France counts 99 reported data breaches at state services

Published

France's national cybersecurity agency has put numbers on a summer of break-ins across the state. Since 1 August 2026, 99 data breaches affecting government services have been reported to ANSSI. Of those, 67 are confirmed and 32 are still being handled by the agency, according to the first situation report of Operation REACTIV, which CERT-FR published on 30 September.

The report reads less like one campaign than a catalogue of ordinary weaknesses exploited at scale, and the exposures are large. At the Education ministry, an intrusion into the GAIA system may have exposed data on 4.35 million teachers. A claimed theft from Zéro Logement Vacant, a platform local authorities use to contact owners of long-term vacant homes, would involve 48 million property owners in France, ANSSI says.

A prime minister's order put ANSSI in charge

REACTIV (REponse et ACTion Interministérielle face aux Violations de données) was ordered by the Prime Minister on 1 September after what the document calls an intensification of criminal data breaches at state services. It gives the agency the power to make ministries take emergency protective measures within tight deadlines, and to run centralised technical crisis communication when a state service is hit. ANSSI cautions that its figures reflect investigations still under way and may change.

One Metabase bug opened nine ministry instances

The most repeated entry point is CVE-2026-72898 in Metabase, the open-source business intelligence tool. ANSSI describes it as an SQL injection that lets an unauthenticated user reach the application's database and obtain administrator rights on the instance, and says mass exploitation has been observed since early August. Nine instances inside ministries were compromised. The fix has been available since 6 August.

Victims the report ties to Metabase include the France VAE portal, where the attacker took all user data on 8 August, the Qualicharge electric vehicle charging application and even ANSSI's own innovation lab. Metabase is also the suspected way into Zéro Logement Vacant.

The other recurring vectors, per ANSSI:

Tax and land registry data among the losses

At the tax administration (DGFIP), incidents detected on 12 and 13 August exposed tax data on about 353,000 individuals and 252,000 businesses, and a compromised account belonging to a private surveyor was used to pull about 2 million cadastral records covering roughly 434,000 people. The Bloctel do-not-call service, breached on 7 August through a business account, was shut down permanently on 11 August.

Patch Metabase, then enforce real MFA

ANSSI has asked every ministry to find its Metabase instances and confirm they are updated, and the same applies to any organisation running the tool: apply the fix released on 6 August and check logs for signs of earlier access, as CERT-FR's earlier alert advised. Background on the flaw is in our coverage of the Metabase bug, and wider context in France's country profile. Beyond that, the lessons are unglamorous: strong multi-factor authentication on every exposed portal, testing for broken access controls, and contractors held to the same standard.

What stands out is how little of this required skill. A patch left unapplied, passwords without a second factor and a contractor's login were enough to move records on millions of French citizens out of state systems in a matter of weeks.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions