-
A threat actor allegedly advertised nearly 190,000 INSERM user records on a cybercrime forum.
-
The claimed database reportedly contains 189,997 records in JSON format, but no detailed sample was shared.
-
INSERM has recently added more security measures as phishing remains a major threat to the institute.
A threat actor has allegedly advertised a database linked to France’s National Institute of Health and Medical Research, INSERM. The listing reportedly appeared on a cybercrime forum and claims to contain 189,997 user records. The seller allegedly offered the data in JSON format.
A screenshot showing INSERM branding also reportedly appeared with the listing. However, the available information does not show a detailed sample of the alleged records. That makes it difficult to confirm the database’s contents or source.
There is also no public confirmation from INSERM or French cybersecurity authorities about the alleged database. Searches for independent reports about the specific 189,997-record claim also found no established coverage.
The claim should therefore be treated as unverified at this stage. No evidence currently confirms that INSERM systems suffered a breach.
Threat Actor Claims INSERM Database Contains Nearly 190,000 Records
The alleged listing involves data reportedly connected to INSERM, a major French medical research organization. The threat actor claims the database contains almost 190,000 user records.
The advertised total stands at 189,997 records. The seller reportedly provided the database in JSON format. A screenshot carrying INSERM branding also appeared alongside the offer.
However, the available listing does not include a detailed sample of the records. Researchers, therefore, cannot confirm what information the database contains.
They also cannot confirm whether the data came from INSERM systems. The alleged listing comes as INSERM continues to improve its security measures. In a February 2026 update, the institute announced new steps to protect its systems.
The measures include two-factor authentication, security awareness programs, phishing tests, and tighter email forwarding controls. INSERM said two-factor authentication already protects services such as InsermBiblio, Share, Cloud, and Sifac+. The institute also planned to extend the protection to most of its other services.
INSERM Warns About Growing Phishing Threat
INSERM has also warned users about phishing, which remains a major problem for organizations. In a July 2026 security advisory, the institute described phishing as a leading method used in cybercrime. INSERM said it receives about 100,000 phishing emails each year. Attackers may pretend to be trusted people or organizations.
They may then try to steal personal information or login details from their targets. The alleged database listing comes against that security backdrop. However, the available information does not show whether the claimed records contain passwords, contact details, or other user information.
That missing detail also makes it difficult to measure the possible impact of the alleged exposure. The claim also follows a confirmed cyberattack involving France’s National Institute of Statistics and Economic Studies, INSEE.
INSEE disclosed in June 2026 that an attack exposed personal and professional contact information linked to about 12,800 people. The affected group included current and former personnel and members of related corps.
INSEE said the incident did not expose passwords, personal contact details, banking information, Social Security numbers, or health data. The INSEE incident shows the type of data exposure French public organizations have faced recently. However, it does not confirm any connection between that attack and the alleged INSERM database.
Alleged Listing Remains Unconfirmed
If the advertised INSERM database is genuine, the exposed information could create risks for affected users. Cybercriminals could potentially use stolen details in phishing or impersonation attempts.
However, the available information does not identify the specific fields included in the alleged database. That means the exact risks cannot be confirmed from the listing alone.
An X account identified as Seb, @cyberseb_, also commented on France’s wider cybersecurity situation. The account said France has a strong cybersecurity sector but warned that artificial intelligence could increase the attack surface. The comment does not confirm the INSERM database claim. It also provides no evidence connecting artificial intelligence to the alleged listing.
For now, the alleged database remains an unverified claim from a cybercrime forum. Confirmation from INSERM, French authorities, or independent security researchers would be needed to establish that a breach occurred.
Similarly, hackers recently claimed a 250GB data theft from Nigeria’s Bankers’ Institute CIBN, highlighting how institutions worldwide are being targeted with unverified, and sometimes genuine, data breach claims. The available information also does not confirm that the advertised records came from INSERM systems.