Following a difficult summer marked by a series of high-profile cyberattacks, France's cybersecurity agency, Anssi, is revising its understanding of the evolving threat landscape. Earlier this year, the agency cautiously noted a "change" in the nature of cyber threats, describing it as "intense" with a potential shift from ransomware attacks to more data leaks. However, after major breaches in government agencies, including the National Agency for Secure Titles (ANTS) in mid-April and the General Directorate of Public Finances (DGFiP) this summer, Anssi director Vincent Strubel has become more definitive in his assessments. During a meeting with universities affiliated with the Hexatrust association, Strubel described the current situation as "the emergence of a new aspect of the threat." While the threat had existed before, it had largely gone unnoticed. On LinkedIn, Strubel called the evolution "major," emphasizing the need for greater awareness and action. Strubel highlighted that the current wave of attacks is not solely attributed to state actors, organized cybercriminal groups, or hacktivists. He noted that since the summer of 2025, a group of "turbulent young French people" has been linked to the surge in data leaks. These individuals, whose profiles are being studied through judicial investigations, launch relatively unsophisticated attacks that are not very stealthy. They act quickly, without seeking to be discreet, and often aim to grab whatever data they can before publishing it immediately. The main motivation for these attackers appears to be "to gain visibility, to have a moment of attention and to discredit their victims," particularly the state. Some hackers seem to have a "particular grudge" against government institutions. They also target "weak targets"—information systems that have been attacked little until now, and whose vulnerabilities had gone unnoticed. Strubel noted that these cybercriminals have managed to surprise Anssi experts, as this threat "is poorly documented." There are not the usual sources of information in terms of intelligence on cyber threats or other monitoring systems, "at least not yet." He also mentioned that there are not yet "well-developed infrastructures" to monitor the threat effectively. However, Strubel emphasized that there are ways to counter this threat. These attacks rely "essentially" on the reuse of compromised authenticators from previous infostealers or attacks. While AI has "undoubtedly" helped in exploring data sets or generating scripts, "it is not the key factor." Strubel compared the evolution of this threat to the emergence of modern ransomware in the late 2010s, noting that it is abrupt. He warned against "defeatism" and the use of slogans like "France passoire," which imply that the country is easily penetrated. Instead, he outlined a program focused on the "systematic deployment of good cybersecurity practices everywhere and all the time," even in systems that have been attacked little or not at all until now.