A threat actor calling itself "ChimeraZ" has reportedly leaked a 2.8 GB database tied to Portalia, a French umbrella employment firm. According to the reporting, the files include more than 22,000 payroll documents and personal records. The Portalia data breach payroll records story is a useful reminder of how much sensitive information sits inside a single employment intermediary, and of the rights French workers have when that information escapes.
The details below come from the initial reporting. Portalia's own account of the incident, its cause and its full scope have not been established in the material available to us, so treat the numbers as reported claims rather than confirmed findings.
What ChimeraZ Leaked From Portalia
The reported leak is a 2.8 GB database published by a threat actor using the name ChimeraZ. The dataset is described as holding over 22,000 payroll files and personal records belonging to Portalia, an umbrella employment firm.
Umbrella employment companies (in France often called portage salarial firms) act as the formal employer for independent professionals and consultants. They handle contracts, invoicing, payroll and social contributions. That role means they routinely hold documents that most employers would only see in part: identity details, bank information, tax identifiers and salary history.
The reporting does not give a full field-by-field inventory, and we are not going to guess at one. What can be said is that payroll and personal records of this type typically sit at the center of a worker's financial identity, which is why the leak deserves attention even before every detail is confirmed.
Why Payroll Data Is So Valuable to Fraudsters
A single payslip can contain a surprising amount of information. Depending on the document, it may show a full name, address, employer, income, social security details and bank account references. Together, these give a fraudster material to build convincing scams.
The risks fall into a few practical categories:
- Targeted phishing: Someone who knows your employer, your income and your contract history can write a message that looks legitimate, such as a fake notice from a tax office or the umbrella firm itself.
- Identity fraud: Tax IDs and personal details can support attempts to open accounts or apply for credit in your name.
- Banking fraud: Bank details alone do not usually allow theft, but they help criminals impersonate banks or set up unauthorized direct debits.
- Long shelf life: Unlike a password, your salary history and identity details cannot be reset. Leaked payroll data can be reused for years.
This is also why breaches at intermediaries hit hard. Recruitment and employment platforms concentrate data from many people at once, a pattern also seen when an unprotected database exposed hiring data tied to more than 5 million job listings.
GDPR and CNIL: What Portalia Owes Affected Workers
Because Portalia operates in France, the EU's General Data Protection Regulation applies, with the CNIL (Commission nationale de l'informatique et des libertรฉs) acting as the national data protection authority. Under GDPR, organizations that suffer a personal data breach generally must notify the supervisory authority without undue delay, and where possible within 72 hours of becoming aware of it. If the breach is likely to result in a high risk to individuals, those individuals must also be told directly.
Affected people also hold rights they can exercise:
- Right of access: You can ask Portalia to confirm whether it holds your data and to provide a copy.
- Right to information: You can ask what happened, what data was involved and what the company is doing about it.
- Right to erasure and restriction: Where applicable, you can request deletion or limits on processing of data no longer needed.
- Right to complain: You can file a complaint with the CNIL if you believe your data was not properly protected or the response was inadequate.
Whether Portalia has notified the CNIL or individuals has not been confirmed in the reporting we reviewed. Workers should not wait for a letter before acting.
What This Means For You
If you have ever worked through Portalia, or signed a contract with them as a freelancer or consultant, assume your records could be among those in the leak until you hear otherwise. If you have no connection to the firm, the story is still a useful check on how many organizations hold your payroll data.
France has seen a heavy run of incidents lately. Dark web monitoring data recorded more than 145 million data exposures in France over two years, and government systems have not been spared, as the ANTS breach affecting 12 million accounts showed. Data from multiple leaks can be combined, so a payroll leak may make earlier exposures more dangerous.
Steps Affected Employees Can Take Now
- Contact Portalia in writing. Submit a GDPR access request and ask whether your records were involved, what fields were exposed and what protective measures are offered.
- Watch your bank accounts. Review statements for unfamiliar debits and consider asking your bank about extra monitoring.
- Set up fraud alerts. Use the alert tools offered by your bank and, where available, credit or identity monitoring services.
- Be skeptical of messages. Treat unexpected emails, texts or calls about pay, taxes or contracts as suspect. Go to official websites directly rather than clicking links.
- Secure your accounts. Use unique passwords and two-factor authentication for email, banking and tax accounts, since email access lets fraudsters reset other logins.
- Consider a CNIL complaint. If you receive no adequate response, you can escalate.
The Bottom Line
The Portalia data breach payroll records leak, if the reported figures hold, shows how one employment intermediary can become a single point of failure for thousands of workers. Check whether you were affected, send your GDPR access request, and turn on fraud alerts today. For broader context on how these incidents fit together, read our coverage of France's data exposure trends and the ANTS breach.




