A recent report from the REACTIV initiative outlines the details of more than a dozen cyber incidents that occurred in recent weeks across various French government and public services. These incidents often involved vulnerabilities in software that allowed unauthorized access to sensitive data. One such vulnerability, found in the Metabase software, allowed attackers to inject SQL commands without needing to authenticate, as highlighted in a security alert issued by CERT-FR on September 10, 2026. This vulnerability was linked to several compromises, including that of Zéro Logement Vacant, a service used by local authorities to track owners of long-term vacant housing. The National Cybersecurity Agency of France (ANSSI) confirmed it learned of this incident on August 28, with the breach originating from a compromised Metabase instance. The report lists approximately twenty incidents that occurred since early July, all involving potential or confirmed data leaks. Some of these are still being investigated, while others have more defined numbers of affected individuals or data volumes. For instance, on August 12, the Agency for French Education Abroad (AEFE) was targeted through a compromised account, which allowed access to the internal directory of more than 30,000 individuals. This included personal details, contact information, and data related to professional qualifications and financial support for vocational education. On August 7, the data management service Bloctel experienced a breach that exposed around 600,000 phone numbers through a compromised company account. Other affected entities included TRACFIN, a financial intelligence service, which suffered a breach through a compromised subcontractor, exposing data on 136 professionals. The DGFiP (Directorate General for Finance) was targeted twice in late August, with the first incident exposing tax data for 353,000 individuals and 252,000 professionals, and the second involving the exfiltration of 2 million cadastral records linked to 434,000 users. The ANSSI itself was also affected, with over 300 user accounts on the BNUM (Digital Bureau) being compromised, allowing the theft of emails and shared files. The OISO portal, used for monitoring organizations, suffered a breach that exposed data on 22,000 employees and organizations. Several other services were also impacted, including the Qualicharge application, which manages electric vehicle charging infrastructure, and the ANSSI’s own innovation laboratory. The latter experienced a breach that compromised 118 user accounts, including those of external partners. The ANSSI also linked a potential data breach at the Ministry of National Education to an attack on its information system, which may have exposed data on 4.35 million teachers. This breach was connected to a reported data theft in the Créteil academy, involving the database of one million students, their guardians, and teachers. Other incidents, such as those involving the Préférence Formations and SNU (National Universal Service) portals, remain uncertain in terms of the exact number of affected individuals.