Between January and August 2026, the French Breaches platform documented 782 data breach incidents involving French organizations, with the number of incidents increasing each month. This platform, managed by a group of cybersecurity enthusiasts, compiles information from various sources, including claims by malicious actors, technical evidence, and official statements or press releases. Its data collection methods have become more reliable since 2024, and its methodology is considered stable for the period covering 2026.
Of the 782 recorded incidents, about 58% were reported by malicious actors on forums or the dark web without confirmation from the affected organizations. This pattern is supported by the National Agency for the Security of Information Systems (ANSSI), which found in its 2025 Cyber Threat Landscape that only 42% of the data breach reports it investigated could be confirmed, with the rest either being false or involving data that had been previously leaked or circulating for years.
Only about 2% of the incidents were explicitly labeled as ransomware by the platform, indicating that the majority of breaches involved data leaks or data exfiltration, without encryption. This aligns with ANSSI's findings that data exfiltration incidents increased by 51% between 2024 and 2025, while ransomware attacks decreased. This suggests a shift in cyber threats from encryption-based attacks to data theft.
The affected organizations, as seen from the data, are typically those with limited IT and security resources, such as sports organizations, educational institutions, local authorities, and administrations. This is consistent with ANSSI’s findings that four sectors—education and research, ministries and local authorities, health, and telecommunications—accounted for about 76% of the incidents in 2025. These organizations often have decentralized IT systems and rely heavily on a few cloud tools, making them more vulnerable to cyber threats.
The 2026 Verizon report adds that while technical vulnerabilities remain the most frequent initial access point, identity-related issues, such as phishing and credential misuse, are more prevalent overall. These factors are also present in 39% of all breaches analyzed, highlighting the importance of identity and access management in cyber defense.
For organizations using Microsoft 365, this shift in risk toward identity management is critical. Most French organizations use Microsoft 365 for their professional communications, making it a central hub for sensitive data. This means that the management of Microsoft 365 identities and access is crucial for security.
Key considerations for organizations include whether high-privilege accounts are protected by multi-factor authentication, whether external document sharing is controlled, and whether visibility is maintained on dormant or orphaned accounts. The role of third-party vendors is also significant, as the ANSSI notes an increase in breaches through suppliers or vendors, who can become entry points for attackers.
With 782 incidents recorded in just eight months, it is clear that data breaches are not isolated events but a recurring issue affecting organizations of all sizes and sectors. Organizations must shift from a reactive to a proactive approach, focusing on continuous preparation and resilience rather than waiting for an incident to occur.
The key principles for maintaining security include continuously mapping exposure in Microsoft 365, aligning configurations with recognized benchmarks, automating account lifecycle management, and conducting thorough access reviews. It is also crucial to recognize that perimeter security alone is not enough when identity is the primary vector for attacks.
The volume of data breaches is unlikely to decrease in the near future, given the economic incentives for cybercriminals and the growing dependence on cloud platforms. Resilient organizations will be those that can quickly detect and respond to abnormal access, maintain their identity configurations rigorously, and recover swiftly from incidents when they occur.
French Data Breach Statistics Highlight Identity Management as Key Vulnerability
AI-rewritten from original reportingHow it works
data-breachransomwarecybersecurityidentity-managementmicrosoft-365france



