-
A seller says a second file tied to French health tech firm Alaxione holds about 8.6 million patient records.
-
The claim lists 168 healthcare centres, 29,647 practitioners, and more than 311,000 French Social Security numbers.
-
No authority has confirmed the figures, and Alaxione says the August attack hit a test server.
A new data leak claim has raised fresh worries about the personal information of French patients. A report from September 28, 2026, says a second Alaxione file is now up for sale. Alaxione is a French healthcare technology company.
The seller says the file holds information on about 8.6 million patients. No French authority has backed up that number yet. Every figure below is a claim, not a confirmed fact.
Seller Lists Second Alaxione File for Sale
According to the information circulating, the file covers 168 healthcare centres and 29,647 practitioners. Some records reportedly go back as far as 2010. That was 16 years before the report came out. A healthcare centre is a place where patients get care. Practitioners are the doctors and other health workers. The claim points to many of both, not just one clinic.
The listing also mentions more than 311,000 French Social Security numbers. That equals about 3.6 percent of the 8.6 million records claimed. The listing adds personal details in two groups. Names and dates of birth identify each person. Addresses, email addresses, and telephone numbers show how to reach them.
France Passoire tracks reported data breaches. Its September 28 update separately points to a second Alaxione patient file with 8.6 million records. The site does not treat the August incident as a confirmed breach either. It also keeps a health data page that covers this kind of breach.
Readers should not take these numbers as final counts. The reporting does not show that all 8.6 million records belong to different patients. It also does not prove the Social Security numbers came straight from Alaxione’s live systems. The 8.6 million total, the 311,000 Social Security numbers, and the centre and practitioner counts all remain unverified.
Alaxione Disputed Size of the August Attack
The new listing follows a cyberattack that became public in August. At that time, a cybercriminal claimed to have stolen about 6.8 million patient profiles. The same claim also covered more than 10 million medical appointment records. That earlier claim involved a separate dataset from the 8.6 million file.
Two claims now sit side by side. The August one spoke of 6.8 million profiles. The new one speaks of 8.6 million records. Neither figure has official confirmation.
Alaxione confirmed that an intrusion had happened. However, the company challenged how big the breach really was. It said the attacker had reached a test or development server. According to Alaxione, that server did not hold genuine patient records. A test or development server is a computer used to try out software. Alaxione’s point is that real patient files were not there. Hashtag Avocats reported this response.
The same legal analysis asked whether patients’ medical data had really leaked. It was written after the August incident and added another point. Nobody had independently established how far the compromise went at that stage. France Passoire still lists the August case as a claimed but unconfirmed breach involving 6.8 million people. Further coverage of that attack is available on the Fortixpass blog.
This history matters for the new claim. Alaxione has admitted an intrusion, yet it disputes the attacker’s description of what was reached. The CNIL, France’s data-protection authority, has not confirmed the latest claim. No other government agency has confirmed it either.
CNIL Warns Stolen Personal Details Can Fuel Fraud
If the new claims prove true, the exposure could be serious. The details described include identifiers that criminals can use for phishing and identity fraud. Phishing means fake messages that trick people into sharing more information. Identity fraud means someone uses another person’s details for their own gain.
The CNIL has warned about stolen mixes of personal details. These include names, birth dates, Social Security numbers, addresses, email addresses, and phone numbers. Such mixes create risks of phishing and identity theft. The warning points to the combination, not to a single detail. It covers exactly the kinds of details named in the new claim.
One CNIL page explains how people can check whether a massive health data leak concerns them. It also lists steps they can take. The regulator also shares advice on leaks and data theft.
A separate healthcare ransomware incident also exposed sensitive patient information, as reported in a Columbia medical practice hit in a ransomware attack, exposing SSNs of thousands of patients.
People who used healthcare services connected to Alaxione should stay careful. Still, nothing reliable shows that every person in the 8.6 million records had data exposed. Until confirmed, the 8.6 million figure remains a seller’s claim. Patients should not treat it as a confirmed count.
Judging big cyberattack claims is hard while investigations continue. More answers must come from Alaxione, the CNIL, or investigators. They would need to show whether the second file holds genuine patient information. They would also need to explain how someone obtained it. Finally, they would need to confirm how many people it truly affects.