France's public sector on the front line: targeted from all sides, yet not defenceless
In mid-August 2026, France's tax authority (DGFiP) confirmed that an attacker had exfiltrated the tax data of 678,000 users, plus a cadastral dataset, after hijacking two legitimate accounts. A few months earlier it was the ANTS and its nearly 12 million accounts, the Crous and its 774,000 students, the national education ministry three times over, the State messaging app Tchap, INSEE, Bloctel. The list is dizzying, and it keeps growing.
This deep dive extends our analysis Why Is France Among the Top 5 Most Cyberattacked Countries?: if France sits durably among the most targeted nations, its public sector is the front line. But a front line is not an abandoned position. This article covers the question in five steps: the real scale of the attacks, their causes, what the numbers actually say, the response, which is far more substantial than commonly believed, and what must now be built.
Two years of attacks: the public sphere takes the hits
The recent chronology almost speaks for itself. From France Travail (43 million people potentially exposed in 2024) to the DGFiP (August 2026), through hospitals, local authorities and State services, no layer of the public sphere has been spared.
| Date | Target | Scale |
|---|---|---|
| March 2024 | France Travail and Cap emploi | 43 million people potentially exposed (including social security numbers) |
| March 2024 | Ministries (Labour, Economy, Health…) | DDoS of "unprecedented intensity" claimed by Anonymous Sudan |
| April 2024 | Simone Veil hospital, Cannes | 61 GB of patient and staff data published after refusal to pay |
| Dec. 2025 | Welfare (CAF) claimants' data | 22 million rows leaked; the Cnaf denies any intrusion into its systems |
| March 2026 | National education (COMPAS), then Cnous/Crous | 243,000 staff; 774,000 students, 329,000 documents (ID photos, payslips) |
| April 2026 | ANTS (France Titres) | Nearly 12 million accounts, almost one French person in six (IDOR flaw) |
| June 2026 | Tchap (the State's messaging app) and INSEE | 643,000 messages claimed; 12,800 INSEE staff |
| July-Aug. 2026 | National education (3rd incident) and Bloctel | Staff in academies since 2001; 3 million phone numbers |
| Aug. 2026 | DGFiP (impots.gouv.fr) | 678,000 taxpayers plus cadastral data; access via hijacked legitimate accounts |
One technical detail deserves attention, because it changes how this dark series should be read. Across the major State incidents of 2026 (national education, Tchap, Bloctel, DGFiP), the recurring vector is not an exotic zero-day or elite spyware: it is the hijacking of a legitimate professional account. At the ANTS, an elementary application flaw, exploited by a fifteen-year-old, was enough.
Analyst Tariq Krim, in his breakdown of the tax authority hack, points to the root of the problem: an inherited trust model in which "more trust is granted to someone once they are inside", which the extension of remote access never led to rebuilding. Intrusion, exfiltration and discovery of the exfiltration are three distinct moments; in the DGFiP case, weeks separated the first from the last. His formula sums up the stakes: "an identity always ends up compromised. What separates a secure system from a fragile one is what happens next."
From Bercy 2010 to the DGFiP 2026: have the lessons been learned?
This scenario is not new. In late 2010, the Ministry of the Economy and Finance suffered what remains the first major cyberattack publicly acknowledged by the French State: an espionage operation targeting the files of France's G20 presidency. The playbook would make today's CISOs smile, so current has it remained: credible emails, sent by senders the victims knew, carrying booby-trapped attachments. Around 150 workstations out of 170,000 fell under the attackers' control, for weeks, before the affair broke in March 2011 and Bercy disconnected 10,000 computers over a remediation weekend.
Fifteen years on, the comparison is instructive in both directions. Institutionally, the lesson was learned: the Bercy electroshock (and a few contemporary affairs) turned the then-fledgling ANSSI into the muscular agency it has become, and France has since built a complete chain, from the national CERT to specialised judicial offices. Technically, however, the fundamentals of the problem have not moved: in 2010 as in 2026, the attacker walks in through the door of trust (a credible email then, a hijacked legitimate account now) and thrives in detection's blind spot. What has changed is the objective: yesterday's targeted espionage sought a few files; today's attacks vacuum up the data of millions of citizens.
