< Back to situation

[REVISION HISTORY]

Data breaches in French public organizations

Updated 1 time since CLSTR started tracking revisions of this situation.

What changed

2026-09-29 17:03 UTC → 2026-09-30 21:25 UTC · added removed

Multiple French organizations have reported significant data breaches involving the theft of personal information. In mid-September, the French National Agency for Adult Training (Afpa) reported a breach potentially affecting 1.7 million people. Officials stated the extraction was linked to a vulnerability in a third-party hosting management tool. While personal details like names and addresses were likely compromised, sensitive data such as banking information was reportedly not available on the affected application. Following this, the French National Cybersecurity Agency (ANSSI) released a an incident report regarding a breach at the Directorate General of Public Finances (DGFiP). This incident, The breach, which occurred in late June, involved the theft of data from the ‘E-Contact’ internal messaging system. system used by agents to communicate with taxpayers. While a hacker known as Zerobytes claimed to have stolen approximately 678,000 records, ANSSI attributed identified roughly 353,000 individuals and 252,000 professionals as being affected. An audit requested by the Prime Minister revealed that the breach to stolen credentials was facilitated by weaknesses in credential protection, system architecture, and attack detection. Hackers utilized agent credentials compromised through use on personal devices. The report also highlighted a lack of multi-factor authentication. network segmentation, noting that attackers were able to move laterally from systems belonging to the Ministry of National Education to access applications via the State Interministerial Network (RIE). The unauthorized access and subsequent data exfiltration went undetected for seven weeks, affecting approximately 353,000 individuals throughout July and 252,000 professionals. August. Cybersecurity experts have noted that these incidents highlight a ‘blind spot’ regarding the exploitation of satellite applications—third-party tools used alongside primary systems that are often poorly mapped or undocumented.

Versions

  1. 2026-09-30 21:25 UTC Data breaches in French public organizations
  2. 2026-09-29 17:03 UTC Data breaches in French public organizations

Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.