In February 2026, a cybercriminal impersonated the credentials of an external official linked to the French Direction Générale des Finances Publiques (DGFiP), an agency responsible for public finances. This official had access to a database of inter-ministerial exchanges, which the attacker used to gain entry to FICOBA, the national file of bank accounts. At least 1.2 million accounts were compromised, exposing sensitive information such as RIB (a French bank account identifier), IBAN (International Bank Account Number), and personal details of the account holders. In April 2026, the Ministry of the Interior confirmed that a data breach had affected 11.7 million accounts, with the Paris prosecutor stating that the stolen data were being sold on the dark web. This was not an isolated incident, as the National Cybersecurity Agency (ANSSI) had previously dismissed the authenticity of a similar database offered for sale in March 2025, with no connection to the agency found.
In August 2026, the DGFiP faced another breach, this time with an attacker impersonating both an internal agent and an authorized third party. The intrusions occurred in June and July, but the data theft was only discovered in August after the attacker claimed to have stolen information. Nearly 678,000 individuals and professionals were affected, with their tax income data, family quotient, and source withholding rate compromised. The breach was uncovered simultaneously by an alert from the ANSSI and the attacker's public claim. The same individual also allegedly accessed the cadastral data server, which contains property records, affecting more than 2 million property owners.
At the same time, the French National Education system reported an intrusion that occurred on the night of July 25. This breach involved sensitive data such as bank accounts, civil registry information, income details, and property records. Unlike typical data leaks that end up on obscure websites, this data was reportedly released directly to the public by the State itself. The incident highlights the growing risks of cyberattacks on critical national infrastructure and the potential for sensitive information to be exposed in unexpected ways.
The concept of defender's asymmetry in cybersecurity describes the challenge that defenders face, where they must be perfect at all times, while attackers only need to succeed once. This imbalance has driven the development of numerous tools and standards aimed at improving digital security, including the General Data Protection Regulation (GDPR), ISO 27001 for information security management, HDS for health data, SecNumCloud for cloud security, DORA for financial institutions, PSSIE for the State, and the Cyber France Reference Framework introduced by the ANSSI in March 2026.
Despite these efforts, the implementation of the decree No. 2022-513 of April 8, 2022, which outlines digital security governance for public administrations and their entities, remains inconsistent. Many systems lack up-to-date security certifications, and some managers fail to take personal responsibility for cybersecurity. The 2026 data breaches demonstrate this weakness, as active user credentials and access rights were never reviewed. Meanwhile, the NIS 2 directive, which aims to strengthen cybersecurity across 15,000 entities in 18 sectors in France, has faced delays due to political disagreements in the Senate. As of January 1, 2026, 20 of the 27 European Union member states had already implemented the directive, leaving France behind. The European Commission has since filed a legal case against France for failing to comply with the directive.
The Resilience bill was introduced to the National Assembly on October 7, 2026, two years after a commitment to accelerate its passage. Despite the delays and existing security measures, data leaks continued, underscoring the need to reassess access rights, close unused accounts, limit unnecessary access, and implement stronger authentication methods. If the 2022 decree had been followed consistently, many of these breaches could have been prevented. A thorough security certification process is more effective than simply adding new reference frameworks. Ultimately, organizations must shift from a mindset focused on building walls around data to understanding the flow of data—tracking where it goes, who accesses it, and the purpose behind such access.
Cybersecurity Challenges and Data Leaks in French Government Agencies
AI-rewritten from original reportingHow it works
cybersecuritydata-breachfrancegovernmentdigital-securitynist