The cumulative effect: leaks that cross-reference each other
This is where the 2024-2026 series changes in nature. Taken in isolation, each leak is already a serious incident; put end to end, they become something else. A fraudster who crosses the civil status and address from the ANTS, the social security number from France Travail, the tax income and household composition from the DGFiP, the claimant data from the December 2025 leak and the identity documents from the Crous can rebuild near-complete profiles of millions of people, without ever having to hack them individually.
Those profiles feed mass scams that are increasingly targeted, and the numbers already show it: according to Cybermalveillance.gouv.fr, 2025 saw fake-bank-adviser fraud jump 159 %, phone-number spoofing 517 % and phishing 70 %, the top threat across all audiences. The French shooting federation case, whose October 2025 leak was followed by targeted burglaries at gun owners' homes, is a reminder that the harm can even turn physical. The accumulation of public-sector leaks does not just weaken administrations: it turns the population itself into an easy target.
What the public sphere weighs in the numbers
Official statistics confirm the exposure. In 2025, four sectors concentrated 76 % of the 1,366 incidents brought to ANSSI's attention: education and research (34 %), ministries and local authorities (24 %), healthcare (10 %) and telecommunications (9 %). In other words, roughly two out of three incidents handled by the national agency involve the broader public sphere.
The picture repeats at every level. ANSSI handled 218 incidents affecting local authorities in 2024 alone, 144 of them targeting municipalities; the Cour des comptes considers French local authorities "the most targeted public sector in Europe". In healthcare, CERT Santé logged 764 reported incidents in 2025, and 38 % of reports led to degraded operations or an interruption of patient care.
Our own intelligence tells the same story at a finer grain: over the past six months, 1,251 major France-related reports were retained by our analyses, and nearly one in four touches the public sphere.
One honest caveat, to which we will return: ANSSI itself warns that these figures reflect reports from its beneficiaries, many of them public entities, "and are not necessarily representative of all security events affecting the various sectors of activity in France".
Why the public service attracts attackers
Data that cannot be revoked. Social security numbers, reference tax income, civil status, health data, identity documents: unlike a credit card number, this information is valid for life. The DGFiP leak illustrates the worst case: among the exposed data sits a list of more than 26,000 taxpayers with declared income above €100,000, a dream directory for "fake bank adviser" fraud.
A systemic chain of trust. impots.gouv.fr is a FranceConnect identity provider. When one link in that chain is perceived as attackable, confidence in the whole public digital-identity edifice wavers, far beyond the volume of stolen data.
Constrained, uneven resources. A Cybermalveillance.gouv.fr study found as early as 2020 that 77 % of local authorities spent less than €2,000 a year on cybersecurity. The Cour des comptes still points to wide disparities in maturity depending on entity size, and to the difficulty of recruiting cyber skills into local public service.
A technical and organisational legacy. Ageing, siloed systems, inter-administration connections, privileged accounts granting access to massive volumes: the public sector's attack surface was built in layers, without its trust models keeping up. Add the dependence on third parties, the weak link we documented in Third-Party Security: Now One of the Leading Entry Points for Attackers: an authorised contractor in the DGFiP case, an externally hosted server for a network of 700 medical laboratories hit in March 2026.
Continuity of service as leverage. A hospital cannot close, a town hall cannot suspend civil registries. That obligation of continuity makes the public sphere a prime extortion target, and every interruption a visible event that feeds the pressure.
France is not an isolated case
It would be tempting to conclude this is a specifically French weakness. International comparisons tell another story: everywhere, public administration has become the most targeted sector.
| Scope | Indicator | Value |
|---|---|---|
| European Union | Public administration's share of recorded incidents | 38 % (top sector, share doubled in a year) |
| France | Share of the EU's public-administration incidents | 27 %, ahead of Italy (26 %) and Germany (16 %) |
| Italy | Cyber events targeting public institutions in 2025 | 1,140, up from 756 in 2024 |
| United Kingdom | "Nationally significant" incidents handled by the NCSC | 204 in one year, up 130 % |
| United States / world | Ransomware attacks on government entities | 276 over nine months of 2025, up 41 % |
In its Threat Landscape 2025, ENISA finds that public administration concentrates 38 % of recorded incidents in the Union, a share that doubled in a year, and puts France first among affected countries (27 % of European incidents aimed at that sector), ahead of Italy and Germany. The United Kingdom saw its "nationally significant" incidents jump 130 % in a year, with a wave of coordinated attacks on London councils in late 2025. In the United States, ransomware attacks on public entities rose 41 % over the first nine months of 2025.
