The Régie Eau Cœur d’Essonne was informed on October 8, 2026, that a file containing subscriber data had been posted online. Investigations are underway to determine its exact origin.
The affected data includes the names of occupants and contract holders, their addresses, meter and connection numbers, contract references, payment methods (monthly installments or direct debit), water and sanitation subscription details, and arrival and departure dates. The National Information Security Agency confirms that no banking details (IBAN, card number) were disclosed.
This information does not allow access to bank accounts, subscriber portals, or intervention on water supply. However, it could be used by malicious individuals to impersonate the Régie and attempt to obtain bank details from subscribers, solicit payments, obtain direct debit mandates, or gain access to their homes.
In response, the Régie has implemented immediate protective measures for its systems, has engaged the National Information Security Agency, has notified the CNIL, and has filed a complaint. Controls on all contract modification requests and telephone support have been strengthened.
The Régie advises extreme vigilance: it will never request bank details, codes, or immediate payment by phone, SMS, or email. Faced with a suspicious message, call, or letter concerning a water contract, do not reply or click on any links; instead, call 0 800 500 19, a number found on invoices. Do not sign any direct debit mandate you have not requested. Do not allow anyone claiming to be from the Régie into your home without verification, as the Régie always informs you in advance of any planned visit. In case of suspicious behavior, call 17. The Régie emphasizes that any message requesting bank details or payment is an attempted scam.




