School Network Breach Exposes 30,000 Across Indian Ocean Region
Oceania

School Network Breach Exposes 30,000 Across Indian Ocean Region

Multiple breaches of French administration services expose 30,000 across Indian Ocean region.

Thirty thousand people connected to French schools across Madagascar, Mauritius, the Comoros, and Seychelles had their professional data exposed in a single breach of the AEFE network in mid-August 2026. That incident was not isolated. It arrived as part of a coordinated wave of attacks on French administration services, prompting the Indian Ocean Cybersecurity Observatory (OCOI) to issue an urgent alert across the region, timed precisely as the school year began.

The scale of what has failed becomes clearer when the incidents are laid out in sequence. France’s tax authority DGFiP reported fraudulent access to its systems dating back to late June 2026, exposing taxpayer and business data including identity information, addresses, and tax-related details. That service reaches every household filing taxes, including residents of Reunion and Mayotte. In both the AEFE and DGFiP breaches, login credentials and passwords were not compromised.

The education infrastructure has taken the heaviest hits. An April 2026 breach of EduConnect exposed 3.5 million students across France, compromising names, user identifiers, and in some cases passwords. The Reunion Rectorate launched awareness campaigns but could not specify how many local students were affected. At the end of July 2026, the French National Education Ministry confirmed a third incident, this time targeting ministry personnel with data dating back to 2001.

March 2026 brought two more failures. Breaches of the COMPAS and Cnous systems exposed 243,000 teachers and trainee personnel alongside 774,000 scholarship recipients and students in university housing. Then on August 11, 2026, Public Health France reported that a platform breach had exposed approximately 80,000 people’s contact information, including addresses, phone numbers, and email addresses. No medical data was involved.

What makes the cumulative picture dangerous is not any single breach but the combination. A person may appear across several of these datasets simultaneously, their health contacts, tax records, and their child’s school data all exposed at once. When malicious actors cross-reference those separate datasets, they can reconstruct detailed individual profiles and craft far more convincing fraudulent schemes.

The practical consequences are already taking shape. People across the region may receive messages impersonating schools, tax authorities, or other recognized institutions. Identity theft targeting both adults and children becomes more feasible. Fraudulent requests tied to school enrollment, cafeteria services, scholarships, or tax procedures grow harder to distinguish from legitimate communications.

The OCOI has issued concrete guidance for users navigating this environment. People should not click links in unsolicited emails or text messages without first confirming the sender’s identity. Passwords, identification documents, and banking information should never be shared via email or phone, since no legitimate administration requests such information through those channels. Users who have not recently updated their EduConnect or Pronote passwords should do so now, and two-factor authentication should be activated wherever available.

Suspicious contacts can be reported to 17Cyber or Cybermalveillance.gouv.fr. The OCOI, a nonprofit association focused on regional cybersecurity across the Indian Ocean, operates with a mandate covering skills development, public awareness, and building a sustainable cyber ecosystem for the region.

The harder question, as the school year gets underway, is whether the administrations responsible for these systems will move faster to close remaining vulnerabilities than attackers move to exploit the data already in circulation.

Q&A

What was the scale of the AEFE network breach and when did it occur?

The AEFE network breach in mid-August 2026 exposed professional data for 30,000 people connected to French schools across Madagascar, Mauritius, Comoros, and Seychelles.

Which education systems were compromised and how many individuals were affected?

EduConnect breach (April 2026) exposed 3.5 million students; COMPAS and Cnous breaches (March 2026) exposed 243,000 teachers and trainee personnel alongside 774,000 scholarship recipients and students in university housing; French National Education Ministry confirmed a third incident targeting personnel.

What makes the cumulative picture of these breaches particularly dangerous?

A single person may appear across multiple datasets simultaneously with health contacts, tax records, and school data all exposed at once. When malicious actors cross-reference these separate datasets, they can reconstruct detailed individual profiles and craft more convincing fraudulent schemes.

What specific operational guidance did the Indian Ocean Cybersecurity Observatory issue?

OCOI advised not clicking links in unsolicited emails or text messages without confirming sender identity; never sharing passwords, identification documents, or banking information via email or phone; updating EduConnect and Pronote passwords; activating two-factor authentication; and reporting suspicious contacts to 17Cyber or Cybermalveillance.gouv.fr.