei, equivalent to €5,000. The investigation began after Gerocossen notified the authority of a personal data breach, as required under Article 33 of the GDPR.
According to ANSPDCP, the cyber-attack targeted the company’s IT infrastructure and resulted in unauthorized access to or disclosure of personal data, including identification and contact details.
The authority found that Gerocossen had failed to put in place adequate security safeguards, including measures to protect the confidentiality and integrity of its data processing systems, in breach of Article 32(1)(b) and Article 32(2).
In addition to the fine, ANSPDCP ordered the company, under Article 58(2)(d) of the GDPR, to implement systems for monitoring and logging access to its IT infrastructure. Access logs must be kept for at least 30 days and backed up.
In a separate case, the Romanian regulator has imposed a 15,728 lei (approx. €3,000) GDPR fine on automobile dealer Poliserv JG (PJG) SRL following a phishing attack that compromised credentials for an administrator-level account. The attackers used the stolen credentials to access customers’ personal data, including at least their names and surnames.
What’s next:
- Request a free product demo or pricing
- Register for our webinars and product trainings
- Read our Cybercrime Investigations weekly blog
- Follow us on LinkedIn, X, Telegram and WhatsApp
- Subscribe to our Newsletter
- Join our Partner Program