Data breaches in the French State: what Operation REACTIV reveals

99 data breaches reported across the French State in two months. ANSSI's first review points to familiar causes, and to a roadmap with a 31 December deadline.

· 8 min read
Illustration: glass folders leaking orange data fragments
CERTFR-2026-CTI-006 99 breaches since 1 August
Metabase 9 instances in ministries
State roadmap Admin MFA by 31/12/2026

Since 1 August 2026, 99 data breaches have been reported to ANSSI by French State services: 67 are confirmed and 32 are still being analysed. The first review of Operation REACTIV, published on 30 September by CERT-FR, does not describe any exceptional attack. It describes credentials stolen by infostealers, accounts without multi-factor authentication (MFA), an internet-facing tool left unpatched and compromised suppliers. In other words, weaknesses that any public-sector CISO can start looking for this week.

01

Data breaches in France: a summer that changed the scale

The series starts at the DGFiP, the French tax authority. In late June, intruders log in to a tax portal with compromised credentials. Access is cut off, but the theft is only confirmed on 12 August, when a hacker claims it on a forum. According to Banque des Territoires, around 678,000 individuals and businesses are affected: contact details, reference tax income, withholding rate, SIREN number. Two more incidents follow: the land registry data server, where the estimate rises from 200,000 accounts to 1.8 million records, then the vacant estates portal, shut down on 17 August.

The Ministry of Finance is not an isolated case. On 2 October, Afpa, the public vocational training agency, announced that its accommodation management software had been accessed illegally between 8 and 13 August: 1,732,703 former trainees are affected. The Association of French Mayors confirmed on 4 September the theft of around 114,000 rows through its website, with passwords stored in clear text for 533 people according to Banque des Territoires. In early October, a hacker claimed the data of more than 700,000 beneficiaries of Hauts-de-France regional grants; the region's president, Xavier Bertrand, put the figure at 545,000 people, affected through two suppliers. These volumes are still to be confirmed.

Citizens feel it: according to the 2026 Cybermalveillance.gouv.fr barometer, 45% of French people say they were told about a leak of their data this year, up from 30% in 2025 (Banque des Territoires). In mid-August, the Prime Minister asked ANSSI for a stronger response capability (Banque des Territoires). On 7 September, the agency announced REACTIV.

02

Operation REACTIV: what ANSSI can now impose

REACTIV stands for "REponse & ACTion Interministérielle face aux Violations de données" (interministerial response and action against data breaches). It is not a new body, IT-Connect points out, but a refocus: ANSSI concentrates its operational teams on two tasks, handling compromised user accounts and analysing data breaches, to contain exfiltration faster.

The agency gains two new powers over ministries:

  • imposing immediate protective measures within tight deadlines: cutting off access, revoking accounts, isolating a server, without waiting for an internal decision;
  • centralising technical crisis communication when an attack of this kind hits a State service.

The scheme comes on top of the 2026-2027 State digital security roadmap, published on 9 April, which the Prime Minister asked to speed up. On 17 August the government had also announced €200 million in funding and a rule requiring each ministry to spend 5% of its digital budget on cybersecurity from 2027. ANSSI's director, Vincent Strubel, said according to Next that the effort was temporary and came at the expense of other topics.

03

99 data breaches: what the first review says

The CERTFR-2026-CTI-006 situation report covers the first two months. CERT-FR warns that its figures are provisional and do not give a complete picture. They are still enough to outline three families of causes.

Operation REACTIV · 1 Aug → 30 Sept 2026

99data breaches reported to ANSSI by French State services

67 confirmed

32 under analysis

  • 9ministry Metabase instances compromised
  • 118accounts compromised at ANSSI's innovation lab
  • 2DINUM instances (ProConnect, Nuage-Public)
Source: CERT-FR, situation report CERTFR-2026-CTI-006 of 30 September 2026. Figures are provisional according to CERT-FR.

An exposed tool, a critical flaw. CVE-2026-72898 affects Metabase, an open-source dashboard tool widely used to explore databases. It is an SQL injection that can be exploited without authentication and grants administrator rights on the instance. Nine ministry instances were compromised. ANSSI's own innovation lab counts 118 compromised accounts, about thirty of them external users (usernames, email addresses, hashed passwords). DINUM, the interministerial digital directorate, had two instances hit, linked to ProConnect and Nuage-Public, with data it considers already public (IT-Connect).

Stolen credentials, no second factor. Credentials stolen by infostealers, on personal computers or partners' machines, were reused against internet-facing services without MFA: the DGFiP public management portal, the land registry, the agency for French education abroad (Next). ANSSI considers that the lack of MFA, or a weak second factor such as email, made these intrusions easier.

Compromised suppliers. The review cites a subcontractor of TRACFIN, the financial intelligence unit, and the server customs (DGDDI) uses to exchange files with its suppliers.

Applying NIS 2 "would have prevented the majority of these attacks".

Vincent Strubel, Director of ANSSI, as reported (in French) by Banque des Territoires
04

Infostealer, MFA, exposed service: anatomy of a typical data breach

Put together, the cases in the review and those noted by the French Senate finance committee (note reported on 8 September by Banque des Territoires) almost always follow the same four-step scenario. Each link is also a place to break it.

Typical attack chain Where to break it
  1. 01

    Infostealer

    Spyware steals the passwords on a personal or partner computer.

    DGFiP staff (Senate note)

    EDR, no sensitive access from unmanaged devices

  2. 02

    Reused credential

    The credential is resold, then replayed on a public service.