An important nuance accompanies the European figure: 96 % of the incidents ENISA records against public administration are denial-of-service attacks by hacktivists, led by the pro-Russian group NoName057(16). These are attacks of visibility far more than of gravity; ransomware accounts for only 2 % of incidents against the sector in Europe. Being the number one target of noise is not being the number one victim of damage.
More attacks, or better detection? Reading the numbers with care
This may be the most counter-intuitive lesson of this dossier: rising numbers do not only measure the threat, they also measure the ability to see it.
ANSSI says so explicitly in its Panorama 2025: its figures correspond to reports from its beneficiaries and "are not necessarily representative" of all events in France. Its own series invite nuance: after three years of steep growth (831 incidents in 2022, 1,112 in 2023, 1,361 in 2024), the incident count stabilised in 2025 (1,366). And while claims of data exfiltration jumped 51 %, the agency could confirm only 80 of them: criminals happily recycle already-public data to inflate their announcements.
The cleanest demonstration comes from Italy. In 2025, cyber events targeting Italian public institutions jumped from 756 to 1,140. The national authority, ACN, explicitly attributes the rise to the entry into force of law 90/2024, which extended notification obligations to many public entities. The result, at national level: reported events rose 38 %, but incidents with confirmed impact rose only 7 %.
France is about to live exactly that scenario. The transposition of NIS 2 will take the number of entities subject to 72-hour incident notification from roughly 300 to some 15,000, local authorities included. A mechanical, massive rise in French reports over the coming years is therefore all but certain, and it will not mean that attacks have exploded. Better to anticipate it now than to read a victory of detection as a defeat of defence.
A final word of honesty on this point: saying that past French increases reflect growing maturity remains a plausible hypothesis, not a demonstrated fact. CESIN attributes the drop in successful attacks (40 % of companies hit in 2025, against 47 % a year earlier) to improved detection and response capabilities; that is one actor's interpretation, based on a panel of large private companies. Maturity signals exist (France ranks 15th in the National Cyber Security Index, ANSSI's workforce has more than doubled since 2021), but they measure an institutional framework, not the effective security of systems.
The response: France arrests, dismantles and convicts
There remains the least-known part of the dossier, and the most encouraging: France is not watching from the sidelines. Over the past three years, its investigative services have lined up a series of concrete wins, alone or in coalition.
| Date | Operation | Outcome |
|---|---|---|
| Feb. 2024 | Operation Cronos (LockBit), task force created at France's initiative | 34 servers seized, 22 sites dismantled; LockBit has since vanished from attacks on Europe's public administration |
| July 2024 | PlugX botnet disinfection (Paris prosecutor, C3N, Sekoia) | ~2.5 million infected machines worldwide, ~3,000 in France; method later adopted by the FBI |
| 2024-2025 | Operation ENDGAME (with the OFAC cybercrime office) | Over 1,000 infostealer servers neutralised (Lumma, Rhadamanthys, VenomRAT…) |
| Feb.-June 2025 | BreachForums arrests in France | 4 suspected administrators detained (ShinyHunters…); "IntelBroker" identified and arrested |
| Sept. 2025 | Takedown of DFAS, the last major French-speaking criminal marketplace | ~12,000 members; 2 arrests, 6 bitcoins seized |
| Feb. 2026 | Phobos conviction (Paris criminal court) | 5 years in prison (1 suspended) and an €80,000 fine for a ransomware operator |
| April 2026 | ANTS leak: lightning investigation by the J3 unit and OFAC | Suspect arrested 12 days after the leak was confirmed |
| June 2026 | DumpSec sweep (OFAC Rennes) | 7 simultaneous arrests in 6 cities; more than 1,500 compromised entities, including Crous and national education |
| June 2026 | Takedown of the Marak group (healthcare) | 5 arrests; nearly 4 million patient records exfiltrated |
Three lessons emerge from this series. First, the effect of takedowns is measurable: LockBit, whose takedown task force was created within Europol at France's initiative, accounted for 26 attacks on Europe's public administration in ENISA's previous census; it has entirely vanished from the latest. Second, justice follows through: the conviction of a Phobos ransomware operator in Paris in February 2026 (five years in prison) shows a criminal-justice chain that now goes all the way. Third, the domestic segment is dealt with fast: the suspected authors of 2026's major public-sector leaks (ANTS, Crous, national education, hospitals) are young French nationals aged 15 to 22, and all were arrested within one to twelve months, including just twelve days for the ANTS leak.
