Following a significant data breach at the Direction générale des Finances publiques (DGFiP), which manages France’s tax and financial data, French Prime Minister Sébastien Lecornu has taken swift action by activating an interministerial crisis cell. This team is tasked with creating a "first response unit" to address cyberattacks more effectively. The unit will be led by the Agence nationale de la sécurité des systèmes d'information (ANSSI), France’s national cybersecurity agency, which is responsible for protecting critical digital infrastructure.
On August 14, 2026, the DGFiP released a statement confirming a large-scale data leak caused by the hacker group ZeroBytes. The breach involved the exposure of tax information for 678,000 individuals and professionals. The hackers managed to impersonate a DGFiP employee and an authorized third party to gain access to the system. They also bypassed security alerts by keeping the volume of data extracted below the usual detection thresholds, allowing them to remain undetected for a longer period.
Prime Minister Lecornu has instructed Nicolas Roche, the Secretary General of Defense and National Security (SGDSN), to oversee the creation of this "first response unit." The unit will primarily consist of ANSSI agents but will also receive support from experts in the Ministry of the Armed Forces, the Ministry of the Interior, and military reservists. The unit is designed to respond immediately to cyber threats, moving directly to the affected ministry’s offices and crisis rooms. Once on site, the team will have full access to the compromised network to deploy their own tools for analysis, including detection probes. This approach aims to streamline crisis management and reduce bureaucratic delays that might slow down the response.
The unit will not wait for a major breach or a ransomware demand to act. Instead, it will deploy quickly after detecting a technical alert, particularly if a high-privilege account—such as a network administrator—has been bypassed, as was the case in the DGFiP incident. In the short term, the unit’s mission will be to trace the attackers, block their data extraction methods, and freeze access to prevent a large-scale data theft. After the operation, the team will prepare a detailed report, which will be submitted directly to the SGDSN and the Prime Minister. This report will include both a technical analysis of the breach and a list of human or software vulnerabilities that need immediate correction. This information will be used by the government to enforce data standardization and impose sanctions if a ministry fails to comply.
France Establishes Cybersecurity Response Unit After Major Data Leak
AI-rewritten from original reportingHow it works
cybersecuritydata-leakfrancedgfipanssicrisis-cell
Original sources:
- 🇫🇷Sciencepost
- 🇫🇷Clubic
- 🇫🇷BFMTV



