Cybersecurity for a French training organisation: protecting your EDOF account and learner data
An email that perfectly imitates the logo and layout of the Caisse des Dépôts, an “urgent” request to update your bank details on your EDOF provider account, a link that redirects to a fake login page: these are not hypothetical scenarios. The Caisse des Dépôts and French government services have publicly warned about phishing campaigns specifically targeting training organisations, with the most serious cases involving a hacked EDOF provider account followed by a fraudulent change of bank details to redirect upcoming CPF (Compte Personnel de Formation) payments. For a solo provider or a small team without a dedicated IT department, this risk deserves as much attention as your Qualiopi or GDPR obligations.
“Too small to be targeted”: a dangerous misconception
The natural instinct of an independent trainer or a small organisation is to assume that its size offers protection — why would a fraudster bother with a structure that serves a handful of learners a month? It is precisely the opposite. Phishing campaigns targeting training organisations do not aim at one specific company: they target, at scale, every structure registered on EDOF, regardless of size, because the CPF payment mechanism (automated transfer to a declared bank account) makes the operation profitable as soon as a single account is compromised. Smaller structures are often even more vulnerable, lacking a dual-check procedure before any change to bank details — a control that a larger team tends to build in almost by construction.
Risk number one: takeover of the EDOF provider account
The scenario documented by the Caisse des Dépôts and several regional DREETS offices follows a recurring pattern:
- An email or SMS impersonating the Caisse des Dépôts, EDOF, or a government service is sent to the organisation, with a link to a fake login page that captures the username and password.
- The fraudster then logs into the real EDOF provider account using these stolen credentials.
- They change the bank details linked to the account, redirecting future CPF transfers to an account they control, without the legitimate organisation noticing until the next bank reconciliation.
This mechanism explains why vigilance should focus first on the authentication step, before even thinking about the security of your other tools:
- Never click a link received by email or SMS to access your EDOF provider account. Always type the official address yourself or use a bookmark saved in your browser.
- Check the full sender address, not just the display name: an email labelled “Caisse des Dépôts” can easily come from a domain with nothing official about it.
- Use a long, unique password for your EDOF account, never reused on another service, and enable two-factor authentication if the platform offers it.
- Check the bank details registered on your provider account regularly, even without any alert, to spot an unauthorised change as early as possible rather than at the next transfer.
- Report any suspicious attempt, even an unsuccessful one, through the dedicated support form in your connected EDOF space: this also helps the Caisse des Dépôts detect ongoing campaigns.
Securing learner data beyond EDOF
The EDOF account is just one entry point among others. A training organisation handles personal data daily in its management software, LMS platform, email, and tracking spreadsheets — all of these are surfaces to protect, independently of the documentary GDPR obligations already covered in our article on GDPR obligations for a training organisation. A few habits cover most of the risk without heavy investment:
- Back up your learner data regularly (attendance sheets, assessments, agreements), ideally automatically and on a separate device from your main workstation, to limit the impact of ransomware or hardware failure.
- Limit access to your management tools to the people who genuinely need it, and revoke a trainer’s or collaborator’s access without delay when they leave the structure.
- Keep your software up to date, including your operating system and antivirus: most compromises exploit vulnerabilities for which a patch already exists but has not been installed.
- Encrypt or password-protect your most sensitive documents (health data shared through your accessibility referent, for example) before sending them by email.
These technical and organisational measures directly connect to the requirements of indicator 17 of the Référentiel National Qualité on the adequacy of human and technical resources to your activity, and of indicator 23 on legal and regulatory monitoring, which implicitly covers your awareness of the digital risks specific to your sector.
What to do if an incident actually happens
If you notice unauthorised access to your EDOF account or a leak of learner data, the response should follow a precise order:
- Change your passwords immediately on the affected service and on any other service where the same password was reused.
- Report the fraud to the Caisse des Dépôts through the support form in your connected space, especially in the case of unauthorised changes to your bank details — the faster the report, the better the chances of blocking fraudulent transfers.
- Assess whether the breach must be reported to the CNIL. As soon as learner data may have been accessed by an unauthorised third party, Article 33 of the GDPR requires notification within 72 hours if there is a genuine risk to the people concerned; our article on GDPR obligations covers this procedure in detail.
- Check the impact on your activity declaration number (NDA) and your EDOF registration. A confirmed security incident can, in some cases, trigger checks from the DREETS or the Caisse des Dépôts; our article on suspension and de-listing of an EDOF account explains the procedures and possible remedies if your access were to be blocked following an incident.
- Keep a written trail of every step (screenshots, receipts, correspondence with your bank): this record will be useful for a police complaint or a later audit.
What the research shows about vigilance against phishing
Cybersecurity for small structures is not just a matter of tools: it is first and foremost a matter of behaviour repeated over time. A nation-wide field experiment involving 670 SMEs and their 33,000 employees, published in 2025 in the Journal of Economic Behavior and Organization by David Gonzalez-Jimenez and co-authors, shows that past exposure to a phishing email (real or simulated during an awareness exercise) improves the ability to detect a subsequent attempt only in a limited and temporary way, with the effect fading after a few months (see the study). In practice, this means that a single reminder to stay vigilant — such as reading this article — is not enough: it is better to build simple, systematic habits (never click a link to log into EDOF, check bank details regularly) than to rely on occasional vigilance that naturally erodes over time.
Cybersecurity checklist for a training organisation
- Long, unique password for the EDOF provider account, never reused elsewhere.
- Two-factor authentication enabled wherever available.
- Regular checks of the bank details registered on EDOF, independent of any alert.
- No clicking on links received by email or SMS to log into an administrative account.
- Automated, regular backups of learner data, on a separate device.
- Access to management tools limited to those who need it.
- A known incident procedure: report to the Caisse des Dépôts, assess GDPR obligations, inform your bank.
Take action
Cybersecurity is one of the blind spots many organisations discover too late, often after a first incident. The Complete Kit Certif (€297, 14-day guarantee) includes procedure and monitoring templates that reassure both a Qualiopi auditor and a learner concerned about the protection of their data. Just starting your organisation? The ebook Create Your Training Organisation in 30 Days (€67) helps you build the right habits from the moment you set up your tools, or choose the complete pack (€347) that combines both.
Frequently asked questions
+How can I recognise a phishing email impersonating the Caisse des Dépôts or EDOF?
Always check the full sender address, not just the display name. Be suspicious of any urgent request to log in through a link embedded in the email rather than the official URL you type yourself, and never open an unsolicited attachment. When in doubt, open your EDOF provider portal by typing the address directly into your browser instead of clicking the link you received.
+My EDOF account was hacked and my bank details were changed without my knowledge — what should I do?
Report the fraud immediately through the support form in your connected EDOF provider space, change your password without delay, and contact your bank to try to block any transfers already sent to the fraudulent account. Keep a written record of every step: you will need it for your report and for any police complaint.
+Does an EDOF account hack count as a data breach under GDPR?
Yes, as soon as learner data (identity, contact details, training history) may have been accessed or extracted by an unauthorised third party. This triggers the obligation to notify the CNIL (the French data protection authority) within 72 hours if there is a genuine risk to the people concerned, just like any other data breach.
+Does a small training organisation need professional cybersecurity software?
Not necessarily expensive tools: up-to-date antivirus software, regular automated backups of your learner data, long unique passwords stored in a dedicated password manager, and two-factor authentication wherever it is offered cover most of the risk for a small structure. The main challenge remains human vigilance against phishing, not the technical equipment itself.