Resources follow the same slope. OFAC, the anti-cybercrime office created in late 2023, is set to grow from 380 to 720 specialised investigators by 2027; more than 15,000 police officers and gendarmes are now digitally trained; ANSSI's workforce has grown 128 % since 2021. And the national cybersecurity strategy for 2026-2030, announced in January 2026, makes "impeding the cyber threat" a pillar in its own right: the response is no longer a series of operations, it is an assumed public policy. After the ANTS leak, the government also released €200 million as an emergency measure, created an authority tasked with standardising the security of ministerial infrastructure, and required that from 2027, 5 % of every ministry's digital budget go to cyber.
Citizens and companies: the ones who ultimately pay
The judicial response punishes perpetrators, but it does not repair the harm. Because the real cost of these attacks is not borne by the administrations that were hit: it trickles down, sometimes years later, onto French citizens and companies.
For citizens, a deferred harm that never expires. With civil status, an address, a social security number and a tax notice cross-referenced, a fraudster can steal an identity: open an account, take out a loan, divert social benefits, all in the name of a victim who discovers the problem long afterwards. The Cybermalveillance.gouv.fr figures quoted above (fake bank adviser +159 %, number spoofing +517 %) already measure that shift. And because a social security number or a date of birth cannot be "revoked", the burden of vigilance now rests, for life, on the people exposed; for the 774,000 Crous students whose identity documents are circulating, that vigilance will begin before they even enter working life.
For companies, fuel for social engineering. Public-sector leaks also arm attacks against the private sector. A scammer who knows their target's taxable income, bank and family situation crafts a fake adviser call or a fake transfer request far more convincing than generic phishing: the list of 26,000 taxpayers with income above €100,000 is, from that standpoint, a turnkey targeting tool. Genuine exfiltrated identity documents also let criminals pass the onboarding checks (KYC) of banks and platforms, and thus open mule accounts for fraud and laundering. And companies that rely on FranceConnect or on civil-status data to verify their customers mechanically inherit the fragility of the public chain.
Risks that compound mechanically. This stock of data does not depreciate: every new leak completes and refreshes it. The coming years should therefore be expected to bring more personalised scams, better-crafted document fraud and, more insidiously, an erosion of trust in online public services themselves. A citizen who no longer dares use digital public services is also a cost, for the State and for the economy alike.
Investing where it matters
Faced with this, the temptation is to ask everything of the judicial response. But a structural problem cannot be prosecuted away: prevention remains underfunded precisely where it would pay off most. Four work sites stand out.
Train the young, on both sides of the fence. The paradox of 2026 is cruel: the year's major public-sector leaks are the work of young French nationals aged 15 to 22, often self-taught, while the Cour des comptes points to the difficulty of recruiting cyber skills into the public service. The talent pool exists; what is missing is direction. Raising awareness from secondary school, opening accessible study paths, channelling talent into legal frameworks (competitions, bug bounty programmes, the cyber reserve) and making public-sector careers attractive would cost a fraction of a single major leak.
Strengthen defence in depth, rather than the outer wall. The 2026 incidents hammer the point home: the attacker walks in with a legitimate account, so the perimeter is no longer enough. Phishing-resistant authentication, least privilege, system segmentation, and above all supervision of what happens after the intrusion, the blind spot the DGFiP paid for in weeks of detection delay. That is exactly the lesson of Tariq Krim's formula quoted above: a system's security is judged by what happens once an identity is compromised.
Treat French citizens' data as it deserves. Data that stays valid for life calls for a lifelong standard of care: minimisation (collect and cross-reference only what is necessary; data that is never collected can never leak), real database encryption, retention periods actually enforced, compartmentalised bulk access. That an elementary application flaw was enough to expose nearly 12 million accounts at the ANTS says less about technical weakness than about a relationship to data: until citizens' informational assets are treated as the critical infrastructure they have become, the same causes will keep producing the same effects.
And fund it over time, not in emergencies. The €200 million released after the ANTS leak and the 5 % of ministerial digital budgets mandated from 2027 point in the right direction. But as long as some local authorities spend less on cybersecurity each year than the price of a single workstation, the weak link will stay the same. Investing before the incident always costs less than paying after it.
