The ANSSI (National Cybersecurity Agency of France) has released its first situation report on the REACTIV program, launched at the request of Prime Minister Sébastien Lecornu. Introduced on September 7, the program shifts the agency’s focus to two key tasks: managing compromised user accounts and analyzing data breaches. The report provides detailed insights into cyber incidents affecting French government ministries over the past two months, highlighting the scale and nature of the vulnerabilities involved. Since August 1, 2026, the ANSSI has recorded 99 data breaches, with 67 confirmed and 32 still under investigation. A major point of concern is the CVE-2026-72898 vulnerability in Metabase, an open-source platform used for economic intelligence. This vulnerability, classified as an SQL injection flaw, allows unauthorized users to access databases and gain administrative control. The vulnerability was identified by Metabase on August 3, and a patch was released on August 6. However, attacks exploiting this flaw were already occurring in French ministries, such as France VAE, as early as August 8. The ANSSI reports that 118 user accounts were compromised in its Innovation Laboratory, including external accounts with sensitive data such as emails and passwords. The affected Metabase instances were updated, passwords were reset, and inactive accounts were disabled. In the DINUM (Interministerial Digital Directorate), two Metabase instances, ProConnect and Nuage-Public, were compromised. The data exfiltrated included administrative details of public organizations and anonymized connection histories, though the agency notes that much of this data was already publicly available. Patches were applied, and compromised accounts were removed. The report also highlights a delay between the publication of the Metabase patch and the first attacks observed in ministries, suggesting that some organizations may have been slow to apply the updates. Other incidents involved classic vulnerabilities, such as stolen credentials from personal or partner computers used to access services without two-factor authentication. The PIGP (Public Management Portal), cadastre (land registry), and AEFE (Agency for French Education Abroad) were among the affected services. The ANSSI points out that the use of simple email-based second-factor authentication is no longer considered secure, and the lack of stronger authentication methods has made breaches easier for attackers.