    A chartered surveyor's account (land registry)

    Strong MFA, no codes sent by email

  3. 03

    Exposed service

    The portal requires no second factor, or the tool is unpatched.

    PIGP, land registry, AEFE, 9 Metabase instances

    Inventory of exposed services, tracked patching

  4. 04

    Exfiltration

    Data is extracted in bulk without triggering any alert.

    ≈ 678,000 taxpayers (DGFiP)

    Quotas, logging, alerts on volumes

Based on situation report CERTFR-2026-CTI-006 (via Next) and the French Senate finance committee note (via Banque des Territoires).

The infostealer, a starting point outside your perimeter

An infostealer is discreet malware that harvests passwords saved in the browser, session cookies and sometimes files, then sends them to resellers. It often lands on a machine IT does not manage: an employee's family computer, a partner's laptop. According to the Senate note, credentials of DGFiP staff were stolen this way.

Without MFA, a password is enough

With a password alone, a stolen credential opens the door. The senators noted that an account covered by tax secrecy had no two-factor authentication. A code sent by email offers little extra protection if the mailbox is compromised too.

Metabase: the patch already existed

The vendor released its patch on 6 August. The France VAE portal was compromised on 8 August, and the CERT-FR alert of 10 September reported "numerous compromises". An analytics tool set up alongside the information system and opened to the internet for business needs easily escapes the inventory and the patch cycle.

Third parties, one door among others

The land registry was reached through a chartered surveyor's account, and the first DGFiP intrusion through the credentials of an Education ministry employee. The Senate also notes that there was no mechanism to detect bulk extraction, and calls for a "better balance between data flows and access security".

05

Lessons for a public-sector CISO

The State roadmap already sets the deadlines. They apply to ministries, but a local authority, a hospital or a public operator can use them as a benchmark.

French State roadmap 2026-2027
8 Oct 2026 article published
31 Dec 2026 84 days
  • MFA on all administrator accounts
  • EDR or XDR on every workstation and server
  • Dedicated administration workstations (NIS 2 entities)
28 Feb 2027
  • MFA on all critical information systems
28 Feb 2028
  • MFA on all information systems
Source: ANSSI, roadmap of priority efforts for the digital security of the French State 2026-2027; deadlines as reported by IT-Connect.
  • MFA first where the impact is highest: administrator accounts, remote access, portals open to partners. Avoid email as a second factor on sensitive access.
  • EDR on every workstation and server, and a clear rule for unmanaged devices: no access to sensitive applications from a personal computer.
  • An inventory of exposed services, including dashboard tools, test instances and business applications hosted by a supplier, with a tracked patch deadline after each CERT-FR alert.
  • A map of third-party access: who has an account, on what, with which authentication factor. Disable dormant accounts, as ANSSI did for those inactive for three months.
  • Detection of bulk extraction: query quotas, like those announced at the DGFiP, logging and alerts on unusual volumes.
  • An up-to-date risk analysis that includes these scenarios, and a data breach procedure rehearsed before day one.

On the GDPR side, the CNIL expects notification within 72 hours if the breach poses a risk to individuals, information to those individuals if the risk is high, and internal documentation of every incident in all cases. Our articles on the French resilience bill and on cyberattacks against hospitals show the same causes recurring elsewhere in the public sector.

06

How to prepare with a tool-supported risk analysis

The REACTIV review reads like a list of attack paths: a poorly protected partner machine, an exposed service, an account without a second factor, a database queried without limits. That is exactly what an EBIOS RM-style risk analysis aims to bring to light before the attacker does, taking the ecosystem into account.

Phinasoft, a French GRC platform whose EBIOS RM risk analysis software holds the ANSSI label, helps public-sector teams link these scenarios to tracked measures, assess their suppliers and keep their GDPR records and impact assessments up to date. The goal is simple: on the day ANSSI or the CNIL asks, know which services are exposed, who can access them and what has been done.

07

Frequently asked questions about data breaches

What is a data breach?

A data breach, or data leak, is the unauthorised access to or disclosure of data, most often personal data. For the CNIL, it falls under personal data breaches, which cover any loss of confidentiality, integrity or availability, whether accidental or malicious.

What should a public body do after a data breach?

Contain it first: cut off access and revoke the sessions and accounts involved. Then report the incident to CERT-FR and notify the CNIL within 72 hours if there is a risk to individuals, and inform them if the risk is high. Finally, document the incident internally, in all cases.

What is an infostealer?

It is malware that steals the credentials, cookies and other secrets stored on a device, then resells them. It explains part of the 2026 breaches: the stolen credentials were reused on public services reachable without MFA.

What is ANSSI's Operation REACTIV?

Launched on 7 September 2026 at the Prime Minister's request, REACTIV focuses ANSSI on data breaches in State services. The agency can impose emergency measures on ministries within tight deadlines and centralises technical crisis communication.

Summary

01

A wave, not an incident

99 data breaches reported to ANSSI by State services between 1 August and the end of September 2026, 67 of them confirmed. REACTIV gives the agency the power to impose emergency measures on ministries.

02

Very familiar causes

Credentials stolen by infostealers, accounts without MFA or with a weak second factor, an exposed tool left unpatched (Metabase), compromised suppliers: nothing sophisticated, all of it avoidable.

03

A plan already written

MFA on administrator accounts and EDR on every workstation and server by 31 December 2026, an inventory of exposed services, a review of third-party access, detection of bulk extraction and an up-to-date risk analysis.

Sources (16)

A platform and service that adapt to you

Our platform is designed for fine-tuned configuration and broad adaptability to your needs.