Front line does not mean lost line
France's public sector is indeed on the front line: the data it holds cannot be revoked, its continuity of service is non-negotiable, and its attack surface grew faster than its trust models. The 2026 incidents, almost all starting from a hijacked legitimate account, point to the real work ahead: identity and access management, and the ability to see what happens after the intrusion.
But the catastrophist reading makes two mistakes. It takes a rise in reports for a rise in attacks, when detection and notification obligations mechanically reshape the curves, as Italy has just demonstrated. And it ignores the response: attackers identified and arrested within weeks, criminal infrastructure dismantled at France's initiative, convictions handed down. The front line is not a fatality; it is a position being held, and held better and better.
One last signal is worth watching, because it says something about the climate. On 12 August 2026, the White House signed a memorandum authorising, for the first time, vetted private companies to conduct offensive cyber operations against foreign criminal organisations, under federal oversight. It is not yet the generalised "hack-back" some are calling for, but it is a threshold: exasperation with the attacks is now pushing States to arm the private sector. Should that path open wider, the framing will be anything but simple: in a space where attribution remains uncertain and attackers route through the infrastructure of innocent victims, avoiding overreach and escalation will be a balancing act. For the response to remain a strength, it will have to remain a governed policy.
Sources
- Cybernetica (Tariq Krim), Piratage des impôts : comment en est-on arrivé là ? (16 August 2026): cybernetica.fr
- France 24, Des cyber-espions à l'assaut de Bercy et des données concernant le G20 (7 March 2011, ~150 compromised workstations): france24.com
- Cybermalveillance.gouv.fr, 2025 activity report (fake bank adviser +159 %, number spoofing +517 %, phishing +70 %): cybermalveillance.gouv.fr
- The Washington Post, Trump signs memo authorizing private sector to launch cyberattacks (14 August 2026): washingtonpost.com
- ANSSI, Panorama de la cybermenace 2025 (CERTFR-2026-CTI-002: sector breakdown, 128 ransomware cases, exfiltrations): cert.ssi.gouv.fr
- ANSSI, Synthèse de la menace sur les collectivités territoriales (CERTFR-2025-CTI-002, 218 incidents in 2024): cert.ssi.gouv.fr
- Cour des comptes, report on local-authority cybersecurity (June 2025), via Banque des Territoires
- CERT Santé / ANS, Observatoire des signalements 2025 (764 incidents, 38 % degraded operations): esante.gouv.fr
- France Travail, statement of 13 March 2024 (43 million people): francetravail.org
- Cnaf, statement of 18 December 2025 (claimants' data leak, intrusion denied): caf.fr
- franceinfo, ANTS leak (~12 million accounts, April 2026): franceinfo.fr
- French Ministry of Education, 2026 security incidents: education.gouv.fr
- ENISA, Threat Landscape 2025 (public administration 38 % of EU incidents; France 27 %; LockBit's disappearance): enisa.europa.eu
- ACN (Italy), Relazione annuale 2025 (+38 % events, +7 % confirmed incidents): acn.gov.it
- NCSC (United Kingdom), Annual Review 2025 (204 nationally significant incidents, +130 %): ncsc.gov.uk
- Comparitech, Government Ransomware Roundup Q1-Q3 2025 (276 attacks, +41 %): comparitech.com
- Gendarmerie nationale, Operation Cronos against LockBit: gendarmerie.interieur.gouv.fr
- Paris prosecutor's office, statements: PlugX disinfection (24 July 2024), DFAS takedown (12 September 2025), ANTS arrest (30 April 2026): tribunal-de-paris.justice.fr
- LeMagIT, DumpSec sweep (June 2026): lemagit.fr
- InCyber, Marak group takedown (June 2026): incyber.org
- Solutions Numériques, Phobos conviction (February 2026): solutions-numeriques.com
- CESIN / OpinionWay, 11th barometer (2026): cesin.fr
- NCSI, France country page (15th, 89.17/100): ncsi.ega.ee
- French Ministry of the Economy, national cybersecurity strategy 2026-2030: presse.economie.gouv.fr
- LuksMentis, Why Is France Among the Top 5 Most Cyberattacked Countries?: luksmentis.com/blog
- LuksMentis, Third-Party Security: Now One of the Leading Entry Points for Attackers: luksmentis.com/blog
- Primary data: LuksMentis intelligence (1,251 major France-related reports, February-August 2026)