Alaxione : 6,8 millions de patients revendiqués
A hacker claims to have stolen data from 6.8 million patients and over 10.1 million appointments from Alaxione, alleging a series of prior intrusions and exploitation of a pre-production environment. The hacker claims to have gained access to the data through multiple development environments, culminating in a complete database from a pre-production instance. This incident follows a pattern of data leaks dating back to 2025, including a SQL database leak in January 2026 and a CSV file in March 2025. The hacker says they alerted Alaxione two days before publishing the information and contacted journalists, receiving no response until the disclosure. The incident highlights a common challenge in cybersecurity: correlating successive data leaks to determine the scope and origin of a recent compromise.
A hacker is alleging a massive data breach at Alaxione, claiming to have obtained the data of 6.8 million patients and over 10.1 million patient appointments. The hacker asserts that this breach is part of a long-standing pattern of incidents, beginning with a SQL database leak in January 2026, and a CSV file in March 2025. The hacker claims to have gained access to the data through multiple development environments before obtaining a complete database from a pre-production instance.
According to the hacker’s account, they alerted Alaxione two days before publishing the information and contacted journalists, but received no response until the disclosure. The hacker states they contacted the ZATAZ Alert Protocol, and their alert was acknowledged within the minute, transforming them into a cybersecurity citizen rather than a criminal.
The hacker’s narrative emphasizes a persistent vulnerability in the management of technical environments. They describe accessing multiple versions of the data from development instances before reaching the complete database, effectively increasing the attack surface. A CSV file containing approximately 4,000 entries associated with Alaxione was found on the hacker’s disk in March 2025, allegedly originating from a previous compromise, though it was not publicly released due to its limited scope.
Furthermore, in November 2025, a smaller SQL leak occurred, the origin of which is currently unclear. The hacker’s claims are complex and require careful analysis to determine the true extent of the recent breach. The incident underscores the importance of correlating successive data leaks and their origins to accurately assess the impact of a potential compromise.
